Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 881527 (CVE-2022-28764) - <net-im/zoom-5.12.6.173: local information leak
Summary: <net-im/zoom-5.12.6.173: local information leak
Status: RESOLVED FIXED
Alias: CVE-2022-28764
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://explore.zoom.us/en/trust/secu...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2022-11-16 17:10 UTC by John Helmert III
Modified: 2022-12-02 16:56 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-11-16 17:10:31 UTC
CVE-2022-28764:

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.

Please cleanup.
Comment 1 Ulrich Müller gentoo-dev 2022-11-16 18:08:07 UTC
Target delay is 40 days, right?
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-11-16 20:49:02 UTC
Are you asking to keep around old Zoom for 40 days? The "vulnerability treatment policy" document is sorely out of date, and very little of it reflects the reality of how we treat vulnerabilities.

And as far as I can tell, this has been the case for at least several years before I became a developer.
Comment 3 Ulrich Müller gentoo-dev 2022-11-17 08:45:23 UTC
No, but the last bump was on 2022-11-12, and normally I keep the previous version around for at least two weeks for the convenience of users. It wouldn't be the first time that there's a regression.

Dropping the old version early for a ~4 bug just seems a little out of balance.
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-11-17 16:00:01 UTC
Yes, we can proceed at maintainer's discretion here
Comment 5 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-12-02 16:56:51 UTC
All done