Bugzilla – Bug 958331
VUL-0: CVE-2015-7542: gwenhywfar: use system ca-certificates
Last modified: 2018-01-24 15:41:48 UTC
rh#1272503 gwenhywfar uses its own ca bundle, which is likely always outdated. On SLE11 this includes a bundle from _2004_. Please switch to use the system CA directory. References: https://bugzilla.redhat.com/show_bug.cgi?id=1272503
An update workflow for this issue was started. This issue was rated as "moderate". Please submit fixed packages until "Dec. 22, 2015". When done, reassign the bug to "security-team@suse.de". /update/121103/.
bugowner was set to dirkmueller osci rdiff -M -r1:2 SUSE:SLE-12:GA/gwenhywfar ---------------------------------------------------------------------------- r2 | adrianSuSE | 2014-01-24 14:18:43 CET | 97157699ba89d587213890c23b7564e7 | None | <no message> as it is a SLED package, can you find the correct maintainer Frederic?
bugbot adjusting priority
Ismail - can you take this... Thanks.
Still unfixed, please submit
Scott, please assign to someone else.
Antonio - can you take this one. Thanks.
I fixed this on https://build.suse.de/package/show/home:alarrosa:branches:SUSE:SLE-12:Update/gwenhywfar But I can't test it since I don't have a testing scenario and I'm leaving for a week and a half. In any case, I think that fix should be enough. Could anyone try it and submit it? If not, I'll submit it when I'm back.
SUSE-SU-2018:0072-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 958331 CVE References: CVE-2015-7542 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP3 (src): gwenhywfar-4.9.0beta-3.3.1 SUSE Linux Enterprise Workstation Extension 12-SP2 (src): gwenhywfar-4.9.0beta-3.3.1 SUSE Linux Enterprise Software Development Kit 12-SP3 (src): gwenhywfar-4.9.0beta-3.3.1 SUSE Linux Enterprise Software Development Kit 12-SP2 (src): gwenhywfar-4.9.0beta-3.3.1 SUSE Linux Enterprise Desktop 12-SP3 (src): gwenhywfar-4.9.0beta-3.3.1 SUSE Linux Enterprise Desktop 12-SP2 (src): gwenhywfar-4.9.0beta-3.3.1
openSUSE-SU-2018:0094-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 958331 CVE References: CVE-2015-7542 Sources used: openSUSE Leap 42.3 (src): gwenhywfar-4.9.0beta-11.1 openSUSE Leap 42.2 (src): gwenhywfar-4.9.0beta-8.3.1
released