Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 631326 - <x11-wm/xpra-{1.0.9,2.1.3}: multiple vulnerabilities
Summary: <x11-wm/xpra-{1.0.9,2.1.3}: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa]
Keywords:
Depends on: 642244
Blocks:
  Show dependency tree
 
Reported: 2017-09-18 13:25 UTC by Joe Stroller
Modified: 2018-01-17 13:59 UTC (History)
2 users (show)

See Also:
Package list:
=x11-wm/xpra-2.1.3 =x11-wm/xpra-1.0.9
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Joe Stroller 2017-09-18 13:25:13 UTC
Current versions are now Xpra 1.0.8 LTS and 2.1.2 main branch.

2.1.2 contains "at least two critical fixes".

Announcements:

• http://lists.devloop.org.uk/pipermail/shifter-users/2017-September/002002.htmlhttp://lists.devloop.org.uk/pipermail/shifter-users/2017-September/002003.html
Comment 1 Joe Stroller 2017-11-02 09:39:16 UTC
Xpra 1.0.9 LTS and 2.1.3 have now been released.

Both releases "fix some critical issues, in particular weaknesses in the initial authentication exchange. Updating immediately is very strongly recommended".

• http://lists.devloop.org.uk/pipermail/shifter-users/2017-October/002028.htmlhttp://lists.devloop.org.uk/pipermail/shifter-users/2017-October/002027.html
Comment 2 Michael Weber (RETIRED) gentoo-dev 2017-12-08 07:59:08 UTC
@arch teams: Please stable these versions for security reasons, asap.
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2017-12-08 16:03:05 UTC
Convertig bug to security bug.
Comment 4 Thomas Deutschmann (RETIRED) gentoo-dev 2017-12-08 16:06:45 UTC
@ Maintainer: Please add the fixed version to repository first before you call for stabilization.
Comment 5 Michael Weber (RETIRED) gentoo-dev 2017-12-08 17:38:36 UTC
(In reply to Thomas Deutschmann from comment #4)
> @ Maintainer: Please add the fixed version to repository first before you
> call for stabilization.

Sorry, forgot to push, fixed now.
Comment 6 Michael Weber (RETIRED) gentoo-dev 2017-12-22 09:33:15 UTC
@arches: go ahead, thanks.
Comment 7 Larry the Git Cow gentoo-dev 2017-12-22 09:55:04 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d464f0a9258f36ab346b2ba154c7440ff6c1d736

commit d464f0a9258f36ab346b2ba154c7440ff6c1d736
Author:     Michael Weber <xmw@gentoo.org>
AuthorDate: 2017-12-22 09:54:40 +0000
Commit:     Michael Weber <xmw@gentoo.org>
CommitDate: 2017-12-22 09:54:54 +0000

    x11-wm/xpra: Version bump and invoce xdg_pkg_post* stuff in all relevant versions.
    
    Closes: https://bugs.gentoo.org/641654
    Bug: https://bugs.gentoo.org/631326
    Package-Manager: Portage-2.3.19, Repoman-2.3.6

 x11-wm/xpra/Manifest          |   1 +
 x11-wm/xpra/xpra-1.0.9.ebuild |   4 +-
 x11-wm/xpra/xpra-2.1.3.ebuild |   4 +-
 x11-wm/xpra/xpra-2.2.1.ebuild | 146 ++++++++++++++++++++++++++++++++++++++++++
 4 files changed, 153 insertions(+), 2 deletions(-)}
Comment 8 Jason Zaman gentoo-dev 2017-12-22 14:02:28 UTC
amd64 stable
Comment 9 Thomas Deutschmann (RETIRED) gentoo-dev 2017-12-26 00:40:55 UTC
x86 cannot stabilize due to bug 642244.
Comment 10 Larry the Git Cow gentoo-dev 2018-01-14 16:23:12 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c3ad188bc9dfb94dcc38ab58c09bbf6e4e48e054

commit c3ad188bc9dfb94dcc38ab58c09bbf6e4e48e054
Author:     Thomas Deutschmann <whissi@gentoo.org>
AuthorDate: 2018-01-14 16:11:50 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2018-01-14 16:22:59 +0000

    x11-wm/xpra: x86 stable
    
    Bug: https://bugs.gentoo.org/631326
    Package-Manager: Portage-2.3.19, Repoman-2.3.6

 x11-wm/xpra/xpra-1.0.9.ebuild | 4 ++--
 x11-wm/xpra/xpra-2.1.3.ebuild | 4 ++--
 2 files changed, 4 insertions(+), 4 deletions(-)}
Comment 11 Thomas Deutschmann (RETIRED) gentoo-dev 2018-01-14 16:26:05 UTC
@ Maintainer(s): Please cleanup and drop 

  =x11-wm/xpra-1.0.6
  =x11-wm/xpra-2.0.2
Comment 12 Larry the Git Cow gentoo-dev 2018-01-16 22:38:13 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1cab2eb1a5e1dbc5c257c40fda200b01e0a55f96

commit 1cab2eb1a5e1dbc5c257c40fda200b01e0a55f96
Author:     Michael Weber <xmw@gentoo.org>
AuthorDate: 2018-01-16 22:37:13 +0000
Commit:     Michael Weber <xmw@gentoo.org>
CommitDate: 2018-01-16 22:37:13 +0000

    x11-wm/xpra: Remove volnerable versions.
    
    Bug: https://bugs.gentoo.org/631326
    Package-Manager: Portage-2.3.19, Repoman-2.3.6

 x11-wm/xpra/Manifest          |   2 -
 x11-wm/xpra/xpra-1.0.6.ebuild | 143 ------------------------------------------
 x11-wm/xpra/xpra-2.0.2.ebuild | 143 ------------------------------------------
 3 files changed, 288 deletions(-)}
Comment 13 Aaron Bauman (RETIRED) gentoo-dev 2018-01-17 13:59:10 UTC
GLSA Vote: No

Michael, thanks for the cleanup!