<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>45608</bug_id>
          
          <creation_ts>2023-03-21 15:10:04 +0300</creation_ts>
          <short_desc>Имеется незакрытая уязвимость CVE-2022-31214 (was fixed in 0.9.70)</short_desc>
          <delta_ts>2023-04-03 14:46:48 +0300</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Branch p10</product>
          <component>firejail</component>
          <version>не указана</version>
          <rep_platform>x86_64</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P5</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>0</everconfirmed>
          <reporter name="Alexander">alxste</reporter>
          <assigned_to name="qa-team@altlinux.org">qa-team</assigned_to>
          <cc>alxste</cc>
    
    <cc>amakeenk</cc>
          
          <qa_contact name="qa-p10@altlinux.org">qa-p10</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>223139</commentid>
    <comment_count>0</comment_count>
    <who name="Alexander">alxste</who>
    <bug_when>2023-03-21 15:10:04 +0300</bug_when>
    <thetext>CVE-2022-31214 - root escalation in --join logic
    Reported by  Matthias Gerstner, working exploit code was provided to our
    development team. In the same time frame, the problem was independently

В актуальной версии приложения уязвимость закрыта</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>223140</commentid>
    <comment_count>1</comment_count>
    <who name="Alexander">alxste</who>
    <bug_when>2023-03-21 15:11:16 +0300</bug_when>
    <thetext>  * security: CVE-2022-31214 - root escalation in --join logic
    Reported by  Matthias Gerstner, working exploit code was provided to our
    development team. In the same time frame, the problem was independently
    reported by Birk Blechschmidt. Full working exploit code was also provided.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>223842</commentid>
    <comment_count>2</comment_count>
    <who name="Alexander Makeenkov">amakeenk</who>
    <bug_when>2023-04-03 14:46:48 +0300</bug_when>
    <thetext>Обновлено в задании https://packages.altlinux.org/ru/tasks/317165/</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>