Bugzilla – Full Text Bug Listing |
Summary: | VUL-1: CVE-2014-0104: fence-agents: no verification of remote SSL certificates | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Sebastian Krahmer <krahmer> |
Component: | Incidents | Assignee: | Kristoffer Gronlund <kgronlund> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P5 - None | CC: | security-team, smash_bz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/109091/ | ||
Whiteboard: | |||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Sebastian Krahmer
2014-10-13 08:25:12 UTC
Seems like a package where missing X509 checks are not a so severe issue. Therefore setting VUL-1 and its enough to fix in Factory. Partially fixed by bnc#896833. Complementary fix for remaining agents to be applied. This is an autogenerated message for OBS integration: This bug (900879) was mentioned in https://build.opensuse.org/request/show/255744 Factory / fence-agents Fix submitted for Factory. |