Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 918118 (CVE-2018-11087) - <app-backup/tsm-8.1.22.0: multiple vulnerabilities
Summary: <app-backup/tsm-8.1.22.0: multiple vulnerabilities
Status: CONFIRMED
Alias: CVE-2018-11087
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B4 [glsa?]
Keywords:
Depends on:
Blocks:
 
Reported: 2023-11-24 11:03 UTC by Horst Prote
Modified: 2024-05-03 08:41 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments
tsm-8.1.20.0.ebuild (tsm-8.1.20.0.ebuild,7.46 KB, text/plain)
2023-11-24 11:05 UTC, Horst Prote
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Horst Prote 2023-11-24 11:03:55 UTC
IBM published two Security Bulletins that affect the current app-backup/tsm-8.1.17.2 in the tree:
https://www.ibm.com/support/pages/node/7037816
This is CVE-2018-11087 and effects the bundled amqp-client jar file
https://www.ibm.com/support/pages/node/7037814
This one doesn't have a CVEID but the "IBM X-Force ID" 177835 and effects the bundled commons-codec jar file.

Reproducible: Always




The vulnerabilities are fixed in version 8.1.20.0
Comment 1 Horst Prote 2023-11-24 11:05:40 UTC
Created attachment 875501 [details]
tsm-8.1.20.0.ebuild

I created this ebuild in my local overlay and installed it on my servers.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-11-24 18:06:47 UTC
Thanks for reporting! Dropping version from the summary while there's no fixed version in tree.
Comment 3 Andreas K. Hüttel archtester gentoo-dev 2024-04-27 23:41:19 UTC
commit c16a53958a2594c747803fd4554550b4bfbb3842
Author: Florian Schmaus <flow@gentoo.org>
Date:   Sat Apr 27 16:46:12 2024 +0200

    app-backup/tsm: add 8.1.22.0
    
    As requested by dilfridge in #-dev.
    
    Signed-off-by: Florian Schmaus <flow@gentoo.org>
Comment 4 Andreas K. Hüttel archtester gentoo-dev 2024-05-03 08:41:57 UTC
Stabilized and cleanup done