** Information type changed from Private Security to Public Security

-- 
You received this bug notification because you are a member of FreeIPA,
which is subscribed to dogtag-pki in Ubuntu.
https://bugs.launchpad.net/bugs/1987054

Title:
  CVE-2022-2414 not assigned/evaluated correctly

Status in dogtag-pki package in Ubuntu:
  Fix Released

Bug description:
  In the CVE tracker https://ubuntu.com/security/CVE-2022-2414 all recent 
Ubuntu releases are marked as "not vulnerable", I think this is wrong. We can 
see in the Debian tracker that the dogtag-pki *source* package is affected: 
https://security-tracker.debian.org/tracker/CVE-2022-2414
  The dogtag-pki binary package is a metapackage, maybe that's why this slipped 
through? I suppose the vulnerable binary package is pki-core or similar. 
Anyhow, the "not vulnerable" status must be wrong.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/dogtag-pki/+bug/1987054/+subscriptions


_______________________________________________
Mailing list: https://launchpad.net/~freeipa
Post to     : freeipa@lists.launchpad.net
Unsubscribe : https://launchpad.net/~freeipa
More help   : https://help.launchpad.net/ListHelp

Reply via email to