Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 586026

Summary: <kde-apps/kopete-16.12.0: OTR plugin leaks unencrypted messages
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: kde
Priority: Normal Flags: stable-bot: sanity-check+
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugzilla.redhat.com/show_bug.cgi?id=1346839
Whiteboard: B3 [noglsa]
Package list:
=kde-apps/kopete-16.12.0 amd64 x86
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2016-06-15 14:46:48 UTC
From ${URL} :

Using kopete with OTR plugin may lead to sending messages unencrypted without notice.

Upstream bugs:

https://bugs.kde.org/show_bug.cgi?id=274099
https://bugs.kde.org/show_bug.cgi?id=362535

References:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=827048


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-11-22 09:33:10 UTC
https://cgit.kde.org/kopete.git/commit/?id=19957f9324a5ae45bcb1479f1bb017efa77d0aa7

Thanks to Kensington for working with upstream to get this fixed!
Comment 2 Andreas Sturmlechner gentoo-dev 2016-11-23 21:32:46 UTC
If anyone is actually still using kopete:4, please test the following PR related to the subject: https://github.com/gentoo/gentoo/pull/2901
Comment 3 Andreas Sturmlechner gentoo-dev 2017-01-01 11:54:00 UTC
This has been part of 16.12.0 release, in tree for two weeks now, which apart from this security fix only has two other bugfixes compared to 16.08.3 (fixing google accounts and jabber server list url). KDE Applications couldn't care less since kopete was removed from kdenetwork-meta, so from my POV 16.12.0 can very well be stabilised.
Comment 4 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-01 18:23:27 UTC
@ Arches,

please test and mark stable: =kde-apps/kopete-16.12.0
Comment 5 Agostino Sarubbo gentoo-dev 2017-01-01 22:10:43 UTC
amd64 stable
Comment 6 Agostino Sarubbo gentoo-dev 2017-01-02 09:57:01 UTC
x86 stable. Closing.
Comment 7 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-02 10:23:57 UTC
Re-opening as security isn't done with this bug yet.

@ Maintainer(s): Please drop <kde-apps/kopete-16.12.0.