Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 750929

Summary: <www-client/opera{,-beta}-73.0.3856.284: Multiple vulnerabilities
Product: Gentoo Security Reporter: Sam James <sam>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: chromium, jer
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://blogs.opera.com/desktop/2020/10/opera-72-update/
Whiteboard: B2 [glsa+]
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 750866    

Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-10-23 21:11:12 UTC
Please advise whether FreeType is bundled in this case. Given upstream have bumped to address the same issue as Chromium (see tracker bug), it seems like it is, and that the RDEPEND is stale (as was the case with www-client/google-chrome).

CCing chromium@ in case they have input.
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-10-23 23:35:05 UTC
Okay, I did some poking and it's not bundled and it seems to use the system one. But we still need a major update anyway.
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-11-01 13:13:36 UTC
(In reply to Sam James from comment #1)
> Okay, I did some poking and it's not bundled and it seems to use the system
> one. But we still need a major update anyway.

Turns out it *is* bundled.
Comment 3 Larry the Git Cow gentoo-dev 2020-11-01 18:20:18 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f90a8cfca6ff92c6da4a44dd2b8ecded4a78e92d

commit f90a8cfca6ff92c6da4a44dd2b8ecded4a78e92d
Author:     Stephan Hartmann <sultan@gentoo.org>
AuthorDate: 2020-11-01 18:19:38 +0000
Commit:     Stephan Hartmann <sultan@gentoo.org>
CommitDate: 2020-11-01 18:20:09 +0000

    www-client/opera: bump to 72.0.3815.186
    
    Bug: https://bugs.gentoo.org/750929
    Package-Manager: Portage-3.0.8, Repoman-3.0.2
    Signed-off-by: Stephan Hartmann <sultan@gentoo.org>

 www-client/opera/Manifest                   |  1 +
 www-client/opera/opera-72.0.3815.186.ebuild | 97 +++++++++++++++++++++++++++++
 2 files changed, 98 insertions(+)
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-12-16 07:12:01 UTC
May need to update if we're not killing opera-bin?
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-12-16 09:09:30 UTC
We still have to bump -beta, as sultan confirmed he plans to keep it for now.
Comment 6 Larry the Git Cow gentoo-dev 2020-12-16 19:04:32 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=649333faec21dd3d0b985175193705d295aae92d

commit 649333faec21dd3d0b985175193705d295aae92d
Author:     Stephan Hartmann <sultan@gentoo.org>
AuthorDate: 2020-12-16 19:01:53 +0000
Commit:     Stephan Hartmann <sultan@gentoo.org>
CommitDate: 2020-12-16 19:04:25 +0000

    www-client/opera: stable channel bump to 73.0.3856.284
    
    Bug: https://bugs.gentoo.org/562038
    Bug: https://bugs.gentoo.org/573052
    Bug: https://bugs.gentoo.org/602670
    Bug: https://bugs.gentoo.org/709652
    Bug: https://bugs.gentoo.org/750929
    Package-Manager: Portage-3.0.9, Repoman-3.0.2
    Signed-off-by: Stephan Hartmann <sultan@gentoo.org>

 www-client/opera/Manifest                   |   2 +
 www-client/opera/metadata.xml               |  10 +-
 www-client/opera/opera-72.0.3815.320.ebuild |  97 --------------------
 www-client/opera/opera-73.0.3856.284.ebuild | 137 ++++++++++++++++++++++++++++
 4 files changed, 146 insertions(+), 100 deletions(-)
Comment 7 Larry the Git Cow gentoo-dev 2020-12-17 08:25:33 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e39e9485642fb9fa78e75b9cdfca3a3a75aadbd3

commit e39e9485642fb9fa78e75b9cdfca3a3a75aadbd3
Author:     Stephan Hartmann <sultan@gentoo.org>
AuthorDate: 2020-12-17 08:24:36 +0000
Commit:     Stephan Hartmann <sultan@gentoo.org>
CommitDate: 2020-12-17 08:25:26 +0000

    www-client/opera-developer: dev channel bump to 74.0.3904.0
    
    Bug: https://bugs.gentoo.org/562038
    Bug: https://bugs.gentoo.org/573052
    Bug: https://bugs.gentoo.org/602670
    Bug: https://bugs.gentoo.org/709652
    Bug: https://bugs.gentoo.org/750929
    Package-Manager: Portage-3.0.9, Repoman-3.0.2
    Signed-off-by: Stephan Hartmann <sultan@gentoo.org>

 www-client/opera-developer/Manifest                |   6 +-
 www-client/opera-developer/metadata.xml            |   6 +-
 .../opera-developer-73.0.3820.0.ebuild             | 105 ----------------
 .../opera-developer-73.0.3827.0.ebuild             | 105 ----------------
 .../opera-developer-73.0.3834.0.ebuild             | 105 ----------------
 .../opera-developer-73.0.3841.0.ebuild             | 105 ----------------
 .../opera-developer-74.0.3904.0.ebuild             | 137 +++++++++++++++++++++
 7 files changed, 144 insertions(+), 425 deletions(-)
Comment 8 Larry the Git Cow gentoo-dev 2020-12-17 17:43:06 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=0995299103784ed702b1c7dc40b25067904b264c

commit 0995299103784ed702b1c7dc40b25067904b264c
Author:     Stephan Hartmann <sultan@gentoo.org>
AuthorDate: 2020-12-17 17:41:06 +0000
Commit:     Stephan Hartmann <sultan@gentoo.org>
CommitDate: 2020-12-17 17:42:57 +0000

    www-client/opera-beta: beta channel bump to 73.0.3856.283
    
    Bug: https://bugs.gentoo.org/750929
    Closes: https://bugs.gentoo.org/562038
    Closes: https://bugs.gentoo.org/573052
    Closes: https://bugs.gentoo.org/593404
    Closes: https://bugs.gentoo.org/602670
    Closes: https://bugs.gentoo.org/709652
    Package-Manager: Portage-3.0.9, Repoman-3.0.2
    Signed-off-by: Stephan Hartmann <sultan@gentoo.org>

 www-client/opera-beta/Manifest                     |   5 +-
 www-client/opera-beta/metadata.xml                 |   6 +-
 .../opera-beta/opera-beta-72.0.3815.133.ebuild     | 103 ---------------
 .../opera-beta/opera-beta-72.0.3815.49.ebuild      | 103 ---------------
 .../opera-beta/opera-beta-72.0.3815.86.ebuild      | 103 ---------------
 .../opera-beta/opera-beta-73.0.3856.283.ebuild     | 138 +++++++++++++++++++++
 6 files changed, 145 insertions(+), 313 deletions(-)
Comment 9 NATTkA bot gentoo-dev 2021-07-29 17:25:36 UTC
Package list is empty or all packages have requested keywords.
Comment 10 Larry the Git Cow gentoo-dev 2024-01-15 12:40:34 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=80a2a979c524a00d3c622fe1bb259d0a32e41700

commit 80a2a979c524a00d3c622fe1bb259d0a32e41700
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2024-01-15 12:40:03 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2024-01-15 12:40:29 +0000

    [ GLSA 202401-19 ] Opera: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/750929
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202401-19.xml | 53 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 53 insertions(+)