| Summary: | [CVE 21] nghttp2 1.51.0 CVEs found | ||
|---|---|---|---|
| Product: | [ROSA-based products] ROSA Fresh | Reporter: | Yury <y.tumanov> |
| Component: | System (kernel, glibc, systemd, bash, PAM...) | Assignee: | ROSA Linux Bugs <bugs> |
| Status: | VERIFIED FIXED | QA Contact: | ROSA Linux Bugs <bugs> |
| Severity: | critical | ||
| Priority: | Highest | CC: | a.proklov, e.kosachev, pastordidi, s.matveev, v.potapov, y.tumanov |
| Version: | All | Flags: | v.potapov:
qa_verified+
y.tumanov: secteam_verified+ a.proklov: published+ |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | CVE-2023-44487, | ||
| Whiteboard: | |||
| Platform: | 2021.1 | ROSA Vulnerability identifier: | |
| RPM Package: | ISO-related: | ||
| Bad POT generating: | Upstream: | ||
|
Description
Yury
2023-10-18 20:29:07 MSK
*** Bug 13775 has been marked as a duplicate of this bug. *** Думаю лучше закрыть CVE обновлением программы, новая версия в репах будет полезна. nghttp2 1.58.0-1 https://abf.io/build_lists/4811083 https://abf.io/build_lists/4811084 https://abf.io/build_lists/4811085 https://abf.io/build_lists/4811086 https://abf.io/build_lists/4811087 ***************************** Обновление отослано в Тестинг nghttp2 1.58.0-2 добавил обсолет https://abf.io/build_lists/4812529 https://abf.io/build_lists/4812530 https://abf.io/build_lists/4812531 https://abf.io/build_lists/4812532 https://abf.io/build_lists/4812533 (In reply to Aleksandr Proklov from comment #4) > nghttp2 1.58.0-2 > > добавил обсолет > > https://abf.io/build_lists/4812529 > https://abf.io/build_lists/4812530 > https://abf.io/build_lists/4812531 > https://abf.io/build_lists/4812532 > https://abf.io/build_lists/4812533 по поводу ошибки Ошибка: Проблема 1: package lib64nghttp2_asio1-1.51.0-1.x86_64 requires lib64nghttp2_14 = 1.51.0-1, but none of the providers can be installed - cannot install both lib64nghttp2_14-1.58.0-1.x86_64 and lib64nghttp2_14-1.51.0-1.x86_64 - cannot install both lib64nghttp2_14-1.51.0-1.x86_64 and lib64nghttp2_14-1.58.0-1.x86_64 - cannot install the best update candidate for package lib64nghttp2_asio1-1.51.0-1.x86_64 - cannot install the best update candidate for package lib64nghttp2_14-1.51.0-1.x86_64 Проблема 2: problem with installed package lib64nghttp2_asio1-1.51.0-1.x86_64 - package lib64nghttp2_asio1-1.51.0-1.x86_64 requires lib64nghttp2_14 = 1.51.0-1, but none of the providers can be installed - cannot install both lib64nghttp2_14-1.58.0-1.x86_64 and lib64nghttp2_14-1.51.0-1.x86_64 - cannot install both lib64nghttp2_14-1.51.0-1.x86_64 and lib64nghttp2_14-1.58.0-1.x86_64 - package lib64nghttp2-devel-1.58.0-1.x86_64 requires lib64nghttp2_14 = 1.58.0-1, but none of the providers can be installed - cannot install the best update candidate for package lib64nghttp2-devel-1.51.0-1.x86_64 1.58.0-2 нигде не фигурирует в выводе. (In reply to Aleksandr Proklov from comment #4) > nghttp2 1.58.0-2 > > добавил обсолет > > https://abf.io/build_lists/4812529 > https://abf.io/build_lists/4812530 > https://abf.io/build_lists/4812531 > https://abf.io/build_lists/4812532 > https://abf.io/build_lists/4812533 У меня нет ошибок при обновлении этой сборки. nghttp2 1.58.0-3 следующий заход https://abf.io/build_lists/4812555 https://abf.io/build_lists/4812556 https://abf.io/build_lists/4812557 https://abf.io/build_lists/4812558 https://abf.io/build_lists/4812559 (In reply to Aleksandr Proklov from comment #8) > nghttp2 1.58.0-3 > > следующий заход > > https://abf.io/build_lists/4812555 > https://abf.io/build_lists/4812556 > https://abf.io/build_lists/4812557 > https://abf.io/build_lists/4812558 > https://abf.io/build_lists/4812559 ******************************************** The update sent to testings secteam_verified nghttp2-1.58.0-3 https://abf.io/build_lists/4812555 https://abf.io/build_lists/4812556 https://abf.io/build_lists/4812557 https://abf.io/build_lists/4812558 https://abf.io/build_lists/4812559 ************************* Advisory ************************** CVE-2023-44487 fixed by update ************************************************************* QA Verified |