Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 572974 - <media-gfx/shotwell-0.23.0: bump to fix some bugs and security issues get it working with webkit-gtk:4
Summary: <media-gfx/shotwell-0.23.0: bump to fix some bugs and security issues get it ...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Markos Chandras (RETIRED)
URL:
Whiteboard: B3 [ebuild cve]
Keywords:
: 581376 (view as bug list)
Depends on:
Blocks: CVE-2016-1723, CVE-2016-1724, CVE-2016-1725, CVE-2016-1726, CVE-2016-1727, CVE-2016-1728
  Show dependency tree
 
Reported: 2016-01-26 12:12 UTC by Pacho Ramos
Modified: 2016-12-13 11:35 UTC (History)
7 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Pacho Ramos gentoo-dev 2016-01-26 12:12:11 UTC
Old webkit-gtk slots are unmaintained and contain multiple security issues:
https://lists.fedoraproject.org/archives/list/devel%40lists.fedoraproject.org/thread/S3VHBCPMPVZ3NBKR7FQZQE6HBUHVEZ3D/

That is the cause Fedora switched to a snapshot of shotwell that finally uses the fixed webkitgtk4:
http://pkgs.fedoraproject.org/cgit/rpms/shotwell.git/tree/shotwell.spec

Could we get also a fixed snapshot?

Thanks a lot
Comment 1 Mart Raudsepp gentoo-dev 2016-03-15 10:07:04 UTC
Without snapshot we are also security vulnerable:
https://mail.gnome.org/archives/distributor-list/2016-March/msg00001.html
Comment 2 Duncan 2016-03-16 22:58:31 UTC
Not a shotwell user, but the security issue (among a few similar security issues against other apps) has been noted in LWN:

http://lwn.net/Articles/679862

which in turn links a gnome blog entry:

https://blogs.gnome.org/mcatanzaro/2016/03/12/do-you-trust-this-application/

which it turn points to the vulnerability notification from back in January on the gnome distributor's list, which gentoo gtk and gnome app maintainers should be on and thus should have gotten the notification back then (with the March followup that leio noted in comment #1):

https://mail.gnome.org/archives/distributor-list/2016-January/msg00000.html

So ccing security@ because this has been going on since January and hwoarang@ and graphics@ seem to have been MIA for six weeks and counting... on a security issue that's now getting more publicity.

Maybe that will at least get the package security-masked and perhaps ultimately last-rited, since nobody seems interested in fixing it.


Users can note that it's the uploading feature that's the issue, as it doesn't verify the security of the connection, which means passwords to the upload accounts may have been exposed and should be changed.  Users simply using shotwell for its local photo management features and not to upload aren't affected.  Too bad the uploading feature isn't switchable via USE flag so just the flag could be use-masked, but I suppose upstream didn't expose that as a build-time option, so...
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2016-03-18 05:06:14 UTC
Added the Gnome project as well.  Should p.mask and last-rites be considered this package will also need to be removed as a dependency from:

gnome-base/gnome-extra-apps

and the local USE flag removed.

If there is not a timely response we will coordinate to mask the package and issue last-rites.

@Markos,  I know have your devaway set, but please let us know what you would like to do as maintainer of the package.  There is a git snapshot available upstream with the appropriate TLS fix from Fedora.  Active development seems to have ceased though.  Thanks.

Still pending a CVE assignment: 

http://www.openwall.com/lists/oss-security/2015/12/04/4
Comment 4 Pacho Ramos gentoo-dev 2016-05-17 15:02:04 UTC
*** Bug 581376 has been marked as a duplicate of this bug. ***
Comment 5 Pacho Ramos gentoo-dev 2016-05-28 15:46:52 UTC
[master a421d5f] media-gfx/shotwell: Version bump
 2 files changed, 115 insertions(+)
 create mode 100644 media-gfx/shotwell/shotwell-0.23.1.ebuild
Comment 6 Pacho Ramos gentoo-dev 2016-07-30 10:21:27 UTC
The vulnerable versions were dropped