Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 936487 - [guru] gui-libs/xdg-desktop-portal-hyprland-1.3.2-r1: Security vulnerability.
Summary: [guru] gui-libs/xdg-desktop-portal-hyprland-1.3.2-r1: Security vulnerability.
Status: RESOLVED FIXED
Alias: None
Product: GURU
Classification: Unclassified
Component: Package issues (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Mia Neufeld
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-07-22 11:53 UTC by Markus Probst
Modified: 2024-07-25 10:10 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Markus Probst 2024-07-22 11:53:58 UTC
Update as fast as possible to 1.3.3. (Haven't verified how criticial the vulnerability is).

See https://github.com/hyprwm/xdg-desktop-portal-hyprland/releases/tag/v1.3.3
(it was also mentioned on their discord)
Comment 1 Gonçalo Negrier Duarte 2024-07-22 15:47:00 UTC
For now bump the package your self by renaming the ebuild file to the new version and running `pkgdev manifest -m -f`

Unfortunately I not in my laptop right now. If you can send the detailed of the vulnerability since the release don’t explain it
Comment 2 Gonçalo Negrier Duarte 2024-07-22 15:52:07 UTC
Well it seems the portal is deleting files it should be touching, well for now just downgrade, thanks for the report downstream but next time don’t make High priority.

This is not really a vulnerability it just a small error of the development. I kinda amazed how portals are capable of deleting the user directory to be fare :)
Comment 3 John M. Harris, Jr. 2024-07-22 22:40:43 UTC
(In reply to Gonçalo Negrier Duarte from comment #2)
> This is not really a vulnerability it just a small error of the development.
> I kinda amazed how portals are capable of deleting the user directory to be
> fare :)

It's a "small error of the development", but that error led to a vulnerability. Most vulnerabilities are accidents.
Comment 4 Larry the Git Cow gentoo-dev 2024-07-25 10:10:23 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/proj/guru.git/commit/?id=6dcb18e838a08ad49746bfd2e5e1facdf6169e2d

commit 6dcb18e838a08ad49746bfd2e5e1facdf6169e2d
Author:     Gonçalo Negrier Duarte <gonegrier.duarte@gmail.com>
AuthorDate: 2024-07-22 19:21:23 +0000
Commit:     Gonçalo Negrier Duarte <gonegrier.duarte@gmail.com>
CommitDate: 2024-07-22 19:21:23 +0000

    gui-libs/xdg-desktop-portal-hyprland: pipewire version need to be bump
    to 1.2.1 do to a error compiling with gcc
    * More info: https://github.com/PipeWire/pipewire/commit/da1dbc1
    
    Closes: https://bugs.gentoo.org/935669
    Closes: https://bugs.gentoo.org/936487
    Signed-off-by: Gonçalo Negrier Duarte <gonegrier.duarte@gmail.com>

 ...yprland-1.3.3.ebuild => xdg-desktop-portal-hyprland-1.3.3-r1.ebuild} | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)