Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 771741 - <net-misc/rygel-0.40.1: leaking user's $HOME/Documents
Summary: <net-misc/rygel-0.40.1: leaking user's $HOME/Documents
Status: IN_PROGRESS
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://gitlab.gnome.org/GNOME/rygel/...
Whiteboard: B4 [glsa?]
Keywords:
: 791148 (view as bug list)
Depends on:
Blocks:
 
Reported: 2021-02-20 16:32 UTC by John Helmert III
Modified: 2022-06-02 22:06 UTC (History)
1 user (show)

See Also:
Package list:
net-misc/rygel-0.40.1 *
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-02-20 16:32:40 UTC
I don't quite see how this is happening as I'm not familiar with Rygel, but this issue is apparently fixed in 0.40.1:

https://mail.gnome.org/archives/gnome-announce-list/2021-February/msg00006.html

Please bump.
Comment 1 Larry the Git Cow gentoo-dev 2021-04-18 16:21:08 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6edd88ca5501f3360551fc8eb87f0b37ca67bf4d

commit 6edd88ca5501f3360551fc8eb87f0b37ca67bf4d
Author:     Matt Turner <mattst88@gentoo.org>
AuthorDate: 2021-04-18 15:53:05 +0000
Commit:     Matt Turner <mattst88@gentoo.org>
CommitDate: 2021-04-18 16:21:02 +0000

    net-misc/rygel: Version bump to 0.40.1
    
    Bug: https://bugs.gentoo.org/771741
    Signed-off-by: Matt Turner <mattst88@gentoo.org>

 net-misc/rygel/Manifest            |  1 +
 net-misc/rygel/rygel-0.40.1.ebuild | 82 ++++++++++++++++++++++++++++++++++++++
 profiles/package.mask              |  1 +
 3 files changed, 84 insertions(+)
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-04-18 19:19:19 UTC
Thanks! Please proceed with stabling when ready.
Comment 3 NATTkA bot gentoo-dev 2021-04-18 19:24:26 UTC Comment hidden (obsolete)
Comment 4 NATTkA bot gentoo-dev 2021-04-28 16:28:30 UTC Comment hidden (obsolete)
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-05-09 01:54:15 UTC
Ugh, this is going to be a pain with the Tracker requirement..
Comment 6 Ionen Wolkens gentoo-dev 2021-05-19 22:27:03 UTC
*** Bug 791148 has been marked as a duplicate of this bug. ***
Comment 7 NATTkA bot gentoo-dev 2021-05-26 22:24:29 UTC Comment hidden (obsolete)
Comment 8 NATTkA bot gentoo-dev 2021-05-26 22:28:48 UTC Comment hidden (obsolete)
Comment 9 NATTkA bot gentoo-dev 2021-05-26 23:24:40 UTC Comment hidden (obsolete)
Comment 10 NATTkA bot gentoo-dev 2021-05-26 23:28:36 UTC Comment hidden (obsolete)
Comment 11 NATTkA bot gentoo-dev 2021-05-27 02:55:20 UTC Comment hidden (obsolete)
Comment 12 NATTkA bot gentoo-dev 2021-05-27 19:24:57 UTC Comment hidden (obsolete)
Comment 13 NATTkA bot gentoo-dev 2021-05-28 04:24:32 UTC Comment hidden (obsolete)
Comment 14 NATTkA bot gentoo-dev 2021-05-28 16:00:36 UTC Comment hidden (obsolete)
Comment 15 NATTkA bot gentoo-dev 2021-05-28 16:43:15 UTC Comment hidden (obsolete)
Comment 16 NATTkA bot gentoo-dev 2021-05-29 08:57:56 UTC Comment hidden (obsolete)
Comment 17 Larry the Git Cow gentoo-dev 2021-05-31 01:59:58 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d4d3b5ef96fee631ec1a00f44af3f883799848f2

commit d4d3b5ef96fee631ec1a00f44af3f883799848f2
Author:     Matt Turner <mattst88@gentoo.org>
AuthorDate: 2021-05-30 23:59:08 +0000
Commit:     Matt Turner <mattst88@gentoo.org>
CommitDate: 2021-05-31 01:58:23 +0000

    net-misc/rygel: Drop old versions
    
    Bug: https://bugs.gentoo.org/771741
    Signed-off-by: Matt Turner <mattst88@gentoo.org>

 net-misc/rygel/Manifest            |  1 -
 net-misc/rygel/rygel-0.38.4.ebuild | 81 --------------------------------------
 2 files changed, 82 deletions(-)
Comment 18 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-05-31 16:10:44 UTC
Thank you!
Comment 19 NATTkA bot gentoo-dev 2022-01-24 22:45:12 UTC
Unable to check for sanity:

> no match for package: net-misc/rygel-0.40.1