Bug 896679 (CVE-2014-5444) - VUL-0: CVE-2014-5444: geary: Update Geary to latest stable - securityfix included.
Summary: VUL-0: CVE-2014-5444: geary: Update Geary to latest stable - securityfix incl...
Status: RESOLVED FIXED
Alias: CVE-2014-5444
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.1
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Bjørn Lie
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-09-15 11:19 UTC by Bjørn Lie
Modified: 2014-09-28 10:04 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bjørn Lie 2014-09-15 11:19:18 UTC
Latest stable (0.6.3) Geary have a security fix that we should have.

I've not yet been "notified" but I have reason to belive that this is
CVE-2014-5444

See http://pkgs.fedoraproject.org/cgit/geary.git/commit/?id=02d24b2f4780b262808eca6064eadaf0d75039d2

and https://wiki.gnome.org/Apps/Geary

News

Geary 0.6.3 (stable) has been released with important security fix. Yorba highly recommends all 0.6 users upgrade to this release.

0.6.3 is already packaged in Gnome:Apps, and up to date in Factory.
Comment 1 Marcus Meissner 2014-09-15 14:23:00 UTC
if you want to, you can update the version
Comment 2 Bjørn Lie 2014-09-15 15:36:28 UTC
Great, the.

But do we have a way to verify the cve ref?
Comment 3 Marcus Meissner 2014-09-15 15:57:52 UTC
redhat usually does correct assignments. 

it is weird that the CVE is not yet public in their bugzilla, so wait perhaps some days.
Comment 4 Bjørn Lie 2014-09-15 18:22:44 UTC
It's public over at ubuntu

https://bugs.launchpad.net/ubuntu/+source/geary/+bug/1364682


MR#249394 done.
Comment 5 Bernhard Wiedemann 2014-09-15 19:00:13 UTC
This is an autogenerated message for OBS integration:
This bug (896679) was mentioned in
https://build.opensuse.org/request/show/249394 13.1 / geary
Comment 6 Swamp Workflow Management 2014-09-15 22:00:11 UTC
bugbot adjusting priority
Comment 7 Marcus Meissner 2014-09-24 10:50:52 UTC
released
Comment 8 Swamp Workflow Management 2014-09-28 10:04:41 UTC
openSUSE-SU-2014:1225-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 896679
CVE References: CVE-2014-5444
Sources used:
openSUSE 13.1 (src):    geary-0.6.3-3.10.1