Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 873331 - <www-apps/element-1.11.8: Multiple vulnerabilities
Summary: <www-apps/element-1.11.8: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://matrix.org/blog/2022/09/28/up...
Whiteboard: ~? [noglsa]
Keywords:
Depends on:
Blocks: 873346
  Show dependency tree
 
Reported: 2022-09-28 16:18 UTC by tastytea
Modified: 2022-09-28 17:43 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description tastytea 2022-09-28 16:18:01 UTC
Two critical severity vulnerabilities in end-to-end encryption and three lower priority issues were found in the SDK which powers Element.
1.11.7[1] seems to be the release that fixes them. It references 4 CVEs that are not published yet:
    - CVE-2022-39249
    - CVE-2022-39250
    - CVE-2022-39251
    - CVE-2022-39236

CVE-2022-39250 and CVE-2022-39251 are the critical severity vulnerabilities, CVE-2022-39249 is a lower severity vulnerability, i don't know what CVE-2022-39236 is.

[1] <https://github.com/vector-im/element-web/releases/tag/v1.11.7>
Comment 1 Bernard Cafarelli gentoo-dev 2022-09-28 16:42:00 UTC
There is even 1.11.8 now already with "Bump IDB crypto store version", looks good to bump to that one (and clean older, this is ~arch only)
Comment 2 Larry the Git Cow gentoo-dev 2022-09-28 16:47:53 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=dcba64768d637f229c9f3287473d8e50337ae612

commit dcba64768d637f229c9f3287473d8e50337ae612
Author:     Bernard Cafarelli <voyageur@gentoo.org>
AuthorDate: 2022-09-28 16:46:06 +0000
Commit:     Bernard Cafarelli <voyageur@gentoo.org>
CommitDate: 2022-09-28 16:47:09 +0000

    www-apps/element: 1.11.8 bump, remove security vulnerable versions
    
    Bug: https://bugs.gentoo.org/873331
    Signed-off-by: Bernard Cafarelli <voyageur@gentoo.org>

 www-apps/element/Manifest                          |  3 +-
 www-apps/element/element-1.11.5.ebuild             | 35 ----------------------
 ...element-1.11.2.ebuild => element-1.11.8.ebuild} |  0
 3 files changed, 1 insertion(+), 37 deletions(-)
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-28 17:43:33 UTC
Thanks, all done already!