Ticket #3540 (closed defect: fixed)

Opened 13 months ago

Last modified 13 months ago

CVE-2013-1897 389-ds: unintended information exposure when rootdse is enabled [fedora-all]

Reported by: mkosek Owned by: mkosek
Priority: major Milestone: FreeIPA 3.2 - 2013/04 (Beta)
Component: IPA Version: 2.0
Keywords: Cc:
Blocked By: Blocking:
Affects Documentation: no Patch posted for review: no
Red Hat Bugzilla: 928948 Patch review by:
External tracker: Design link:
Needs UI design: Fedora test page:
Feature: Source:
Expertise:
Release Notes:

Description

Ticket was cloned from Red Hat Bugzilla (product Fedora): Bug 928948

This is an automatically created tracking bug!  It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.

For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.

For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs

When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s).  This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.

Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.

Please note: this issue affects multiple supported versions of Fedora.
Only one tracking bug has been filed; please ensure that it is only closed
when all affected versions are fixed.

[bug automatically created by: add-tracking-bugs]

Change History

comment:1 Changed 13 months ago by mkosek

  • Owner changed from someone to mkosek
  • Patch posted for review unset
  • Milestone changed from 0.0 NEEDS_TRIAGE to 2013 Month 04 - April (3.2 Beta)
  • Affects Documentation unset
  • design_review set to 0
  • testsupdated set to 0

This ticket is just a spec file update so that new FreeIPA releases requires the 389-ds-base version with CVE fix included.

Since this is a CVE fix which needs to be fixed now, moving to current release bucket.

comment:2 Changed 13 months ago by mkosek

  • Resolution set to fixed
  • Status changed from new to closed
Note: See TracTickets for help on using tickets.