Bug 861483 (CVE-2014-0042) - VUL-1: CVE-2014-0042: openstack-heat-templates: setting gpgcheck=0 for signed packages
Summary: VUL-1: CVE-2014-0042: openstack-heat-templates: setting gpgcheck=0 for signed...
Status: RESOLVED DUPLICATE of bug 861481
Alias: CVE-2014-0042
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Vincent Untz
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-01-31 10:08 UTC by Alexander Bergmann
Modified: 2016-04-27 20:24 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-01-31 10:08:14 UTC
Grant Murphy found several problems within the openstack/heat-templates project.

* yum repositories being created with gpgcheck=0 (gpg should be used to verify the packages)

CVE-2014-0042 was assigned to this issue.

External reference:
https://bugs.launchpad.net/heat-templates/+bug/1267635
https://github.com/openstack/heat-templates/
https://bugzilla.redhat.com/show_bug.cgi?id=1059520
Comment 1 Swamp Workflow Management 2014-01-31 23:00:34 UTC
bugbot adjusting priority
Comment 4 Dirk Mueller 2014-04-22 08:38:13 UTC
It is all done in one patch

*** This bug has been marked as a duplicate of bug 861481 ***
Comment 5 SMASH SMASH 2014-07-07 10:35:16 UTC
Affected packages:

SLE-11-SP3-PRODUCTS: openstack-heat-templates