2.8.6 is a security and bugfix release.

Included in the list of fixed issues in 2.8.5 are two CVEs:

CVE-2016-3696: Leakage of CA key in pulp-qpid-ssl-cfg

CVE-2016-3704: Unsafe use of bash $RANDOM for NSS DB password and seed

Several issues with database migrations are also addressed in this release.

How to install

sudo dnf upgrade --advisory=FEDORA-2016-4373f7d32a

This update has been submitted for testing by jcline.

5 years ago

jcline edited this update.

5 years ago

This update has been pushed to testing.

5 years ago

jcline edited this update.

New build(s):

  • pulp-2.8.6-1.fc24
  • pulp-puppet-2.8.6-1.fc24
  • pulp-rpm-2.8.6-1.fc24

Removed build(s):

  • pulp-rpm-2.8.5-1.fc24
  • pulp-puppet-2.8.5-1.fc24
  • pulp-2.8.5-1.fc24
5 years ago

This update has been submitted for testing by jcline.

5 years ago

This update has been pushed to testing.

5 years ago

This update has reached 7 days in testing and can be pushed to stable now if the maintainer wishes

5 years ago

This update has been submitted for stable by pcreech17.

5 years ago

This update has been unpushed.

This update has been unpushed.

jcline edited this update.

New build(s):

  • pulp-puppet-2.8.6-2.fc24
  • pulp-rpm-2.8.6-2.fc24

Removed build(s):

  • pulp-rpm-2.8.6-1.fc24
  • pulp-puppet-2.8.6-1.fc24
5 years ago

This update has been submitted for testing by jcline.

5 years ago

This update has been pushed to testing.

5 years ago

This update has been submitted for stable by jcline.

5 years ago

This update has been pushed to stable.

5 years ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-1
Stable by Karma
1
Stable by Time
disabled
Dates
submitted
5 years ago
in testing
5 years ago
in stable
5 years ago
modified
5 years ago
BZ#1328930 CVE-2016-3696 pulp: Leakage of CA key in pulp-qpid-ssl-cfg
0
0
BZ#1330264 CVE-2016-3704 Pulp: Unsafe use of bash $RANDOM for NSS DB password and seed
0
0
BZ#1338359 pulp-server and python-pulp-streamer rpms both provide the pulp_streamer.service systemd unit
0
0

Automated Test Results