Summary: | <dev-qt/qtwebengine-5.15.2: Multiple vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | qt |
Priority: | Normal | Flags: | nattka:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
See Also: |
https://bugs.gentoo.org/show_bug.cgi?id=756763 https://bugs.gentoo.org/show_bug.cgi?id=755704 |
||
Whiteboard: | A2 [glsa+++ cve] | ||
Package list: |
dev-qt/assistant-5.15.2 amd64 arm64 ppc64 x86
dev-qt/designer-5.15.2
dev-qt/linguist-5.15.2 amd64 arm64 ppc64 x86
dev-qt/linguist-tools-5.15.2
dev-qt/pixeltool-5.15.2 amd64 arm64 ppc64 x86
dev-qt/qdbus-5.15.2 amd64 arm64 ppc ppc64 x86
dev-qt/qdbusviewer-5.15.2 amd64 arm64 ppc64 x86
dev-qt/qdoc-5.15.2 amd64 arm64 x86
dev-qt/qt3d-5.15.2 amd64 arm64 x86
dev-qt/qtbluetooth-5.15.2 amd64 arm arm64 x86
dev-qt/qtcharts-5.15.2 amd64 arm64 x86
dev-qt/qtconcurrent-5.15.2
dev-qt/qtcore-5.15.2-r2
dev-qt/qtdatavis3d-5.15.2 amd64 arm64 x86
dev-qt/qtdbus-5.15.2
dev-qt/qtdeclarative-5.15.2
dev-qt/qtdiag-5.15.2 amd64 x86
dev-qt/qt-docs-5.15.2_p202011130614 amd64 arm64 x86
dev-qt/qtgamepad-5.15.2 amd64 arm64 x86
dev-qt/qtgraphicaleffects-5.15.2 amd64 arm64 ppc ppc64 x86
dev-qt/qtgui-5.15.2-r1
dev-qt/qthelp-5.15.2
dev-qt/qtimageformats-5.15.2 amd64 arm64 ppc64 x86
dev-qt/qtlocation-5.15.2-r1 amd64 arm arm64 x86
dev-qt/qtmultimedia-5.15.2
dev-qt/qtnetwork-5.15.2-r1
dev-qt/qtnetworkauth-5.15.2 amd64 arm64 x86
dev-qt/qtopengl-5.15.2
dev-qt/qtpaths-5.15.2 amd64 arm64 ppc ppc64 x86
dev-qt/qtpositioning-5.15.2
dev-qt/qtprintsupport-5.15.2
dev-qt/qtquickcontrols2-5.15.2 amd64 arm64 x86
dev-qt/qtquickcontrols-5.15.2 amd64 arm64 ppc ppc64 x86
dev-qt/qtscript-5.15.2 amd64 arm64 ppc ppc64 x86
dev-qt/qtscxml-5.15.2 amd64 arm64 x86
dev-qt/qtsensors-5.15.2 amd64 arm arm64 ppc64 x86
dev-qt/qtserialport-5.15.2
dev-qt/qtspeech-5.15.2 amd64 arm64 x86
dev-qt/qtsql-5.15.2
dev-qt/qtsvg-5.15.2
dev-qt/qttest-5.15.2
dev-qt/qttranslations-5.15.2
dev-qt/qtvirtualkeyboard-5.15.2 amd64 arm64 x86
dev-qt/qtwayland-5.15.2-r1
dev-qt/qtwebchannel-5.15.2 amd64 arm arm64 ppc64 x86
dev-qt/qtwebengine-5.15.2 amd64 arm64 x86
dev-qt/qtwebsockets-5.15.2 amd64 arm arm64 ppc64 x86
dev-qt/qtwidgets-5.15.2
dev-qt/qtx11extras-5.15.2
dev-qt/qtxml-5.15.2
dev-qt/qtxmlpatterns-5.15.2
|
Runtime testing required: | --- |
Bug Depends on: | 757621, 757657 | ||
Bug Blocks: | 684580 |
Description
Sam James
2020-11-16 02:05:19 UTC
These will be included in 5.15.2. (In reply to Sam James from comment #1) > These will be included in 5.15.2. It's out! \o/ Please stable when ready. Sanity check failed:
> dev-qt/qtwebengine-5.15.2
> depend amd64 dev profile default/linux/amd64/17.0/no-multilib/prefix/kernel-3.2+ (3 total)
> ~dev-qt/designer-5.15.2
> ~dev-qt/qtcore-5.15.2
> ~dev-qt/qtdeclarative-5.15.2
> ~dev-qt/qtdeclarative-5.15.2[widgets]
> ~dev-qt/qtgui-5.15.2
> ~dev-qt/qtnetwork-5.15.2
> ~dev-qt/qtpositioning-5.15.2
> ~dev-qt/qtprintsupport-5.15.2
> ~dev-qt/qttest-5.15.2
> ~dev-qt/qtwebchannel-5.15.2[qml]
> ~dev-qt/qtwidgets-5.15.2
> depend amd64 stable profile default/linux/amd64/17.1 (34 total)
> ~dev-qt/designer-5.15.2
> ~dev-qt/qtcore-5.15.2
> ~dev-qt/qtdeclarative-5.15.2
> ~dev-qt/qtdeclarative-5.15.2[widgets]
> ~dev-qt/qtgui-5.15.2
> ~dev-qt/qtnetwork-5.15.2
> ~dev-qt/qtpositioning-5.15.2
> ~dev-qt/qtprintsupport-5.15.2
> ~dev-qt/qttest-5.15.2
> ~dev-qt/qtwebchannel-5.15.2[qml]
> ~dev-qt/qtwidgets-5.15.2
> rdepend amd64 dev profile default/linux/amd64/17.0/no-multilib/prefix/kernel-3.2+ (3 total)
> ~dev-qt/designer-5.15.2
> ~dev-qt/qtcore-5.15.2
> ~dev-qt/qtdeclarative-5.15.2
> ~dev-qt/qtdeclarative-5.15.2[widgets]
> ~dev-qt/qtgui-5.15.2
> ~dev-qt/qtnetwork-5.15.2
> ~dev-qt/qtpositioning-5.15.2
> ~dev-qt/qtprintsupport-5.15.2
> ~dev-qt/qtwebchannel-5.15.2[qml]
> ~dev-qt/qtwidgets-5.15.2
> rdepend amd64 stable profile default/linux/amd64/17.1 (34 total)
> ~dev-qt/designer-5.15.2
> ~dev-qt/qtcore-5.15.2
> ~dev-qt/qtdeclarative-5.15.2
> ~dev-qt/qtdeclarative-5.15.2[widgets]
> ~dev-qt/qtgui-5.15.2
> ~dev-qt/qtnetwork-5.15.2
> ~dev-qt/qtpositioning-5.15.2
> ~dev-qt/qtprintsupport-5.15.2
> ~dev-qt/qtwebchannel-5.15.2[qml]
> ~dev-qt/qtwidgets-5.15.2
Can we think about doing this now? We should do it at the same time with ICU-68.2. Unable to check for sanity:
> no match for package: dev-qt/qtcore-5.15.2
ping Unable to check for sanity:
> no match for package: dev-qt/qtcore-5.15.2-r1
All sanity-check issues have been resolved arm done arm64 done x86 done ppc64 done ppc done amd64 done all arches done The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=37bcd8a2357a6948aa4d788f6babe299e072c735 commit 37bcd8a2357a6948aa4d788f6babe299e072c735 Author: Andreas Sturmlechner <asturm@gentoo.org> AuthorDate: 2021-01-10 09:53:59 +0000 Commit: Andreas Sturmlechner <asturm@gentoo.org> CommitDate: 2021-01-10 09:53:59 +0000 dev-qt: Security cleanup Bug: https://bugs.gentoo.org/754852 Package-Manager: Portage-3.0.12, Repoman-3.0.2 Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org> dev-qt/assistant/Manifest | 1 - dev-qt/assistant/assistant-5.15.1.ebuild | 55 ---- dev-qt/designer/Manifest | 1 - dev-qt/designer/designer-5.15.1.ebuild | 53 --- dev-qt/designer/metadata.xml | 1 - dev-qt/linguist-tools/Manifest | 1 - dev-qt/linguist-tools/linguist-tools-5.15.1.ebuild | 45 --- dev-qt/linguist/Manifest | 1 - dev-qt/linguist/linguist-5.15.1.ebuild | 48 --- dev-qt/pixeltool/Manifest | 1 - dev-qt/pixeltool/pixeltool-5.15.1.ebuild | 21 -- dev-qt/qdbus/Manifest | 1 - dev-qt/qdbus/qdbus-5.15.1.ebuild | 25 -- dev-qt/qdbusviewer/Manifest | 1 - dev-qt/qdbusviewer/qdbusviewer-5.15.1.ebuild | 45 --- dev-qt/qdoc/Manifest | 1 - dev-qt/qdoc/qdoc-5.15.1.ebuild | 28 -- dev-qt/qt-docs/Manifest | 55 ---- dev-qt/qt-docs/qt-docs-5.15.1_p202009071124.ebuild | 105 ------ dev-qt/qt3d/Manifest | 1 - dev-qt/qt3d/qt3d-5.15.1.ebuild | 36 --- dev-qt/qtbluetooth/Manifest | 1 - dev-qt/qtbluetooth/qtbluetooth-5.15.1.ebuild | 33 -- dev-qt/qtcharts/Manifest | 1 - dev-qt/qtcharts/qtcharts-5.15.1.ebuild | 29 -- dev-qt/qtconcurrent/Manifest | 1 - dev-qt/qtconcurrent/qtconcurrent-5.15.1.ebuild | 23 -- dev-qt/qtcore/Manifest | 1 - dev-qt/qtcore/qtcore-5.15.1-r1.ebuild | 104 ------ dev-qt/qtdatavis3d/Manifest | 1 - dev-qt/qtdatavis3d/qtdatavis3d-5.15.1.ebuild | 31 -- dev-qt/qtdbus/Manifest | 1 - dev-qt/qtdbus/qtdbus-5.15.1.ebuild | 43 --- dev-qt/qtdeclarative/Manifest | 1 - dev-qt/qtdeclarative/qtdeclarative-5.15.1.ebuild | 57 ---- dev-qt/qtdiag/Manifest | 1 - dev-qt/qtdiag/qtdiag-5.15.1.ebuild | 35 -- dev-qt/qtgamepad/Manifest | 1 - dev-qt/qtgamepad/qtgamepad-5.15.1.ebuild | 35 -- dev-qt/qtgraphicaleffects/Manifest | 1 - .../qtgraphicaleffects-5.15.1.ebuild | 21 -- dev-qt/qtgui/Manifest | 1 - ...-qscreen-geometrychanged-when-dpi-changes.patch | 86 ----- dev-qt/qtgui/qtgui-5.15.1-r1.ebuild | 185 ----------- dev-qt/qthelp/Manifest | 1 - dev-qt/qthelp/qthelp-5.15.1.ebuild | 29 -- dev-qt/qtimageformats/Manifest | 1 - dev-qt/qtimageformats/qtimageformats-5.15.1.ebuild | 30 -- dev-qt/qtlocation/Manifest | 1 - dev-qt/qtlocation/qtlocation-5.15.1.ebuild | 47 --- dev-qt/qtmultimedia/Manifest | 1 - dev-qt/qtmultimedia/qtmultimedia-5.15.1.ebuild | 68 ---- dev-qt/qtnetwork/Manifest | 1 - .../files/qtnetwork-5.15.1-libressl.patch | 359 --------------------- dev-qt/qtnetwork/qtnetwork-5.15.1-r1.ebuild | 68 ---- dev-qt/qtnetworkauth/Manifest | 1 - dev-qt/qtnetworkauth/qtnetworkauth-5.15.1.ebuild | 20 -- dev-qt/qtopengl/Manifest | 1 - dev-qt/qtopengl/qtopengl-5.15.1.ebuild | 34 -- dev-qt/qtpaths/Manifest | 1 - dev-qt/qtpaths/qtpaths-5.15.1.ebuild | 19 -- dev-qt/qtplugininfo/Manifest | 1 - dev-qt/qtplugininfo/qtplugininfo-5.15.1.ebuild | 19 -- dev-qt/qtpositioning/Manifest | 1 - dev-qt/qtpositioning/qtpositioning-5.15.1.ebuild | 40 --- dev-qt/qtprintsupport/Manifest | 1 - dev-qt/qtprintsupport/qtprintsupport-5.15.1.ebuild | 42 --- dev-qt/qtquickcontrols/Manifest | 1 - .../qtquickcontrols/qtquickcontrols-5.15.1.ebuild | 32 -- dev-qt/qtquickcontrols2/Manifest | 1 - .../qtquickcontrols2-5.15.1.ebuild | 30 -- dev-qt/qtquicktimeline/Manifest | 1 - .../qtquicktimeline/qtquicktimeline-5.15.1.ebuild | 18 -- dev-qt/qtscript/Manifest | 1 - dev-qt/qtscript/qtscript-5.15.1.ebuild | 36 --- dev-qt/qtscxml/Manifest | 1 - dev-qt/qtscxml/qtscxml-5.15.1.ebuild | 19 -- dev-qt/qtsensors/Manifest | 1 - dev-qt/qtsensors/qtsensors-5.15.1.ebuild | 28 -- dev-qt/qtserialbus/Manifest | 1 - dev-qt/qtserialbus/qtserialbus-5.15.1.ebuild | 20 -- dev-qt/qtserialport/Manifest | 1 - dev-qt/qtserialport/qtserialport-5.15.1.ebuild | 27 -- dev-qt/qtspeech/Manifest | 1 - dev-qt/qtspeech/qtspeech-5.15.1.ebuild | 20 -- dev-qt/qtsql/Manifest | 1 - dev-qt/qtsql/qtsql-5.15.1.ebuild | 55 ---- dev-qt/qtsvg/Manifest | 1 - dev-qt/qtsvg/qtsvg-5.15.1.ebuild | 23 -- dev-qt/qttest/Manifest | 1 - dev-qt/qttest/qttest-5.15.1.ebuild | 33 -- dev-qt/qttranslations/Manifest | 1 - dev-qt/qttranslations/qttranslations-5.15.1.ebuild | 19 -- dev-qt/qtvirtualkeyboard/Manifest | 1 - .../qtvirtualkeyboard-5.15.1.ebuild | 43 --- dev-qt/qtwayland/Manifest | 1 - dev-qt/qtwayland/qtwayland-5.15.1.ebuild | 39 --- dev-qt/qtwebchannel/Manifest | 1 - dev-qt/qtwebchannel/qtwebchannel-5.15.1.ebuild | 26 -- dev-qt/qtwebengine/Manifest | 2 - .../files/qtwebengine-5.15.1-icu-68.patch | 260 --------------- dev-qt/qtwebengine/metadata.xml | 1 - dev-qt/qtwebengine/qtwebengine-5.15.1.ebuild | 158 --------- dev-qt/qtwebsockets/Manifest | 1 - dev-qt/qtwebsockets/qtwebsockets-5.15.1.ebuild | 27 -- dev-qt/qtwebview/Manifest | 1 - dev-qt/qtwebview/qtwebview-5.15.1.ebuild | 21 -- dev-qt/qtwidgets/Manifest | 1 - dev-qt/qtwidgets/qtwidgets-5.15.1.ebuild | 57 ---- dev-qt/qtx11extras/Manifest | 1 - dev-qt/qtx11extras/qtx11extras-5.15.1.ebuild | 22 -- dev-qt/qtxml/Manifest | 1 - dev-qt/qtxml/qtxml-5.15.1.ebuild | 29 -- dev-qt/qtxmlpatterns/Manifest | 1 - dev-qt/qtxmlpatterns/qtxmlpatterns-5.15.1.ebuild | 30 -- 115 files changed, 3102 deletions(-) This issue was resolved and addressed in GLSA 202101-30 at https://security.gentoo.org/glsa/202101-30 by GLSA coordinator Sam James (sam_c). This issue was resolved and addressed in GLSA 202101-30 at https://security.gentoo.org/glsa/202101-30 by GLSA coordinator Sam James (sam_c). This issue was resolved and addressed in GLSA 202101-30 at https://security.gentoo.org/glsa/202101-30 by GLSA coordinator Sam James (sam_c). |