Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 550180 - <net-ftp/filezilla-3.12.0.2: Logjam TLS vulnerability (CVE-2015-4000)
Summary: <net-ftp/filezilla-3.12.0.2: Logjam TLS vulnerability (CVE-2015-4000)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://filezilla-project.org/
Whiteboard: B3 [noglsa/cve]
Keywords:
Depends on: 547680
Blocks:
  Show dependency tree
 
Reported: 2015-05-22 15:52 UTC by Bernard Cafarelli
Modified: 2015-11-04 15:12 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bernard Cafarelli gentoo-dev 2015-05-22 15:52:16 UTC
Filezilla project released a bugfix version including a Logjam workaround:
"Reject Diffie-Hellman Groups smaller than 1024 bits when using FTP over TLS to protect against the Logjam attack"

On the security-stabling side, this is based on a recent release (3.11 is 3 days old), and requires >=x11-libs/wxGTK-3.0.2.0-r1 (no wxGTK/3.0 has stable keywords at the moment). Still I suppose it is better to also fix this vulnerability on the client side

Anyway if you want to start a stable request, 3.11.0.1 is in tree and works fine in my (limited and not including FT over TLS) testing
Comment 1 Frank Krömmelbein 2015-07-02 22:48:07 UTC
Ping.
Comment 2 Michael Lange 2015-07-17 17:58:05 UTC
If I using stable net-ftp/filezilla-3.7.3 from tree on the client side and openssh-6.9p1-1 on the server side (up-to-date arch-linux-arm on armv7), give me this in the logs on server side:

Jul 17 19:19:12 CubieTruck sshd[621]: error: Hm, kex protocol error: type 30 seq 1 [preauth]

... and no login for sftp.

I updated to net-ftp/filezilla-3.12.0.2 and login again is possible.
The required x11-libs/wxGTK-3.0.2.0-r1 is stable for amd64 and x86.
Comment 3 Bernard Cafarelli gentoo-dev 2015-08-06 09:21:15 UTC
Ah yes, looks like some progress was made in bug #547680 for =wxGTK-3.0.2.0-r1
We still need ppc stabling first, though
Comment 4 Bernard Cafarelli gentoo-dev 2015-09-24 09:34:27 UTC
net-ftp/filezilla-3.12.0.2 is good to go for stabling (now that deps are OK) and has been in tree for some time, so let's stable this one (even as a "normal" stabling request)

Arches, please test and mark stable =net-ftp/filezilla-3.12.0.2, thanks!
Comment 5 Agostino Sarubbo gentoo-dev 2015-09-24 13:03:33 UTC
amd64 stable
Comment 6 Agostino Sarubbo gentoo-dev 2015-09-25 14:44:23 UTC
x86 stable
Comment 7 Agostino Sarubbo gentoo-dev 2015-11-04 14:27:30 UTC
ppc stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 8 Bernard Cafarelli gentoo-dev 2015-11-04 14:57:34 UTC
Vulnerable version removed from tree:
https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=df609bc3c5ea18d7baeb2e086bf792f51480f6ae
Comment 9 Yury German Gentoo Infrastructure gentoo-dev 2015-11-04 15:02:53 UTC
Arches and Maintainer(s), Thank you for your work.

Security Please Vote.
GLSA Vote: No
Comment 10 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-11-04 15:12:22 UTC
GLSA Vote: No