Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 598774 (CVE-2016-9107)

Summary: <net-im/gajim-0.16.6-r1: otr plugin cleartext leak
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED INVALID    
Severity: minor CC: aidecoe, alexander
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://trac-plugins.gajim.org/ticket/145
Whiteboard: B3 [noglsa]
Package list:
Runtime testing required: ---
Bug Depends on: 599546    
Bug Blocks:    

Description Agostino Sarubbo gentoo-dev 2016-11-02 11:15:56 UTC
From ${URL} :

<message from='xxxxxxxxxx' to='xxxxxxxxxxxx' xml:lang='de' type='chat' id='386'>
<body>asd</body>
<html xmlns='http://jabber.org/protocol/xhtml-im'>
<body xmlns='http://www.w3.org/1999/xhtml'>
<p>
<strong>asd</strong>
</p>
</body>
<body 
xmlns='http://www.w3.org/1999/xhtml'>?OTR:AAIDAAAAAAEAAAABAAAAwKBYzRnXBpmvA2WtMapToeCp1aCqWp8Q+vyblAA7R/+meZP0i6if3pLIByBYzo67+B/5WxfCqfL+LsHvgQ4EjVAdyX29DLxhPHLCTxodAHSooyDdZGq9X7aV7SMQNukAUEnmqEynslW5eeTxsPRWYt8kOhPiczx/36W89sabeySnWXMwHGD8Hout2sBZW6uOStjW9E44PkVOa9ertLYj1pCK5uN6uqW2xOCjgsRaFdihGUcndQa99UEQK9Ifa3x2XgAAAAAAAAAEAAAATthfI2LuhtECdNIRoks586yu91Cmr+Vclb2oYvCOYna8Lj/UR2NGnyutdvQwaPGyMpKOUpo9J0BmpDRNpITeQNgRehYmT+NNAgNpdeqbdw/4m6k75Yp3lXddsE+DBgCcXGq+AAAAPJIKTim0Sq5pJ40FN3ycXGUgsFhcsWPjXCjubSpYwQqS5Fm69Wuhr4u6EiVKDoElqjvEZkrK6anvb656sw==.</body>
</html>
<active xmlns='http://jabber.org/protocol/chatstates'/>
<request xmlns='urn:xmpp:receipts'/>
<thread>NNJdLcCElUpAPnWLvRiekJIBxAiJUdAc</thread>
<private xmlns='urn:xmpp:carbons:2'/>
<no-permanent-store xmlns='urn:xmpp:hints'/>
<no-copy xmlns='urn:xmpp:hints'/>
</message>

Commit fix:
https://trac-plugins.gajim.org/changeset/c7c2e519ed63377bc943dd01c4661b0fe49321ae


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-11-12 00:40:24 UTC
@arches, please stabilize:

=net-im/gajim-0.16.6-r1

GLSA Vote: No
Comment 2 Alexander Tsoy 2016-11-12 23:03:32 UTC
1. This bug is in 3rd party OTR plugin. It is not included in gajim package and can be installed via Plugin Installer.
2. Patch commited to the gentoo repo is empty :)
https://gitweb.gentoo.org/repo/gentoo.git/tree/net-im/gajim/files/gajim-0.16.6-otr-cleartext-leak-fix.patch
Comment 3 Amadeusz Żołnowski (RETIRED) gentoo-dev 2016-11-13 09:15:14 UTC
How I possibly could commit an empty patch? I guess I have just taken a look at diff in webui, downloaded empty patch without second look at it, and because empty patch applies cleanly, I've just pushed that. What a shame... I am sorry for that. It won't happen again. I'll just remove gajim-0.16.6-r1.ebuild.

Because it's a plugin not managed within Portage, I think this bug can be closed.

Thanks Alexander for constant vigilance!
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2016-11-17 06:47:35 UTC
@maintainer, thanks for the information.