Bug 958331 (CVE-2015-7542) - VUL-0: CVE-2015-7542: gwenhywfar: use system ca-certificates
Summary: VUL-0: CVE-2015-7542: gwenhywfar: use system ca-certificates
Status: RESOLVED FIXED
Alias: CVE-2015-7542
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/159466/
Whiteboard: CVSSv2:RedHat:CVE-2015-7542:4.0:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-12-08 12:00 UTC by Marcus Meissner
Modified: 2018-01-24 15:41 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2015-12-08 12:00:22 UTC
rh#1272503

gwenhywfar uses its own ca bundle, which is likely always outdated.

On SLE11 this includes a bundle from  _2004_.

Please switch to use the system CA directory.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1272503
Comment 2 SMASH SMASH 2015-12-08 12:22:45 UTC
An update workflow for this issue was started.

This issue was rated as "moderate".
Please submit fixed packages until "Dec. 22, 2015".

When done, reassign the bug to "security-team@suse.de".
/update/121103/.
Comment 3 Marcus Meissner 2015-12-08 12:33:59 UTC
bugowner was set to dirkmueller 

osci rdiff -M -r1:2 SUSE:SLE-12:GA/gwenhywfar 

----------------------------------------------------------------------------
r2 | adrianSuSE | 2014-01-24 14:18:43 CET | 97157699ba89d587213890c23b7564e7 | None | 

<no message>



as it is a SLED package, can you find the correct maintainer Frederic?
Comment 5 Swamp Workflow Management 2015-12-08 23:00:36 UTC
bugbot adjusting priority
Comment 6 Scott Reeves 2016-05-23 17:33:44 UTC
Ismail - can you take this...  Thanks.
Comment 7 Johannes Segitz 2017-07-11 15:47:01 UTC
Still unfixed, please submit
Comment 8 Ismail Dönmez 2017-08-02 10:51:24 UTC
Scott, please assign to someone else.
Comment 9 Scott Reeves 2017-10-26 22:43:32 UTC
Antonio - can you take this one. Thanks.
Comment 13 Antonio Larrosa 2017-11-29 00:02:18 UTC
I fixed this on https://build.suse.de/package/show/home:alarrosa:branches:SUSE:SLE-12:Update/gwenhywfar

But I can't test it since I don't have a testing scenario and I'm leaving for a week and a half. In any case, I think that fix should be enough.

Could anyone try it and submit it? If not, I'll submit it when I'm back.
Comment 16 Swamp Workflow Management 2018-01-12 14:08:32 UTC
SUSE-SU-2018:0072-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 958331
CVE References: CVE-2015-7542
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP3 (src):    gwenhywfar-4.9.0beta-3.3.1
SUSE Linux Enterprise Workstation Extension 12-SP2 (src):    gwenhywfar-4.9.0beta-3.3.1
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    gwenhywfar-4.9.0beta-3.3.1
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    gwenhywfar-4.9.0beta-3.3.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    gwenhywfar-4.9.0beta-3.3.1
SUSE Linux Enterprise Desktop 12-SP2 (src):    gwenhywfar-4.9.0beta-3.3.1
Comment 17 Swamp Workflow Management 2018-01-15 14:14:52 UTC
openSUSE-SU-2018:0094-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 958331
CVE References: CVE-2015-7542
Sources used:
openSUSE Leap 42.3 (src):    gwenhywfar-4.9.0beta-11.1
openSUSE Leap 42.2 (src):    gwenhywfar-4.9.0beta-8.3.1
Comment 18 Marcus Meissner 2018-01-15 14:21:17 UTC
released