Bug#907298: CVE-2018-15869

2018-10-19 Thread Shengjing Zhu
Control: found -1 1.0.2+dfsg-1 The dynamic source ami is introduced in https://github.com/hashicorp/packer/pull/3817 So the affected upstream version is 0.12 and later. signature.asc Description: PGP signature

Bug#907298: CVE-2018-15869

2018-10-18 Thread Moritz Muehlenhoff
On Thu, Oct 18, 2018 at 10:24:44AM +0200, Moritz Muehlenhoff wrote: > On Thu, Oct 18, 2018 at 04:01:11PM +0800, Shengjing Zhu wrote: > > On Thu, Oct 18, 2018 at 08:54:51AM +0100, Ian Campbell wrote: > > > On Thu, 2018-10-18 at 11:48 +0800, Shengjing Zhu wrote: > > > > Package: awscli > > > > Follow

Bug#907298: CVE-2018-15869

2018-10-18 Thread Moritz Muehlenhoff
On Thu, Oct 18, 2018 at 04:01:11PM +0800, Shengjing Zhu wrote: > On Thu, Oct 18, 2018 at 08:54:51AM +0100, Ian Campbell wrote: > > On Thu, 2018-10-18 at 11:48 +0800, Shengjing Zhu wrote: > > > Package: awscli > > > Followup-For: Bug #907298 > > > > > > The corresponding bug on Redhat is closed as

Bug#907298: CVE-2018-15869

2018-10-18 Thread Ian Campbell
On Thu, 2018-10-18 at 11:48 +0800, Shengjing Zhu wrote: > Package: awscli > Followup-For: Bug #907298 > > The corresponding bug on Redhat is closed as > > > Closing this bug as NOTABUG and asked MITRE for rejection, since the issue > > does not seem to be in AWS CLI but in Packer. > > Can we dow

Bug#907298: CVE-2018-15869

2018-10-18 Thread Shengjing Zhu
On Thu, Oct 18, 2018 at 08:54:51AM +0100, Ian Campbell wrote: > On Thu, 2018-10-18 at 11:48 +0800, Shengjing Zhu wrote: > > Package: awscli > > Followup-For: Bug #907298 > > > > The corresponding bug on Redhat is closed as > > > > > Closing this bug as NOTABUG and asked MITRE for rejection, since

Bug#907298: CVE-2018-15869

2018-10-17 Thread Shengjing Zhu
Package: awscli Followup-For: Bug #907298 The corresponding bug on Redhat is closed as > Closing this bug as NOTABUG and asked MITRE for rejection, since the issue > does not seem to be in AWS CLI but in Packer. Can we downgrade this bug and keep awscli in buster? [1] https://bugzilla.redhat.co

Bug#907298: CVE-2018-15869

2018-08-25 Thread Moritz Muehlenhoff
Package: awscli Severity: grave Tags: security Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15869 Cheers, Moritz