Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 787950

Summary: <dev-qt/qtwebengine-5.15.2_p20210421: Multiple vulnerabilities
Product: Gentoo Security Reporter: Andreas Sturmlechner <asturm>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: gyakovlev
Priority: Normal Keywords: PullRequest
Version: unspecified   
Hardware: All   
OS: Linux   
See Also: https://bugs.gentoo.org/show_bug.cgi?id=784554
https://bugs.gentoo.org/show_bug.cgi?id=782970
https://bugs.gentoo.org/show_bug.cgi?id=782802
https://bugs.gentoo.org/show_bug.cgi?id=779493
https://bugs.gentoo.org/show_bug.cgi?id=776181
https://bugs.gentoo.org/show_bug.cgi?id=774015
https://bugs.gentoo.org/show_bug.cgi?id=766207
https://github.com/gentoo/gentoo/pull/20688
Whiteboard: A2 [glsa+]
Package list:
Runtime testing required: ---
Bug Depends on: 773040    
Bug Blocks: 800181    

Description Andreas Sturmlechner gentoo-dev 2021-05-03 18:42:19 UTC
Too many really to keep track of.

See also: https://code.qt.io/cgit/qt/qtwebengine-chromium.git/log/?h=87-based&qt=range&q=3f594ea1
Comment 1 NATTkA bot gentoo-dev 2021-05-03 18:44:20 UTC Comment hidden (obsolete)
Comment 2 Larry the Git Cow gentoo-dev 2021-05-06 20:09:36 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=39f0ab3ba085648310449bdb6cf8ae9c9ffbef3a

commit 39f0ab3ba085648310449bdb6cf8ae9c9ffbef3a
Author:     Andreas Sturmlechner <asturm@gentoo.org>
AuthorDate: 2021-05-04 23:22:07 +0000
Commit:     Andreas Sturmlechner <asturm@gentoo.org>
CommitDate: 2021-05-06 20:04:04 +0000

    profiles: Unmask all the things
    
    - app-office/libreoffice-7.1.3.2
    - app-office/libreoffice-l10n-7.1.3.2
    - app-text/poppler-21.05.0
    - dev-libs/boost-1.76.0
    - dev-util/boost-build-1.76.0
    - dev-libs/icu-69.1
    - dev-libs/icu-layoutex-69.1
    - dev-qt/qtwebengine-5.15.2_p20210421
    
    Bug: https://bugs.gentoo.org/787950
    Bug: https://bugs.gentoo.org/788112
    Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org>

 profiles/package.mask | 20 --------------------
 1 file changed, 20 deletions(-)
Comment 3 NATTkA bot gentoo-dev 2021-05-06 20:16:34 UTC Comment hidden (obsolete)
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-06-01 09:00:06 UTC
x86 done
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-06-01 09:00:09 UTC
amd64 done
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-06-01 10:47:41 UTC
arm64 done

all arches done
Comment 7 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-06-02 02:23:09 UTC
Please cleanup
Comment 8 Larry the Git Cow gentoo-dev 2021-06-14 09:25:47 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=34183adb0b20533e5a61c1ab863ace6108193aa7

commit 34183adb0b20533e5a61c1ab863ace6108193aa7
Author:     Andreas Sturmlechner <asturm@gentoo.org>
AuthorDate: 2021-06-14 09:25:07 +0000
Commit:     Andreas Sturmlechner <asturm@gentoo.org>
CommitDate: 2021-06-14 09:25:36 +0000

    dev-qt/qtwebengine: 5.15.2_p20210224 security cleanup
    
    Bug: https://bugs.gentoo.org/787950
    Package-Manager: Portage-3.0.20, Repoman-3.0.3
    Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org>

 dev-qt/qtwebengine/Manifest                        |   1 -
 ...-5.15.2_p20210224-fix-crash-w-app-locales.patch | 135 ---------------
 .../qtwebengine-5.15.2_p20210224.ebuild            | 189 ---------------------
 3 files changed, 325 deletions(-)
Comment 9 NATTkA bot gentoo-dev 2021-07-22 09:36:23 UTC Comment hidden (obsolete)
Comment 10 Andreas Sturmlechner gentoo-dev 2021-07-26 18:36:07 UTC
qt proj done anyway, ping security.
Comment 11 NATTkA bot gentoo-dev 2021-07-26 18:40:26 UTC Comment hidden (obsolete)
Comment 12 NATTkA bot gentoo-dev 2021-07-29 17:22:35 UTC Comment hidden (obsolete)
Comment 13 NATTkA bot gentoo-dev 2021-07-29 17:30:51 UTC Comment hidden (obsolete)
Comment 14 NATTkA bot gentoo-dev 2021-07-29 17:38:47 UTC Comment hidden (obsolete)
Comment 15 NATTkA bot gentoo-dev 2021-07-29 17:46:57 UTC Comment hidden (obsolete)
Comment 16 NATTkA bot gentoo-dev 2021-07-29 18:02:54 UTC Comment hidden (obsolete)
Comment 17 NATTkA bot gentoo-dev 2021-07-29 18:11:13 UTC
Package list is empty or all packages have requested keywords.
Comment 18 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-14 04:59:00 UTC
GLSA request filed
Comment 19 Larry the Git Cow gentoo-dev 2022-08-14 14:34:09 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=3212eacb7aa1bccb5bf765cd0a4fb91d206ad2c5

commit 3212eacb7aa1bccb5bf765cd0a4fb91d206ad2c5
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2022-08-14 14:29:30 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2022-08-14 14:33:57 +0000

    [ GLSA 202208-25 ] Chromium, Google Chrome, Microsoft Edge, QtWebEngine: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/773040
    Bug: https://bugs.gentoo.org/787950
    Bug: https://bugs.gentoo.org/800181
    Bug: https://bugs.gentoo.org/810781
    Bug: https://bugs.gentoo.org/815397
    Bug: https://bugs.gentoo.org/828519
    Bug: https://bugs.gentoo.org/829161
    Bug: https://bugs.gentoo.org/834477
    Bug: https://bugs.gentoo.org/835397
    Bug: https://bugs.gentoo.org/835761
    Bug: https://bugs.gentoo.org/836011
    Bug: https://bugs.gentoo.org/836381
    Bug: https://bugs.gentoo.org/836777
    Bug: https://bugs.gentoo.org/836830
    Bug: https://bugs.gentoo.org/837497
    Bug: https://bugs.gentoo.org/838049
    Bug: https://bugs.gentoo.org/838433
    Bug: https://bugs.gentoo.org/838682
    Bug: https://bugs.gentoo.org/841371
    Bug: https://bugs.gentoo.org/843035
    Bug: https://bugs.gentoo.org/843728
    Bug: https://bugs.gentoo.org/847370
    Bug: https://bugs.gentoo.org/847613
    Bug: https://bugs.gentoo.org/848864
    Bug: https://bugs.gentoo.org/851003
    Bug: https://bugs.gentoo.org/851009
    Bug: https://bugs.gentoo.org/853229
    Bug: https://bugs.gentoo.org/853643
    Bug: https://bugs.gentoo.org/854372
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Sam James <sam@gentoo.org>

 glsa-202208-25.xml | 284 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 284 insertions(+)
Comment 20 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2022-08-14 14:36:04 UTC
GLSA done, all done.