Summary: | <dev-qt/qtnetwork-5.14.2-r1: Incorrectly calls SSL_shutdown() (OpenSSL) causing denial of service (CVE-2020-13962) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | qt |
Priority: | Normal | Flags: | nattka:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugreports.qt.io/browse/QTBUG-83450 | ||
See Also: | https://github.com/gentoo/gentoo/pull/16149 | ||
Whiteboard: | A3 [glsa+ cve] | ||
Package list: |
dev-qt/qtnetwork-5.14.2-r1
dev-qt/qtmultimedia-5.14.2-r1
dev-qt/qtdeclarative-5.14.2-r3
dev-qt/qtquickcontrols2-5.14.2-r1 amd64 arm64 x86
|
Runtime testing required: | --- |
Description
Sam James
![]() ![]() ![]() ![]() Patch for 5.14.x: https://codereview.qt-project.org/c/qt/qtbase/+/297147 The bug has been closed via the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8ededff26ca832ef16f40e986c3cf85062de3428 commit 8ededff26ca832ef16f40e986c3cf85062de3428 Author: Andreas Sturmlechner <asturm@gentoo.org> AuthorDate: 2020-06-09 19:05:03 +0000 Commit: Andreas Sturmlechner <asturm@gentoo.org> CommitDate: 2020-06-10 17:52:29 +0000 dev-qt/qtnetwork: Fix CVE-2020-13962 Tested-by: Sam James (sam_c) <sam@cmpct.info Closes: https://bugs.gentoo.org/727604 Package-Manager: Portage-2.3.100, Repoman-2.3.22 Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org> .../files/qtnetwork-5.14.2-CVE-2020-13962.patch | 172 +++++++++++++++++++++ dev-qt/qtnetwork/qtnetwork-5.14.2-r1.ebuild | 66 ++++++++ 2 files changed, 238 insertions(+) @maintainer(s), let us know when ready for stabling! arm64 stable x86 stable amd64 stable arm stable ppc stable ppc64 stable. Maintainer(s), please cleanup. Security, please add it to the existing request, or file a new one. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=50f156c75fa341b22c322a9eedefcf60cfb1daa3 commit 50f156c75fa341b22c322a9eedefcf60cfb1daa3 Author: Andreas Sturmlechner <asturm@gentoo.org> AuthorDate: 2020-06-21 22:23:11 +0000 Commit: Andreas Sturmlechner <asturm@gentoo.org> CommitDate: 2020-06-21 22:23:11 +0000 dev-qt/qtnetwork: Drop vulnerable 5.14.2 (r0) Bug: https://bugs.gentoo.org/727604 Package-Manager: Portage-2.3.101, Repoman-2.3.22 Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org> dev-qt/qtnetwork/qtnetwork-5.14.2.ebuild | 62 -------------------------------- 1 file changed, 62 deletions(-) This issue was resolved and addressed in GLSA 202007-18 at https://security.gentoo.org/glsa/202007-18 by GLSA coordinator Sam James (sam_c). |