stable

fedmsg-0.18.2-1.fc25

FEDORA-2017-fff6e1af37 created by ralph 8 years ago for Fedora 25

Fix validation logic in the base consumer

The base consumer is intended to only derive its validation switch from the on-disk configuration if the child class doesn't override the validate_signatures switch.

There was a bug here where the default value provided in the base class made it appear as if all child consumers had turned off validation, which is incorrect.

This fix turns on signature validation by default while preserving the ability of child consumers to override the on-disk configuration in special cases.

  • Fixes: CVE-2017-1000001
  • Reviewed-by: Patrick Uiterwijk

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2017-fff6e1af37

This update has been submitted for testing by ralph.

8 years ago

This update has been pushed to testing.

8 years ago
User Icon bt0dotninja commented & provided feedback 8 years ago
karma

checking code and testing it, works fine but still use flask-oidc < 0.1.2

User Icon ignacio provided feedback 8 years ago
karma

This update has reached 7 days in testing and can be pushed to stable now if the maintainer wishes

8 years ago

This update has been submitted for stable by bodhi.

8 years ago
User Icon mhayden commented & provided feedback 8 years ago
karma

Works for me.

This update has been pushed to stable.

8 years ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
3
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
disabled
Dates
submitted
8 years ago
in testing
8 years ago
in stable
8 years ago

Automated Test Results