Mageia 2019-0144: koji security update
Summary
Multiple xmlrpc call handlers in Koji’s hub code contain SQL injection
bugs. By passing carefully constructed arguments to these calls, an
unauthenticated user can issue arbitrary SQL commands to Koji’s database.
This gives the attacker broad ability to manipulate or destroy data
(CVE-2018-1002161).
References
- https://bugs.mageia.org/show_bug.cgi?id=24421
- - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/ZK4UFB6Q4EDKJYDCXJ7R43EBRSWBS3SR/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1002161
Resolution
MGASA-2019-0144 - Updated koji packages fix security vulnerability
SRPMS
- 6/core/koji-1.12.2-1.mga6