Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 586026 - <kde-apps/kopete-16.12.0: OTR plugin leaks unencrypted messages
Summary: <kde-apps/kopete-16.12.0: OTR plugin leaks unencrypted messages
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-06-15 14:46 UTC by Agostino Sarubbo
Modified: 2017-01-02 11:22 UTC (History)
1 user (show)

See Also:
Package list:
=kde-apps/kopete-16.12.0 amd64 x86
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-06-15 14:46:48 UTC
From ${URL} :

Using kopete with OTR plugin may lead to sending messages unencrypted without notice.

Upstream bugs:

https://bugs.kde.org/show_bug.cgi?id=274099
https://bugs.kde.org/show_bug.cgi?id=362535

References:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=827048


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-11-22 09:33:10 UTC
https://cgit.kde.org/kopete.git/commit/?id=19957f9324a5ae45bcb1479f1bb017efa77d0aa7

Thanks to Kensington for working with upstream to get this fixed!
Comment 2 Andreas Sturmlechner gentoo-dev 2016-11-23 21:32:46 UTC
If anyone is actually still using kopete:4, please test the following PR related to the subject: https://github.com/gentoo/gentoo/pull/2901
Comment 3 Andreas Sturmlechner gentoo-dev 2017-01-01 11:54:00 UTC
This has been part of 16.12.0 release, in tree for two weeks now, which apart from this security fix only has two other bugfixes compared to 16.08.3 (fixing google accounts and jabber server list url). KDE Applications couldn't care less since kopete was removed from kdenetwork-meta, so from my POV 16.12.0 can very well be stabilised.
Comment 4 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-01 18:23:27 UTC
@ Arches,

please test and mark stable: =kde-apps/kopete-16.12.0
Comment 5 Agostino Sarubbo gentoo-dev 2017-01-01 22:10:43 UTC
amd64 stable
Comment 6 Agostino Sarubbo gentoo-dev 2017-01-02 09:57:01 UTC
x86 stable. Closing.
Comment 7 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-02 10:23:57 UTC
Re-opening as security isn't done with this bug yet.

@ Maintainer(s): Please drop <kde-apps/kopete-16.12.0.