Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.

Bug 891401

Summary: Update to 1.4.13 before release to fix CVE-2012-6085
Product: [Fedora] Fedora Reporter: Adam Williamson <awilliam>
Component: gnupgAssignee: Brian Lane <bcl>
Status: CLOSED CURRENTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: unspecified    
Version: 18CC: bcl, rdieter, tmraz
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: All   
Whiteboard: AcceptedNTH
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-01-10 03:08:31 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 752665    

Description Adam Williamson 2013-01-02 19:52:52 UTC
Note https://bugzilla.redhat.com/show_bug.cgi?id=891142 and https://bugzilla.redhat.com/show_bug.cgi?id=889440 . This bug is filed for NTH purposes: security team doesn't like us doing NTH stuff on the SRT bugs.

Discussed at 2013-01-02 blocker review meeting: http://meetbot.fedoraproject.org/fedora-bugzappers/2013-01-02/f18final-blocker-review-8.2013-01-02-17.03.log.txt . Accepted as NTH as a security issue in a key component: we should fix this before release.

Comment 1 Adam Williamson 2013-01-02 19:53:24 UTC
You don't have to do anything here, Brian, we just need to pull the update through the freeze.

Comment 2 Tomas Mraz 2013-01-02 21:16:43 UTC
Can we use this bug also for the gnupg2 update (which will just contain the patch from the upstream git)?

Comment 3 Fedora Update System 2013-01-02 22:26:18 UTC
gnupg-1.4.13-1.fc18 has been submitted as an update for Fedora 18.
https://admin.fedoraproject.org/updates/gnupg-1.4.13-1.fc18

Comment 4 Fedora Update System 2013-01-03 10:23:47 UTC
gnupg2-2.0.19-7.fc18 has been submitted as an update for Fedora 18.
https://admin.fedoraproject.org/updates/gnupg2-2.0.19-7.fc18

Comment 5 Fedora Update System 2013-01-03 23:51:48 UTC
Package gnupg2-2.0.19-7.fc18:
* should fix your issue,
* was pushed to the Fedora 18 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing gnupg2-2.0.19-7.fc18'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2013-0148/gnupg2-2.0.19-7.fc18
then log in and leave karma (feedback).

Comment 6 Fedora Update System 2013-01-07 15:01:36 UTC
gnupg-1.4.13-2.fc18 has been submitted as an update for Fedora 18.
https://admin.fedoraproject.org/updates/gnupg-1.4.13-2.fc18

Comment 7 Fedora Update System 2013-01-07 15:02:01 UTC
gnupg-1.4.13-2.fc17 has been submitted as an update for Fedora 17.
https://admin.fedoraproject.org/updates/gnupg-1.4.13-2.fc17

Comment 8 Fedora Update System 2013-01-07 15:02:19 UTC
gnupg-1.4.13-2.fc16 has been submitted as an update for Fedora 16.
https://admin.fedoraproject.org/updates/gnupg-1.4.13-2.fc16

Comment 9 Fedora Update System 2013-01-10 03:08:34 UTC
gnupg2-2.0.19-7.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 10 Fedora Update System 2013-01-10 03:09:25 UTC
gnupg-1.4.13-2.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 11 Fedora Update System 2013-01-20 03:16:50 UTC
gnupg-1.4.13-2.fc16 has been pushed to the Fedora 16 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2013-01-20 03:37:18 UTC
gnupg-1.4.13-2.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.