Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 670028 - app-misc/ freeplane: multiple vulnerabilities
Summary: app-misc/ freeplane: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Deadline: 2019-04-22
Assignee: Gentoo Security
URL:
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2018-10-31 14:11 UTC by Pavol Cupka
Modified: 2019-04-22 07:32 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Pavol Cupka 2018-10-31 14:11:28 UTC
The version of freeplane is (probably) vulnerable to two bugs as stated on the freeplane website.

     Groovy scripts and formulas can escape sandbox, fixed in versions 1.5.20 and 1.6.1_17
    XML External Entity vulnerability in map parser, fixed in versions 1.5.20 and 1.6.1_17 

ref: https://www.freeplane.org/wiki/index.php/Fixed_security_vulnerabilities

Reproducible: Always

Steps to Reproduce:
Here are the links to the vulnerabilities:
1. https://www.freeplane.org/wiki/index.php/XML_External_Entity_vulnerability_in_map_parser
2. https://www.freeplane.org/wiki/index.php/Groovy_scripts_and_formulas_can_escape_sandbox
Comment 1 Larry the Git Cow gentoo-dev 2019-03-23 18:25:28 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=91128b1d969038e07aa1de5c3bd505d141e2a5f0

commit 91128b1d969038e07aa1de5c3bd505d141e2a5f0
Author:     Michał Górny <mgorny@gentoo.org>
AuthorDate: 2019-03-23 18:24:56 +0000
Commit:     Michał Górny <mgorny@gentoo.org>
CommitDate: 2019-03-23 18:24:56 +0000

    package.mask: Last rite app-misc/freeplane
    
    Bug: https://bugs.gentoo.org/670028
    Signed-off-by: Michał Górny <mgorny@gentoo.org>

 profiles/package.mask | 5 +++++
 1 file changed, 5 insertions(+)
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2019-03-27 05:32:06 UTC
Package has been masked, scheduled for removal.
Comment 3 Larry the Git Cow gentoo-dev 2019-04-22 07:32:34 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e03c0e8c36e61b9b3d2493f1b3ff1f52b375a3f1

commit e03c0e8c36e61b9b3d2493f1b3ff1f52b375a3f1
Author:     Michał Górny <mgorny@gentoo.org>
AuthorDate: 2019-04-22 07:31:50 +0000
Commit:     Michał Górny <mgorny@gentoo.org>
CommitDate: 2019-04-22 07:31:50 +0000

    app-misc/freeplane: Remove last-rited pkg
    
    Closes: https://bugs.gentoo.org/670028
    Signed-off-by: Michał Górny <mgorny@gentoo.org>

 app-misc/freeplane/Manifest                |  2 --
 app-misc/freeplane/freeplane-1.5.18.ebuild | 49 ------------------------------
 app-misc/freeplane/metadata.xml            | 11 -------
 profiles/package.mask                      |  5 ---
 4 files changed, 67 deletions(-)