Menu

#99 fix CVE-2011-4339

version-1.8.15
closed-out-of-date
CVE (1)
5
2014-05-21
2014-05-20
No

fix CVE-2011-4339

1 Attachments

Discussion

  • Zdenek Styblik

    Zdenek Styblik - 2014-05-20

    CVE-2011-4339 has already been fixed. Please, drop this patch.

     
  • Zdenek Styblik

    Zdenek Styblik - 2014-05-20
    • status: open --> closed-out-of-date
    • assigned_to: Zdenek Styblik
    • Group: version-1.8.14 --> version-1.8.15
     
  • Jörg Frings-Fürst

    Please take a lock at https://bugzilla.redhat.com/attachment.cgi?id=525972

    It's in lib/helper.c and not in src/ipmievd.c

     
    • Zdenek Styblik

      Zdenek Styblik - 2014-05-21

      I know it's in 'lib/helper.c', and?

       
    • Zdenek Styblik

      Zdenek Styblik - 2014-05-21

      CVE-2011-4339 was about ipmievd's PID file being world writable. And as far as I know, this has been fixed.

       
  • Jörg Frings-Fürst

    In the last downloadable tarball (1.8.14) is the bug not fixed.
    And your link is from src/ipmievd.c.

     
    • Zdenek Styblik

      Zdenek Styblik - 2014-05-21

      Just because patch you've provided hasn't been applied doesn't mean it's not fixed, or does it?

      And yes, I believe 'src/ipmievd.c' that's where the fix should be. Feel free to prove me wrong.

       

Log in to post a comment.