Bug 52969 - cloud-init: Multiple issues (4.4)
cloud-init: Multiple issues (4.4)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.4
All Linux
: P5 normal (vote)
: UCS 4.4-7-errata
Assigned To: Quality Assurance
Erik Damrose
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-03-22 10:24 CET by Quality Assurance
Modified: 2021-03-24 15:59 CET (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 0.0 () Debian


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2021-03-22 10:24:48 CET
New Debian cloud-init 0.7.9-2+deb9u1 fixes:
This update addresses the following issue:
* cloud-init (CVE-2021-3429)
Comment 1 Quality Assurance univentionstaff 2021-03-22 11:00:37 CET
--- mirror/ftp/4.3/unmaintained/4.3-0/source/cloud-init_0.7.9-2.dsc
+++ apt/ucs_4.4-0-errata4.4-7/source/cloud-init_0.7.9-2+deb9u1.dsc
@@ -1,3 +1,7 @@
+0.7.9-2+deb9u1 [Fri, 19 Mar 2021 17:35:37 +0000] Noah Meyerhans <noahm@debian.org>:
+
+  * Avoid logging generated passwords (CVE-2021-3429) (Closes: #985540)
+
 0.7.9-2 [Thu, 02 Feb 2017 13:23:41 +0000] Thomas Goirand <zigo@debian.org>:
 
   * Add net-tools as runtime depends (Closes: #853926).

<http://piuparts.knut.univention.de/4.4-7/#3884571582079831731>
Comment 2 Erik Damrose univentionstaff 2021-03-23 19:04:09 CET
OK: yaml
OK: announce_errata
OK: patch
FAIL: piuparts
-> Due to bug 50759 (missing dependencies in maintained)

Verified