Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 794841 (CVE-2021-33896)

Summary: <net-im/dino-0.2.1: Path traversal in file transfers (CVE-2021-33896)
Product: Gentoo Security Reporter: Andriy Utkin (RETIRED) <andrey_utkin>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: IN_PROGRESS ---    
Severity: minor CC: andrey_utkin, sam
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://dino.im/security/cve-2021-33896/
Whiteboard: B3 [glsa?]
Package list:
net-im/dino-0.2.1
Runtime testing required: ---

Description Andriy Utkin (RETIRED) gentoo-dev 2021-06-07 21:59:23 UTC
Dino has just sent out a security advisory.
https://dino.im/security/cve-2021-33896/

I have successfully built and am running 0.2.1 now.
v0.2 branch is clearly maintained well in a conservative manner, so I trust this may go to stable immediately.
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-06-07 23:09:47 UTC
amd64 done
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-06-08 04:03:23 UTC
arm64 done

all arches done
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-06-08 04:14:44 UTC
Please cleanup, thanks!
Comment 4 Larry the Git Cow gentoo-dev 2021-07-24 06:22:17 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ba60cb08a283cde422ddb503900da68b979bc5c5

commit ba60cb08a283cde422ddb503900da68b979bc5c5
Author:     John Helmert III <ajak@gentoo.org>
AuthorDate: 2021-07-24 06:16:46 +0000
Commit:     John Helmert III <ajak@gentoo.org>
CommitDate: 2021-07-24 06:21:45 +0000

    net-im/dino: drop 0.2.0
    
    Bug: https://bugs.gentoo.org/794841
    Signed-off-by: John Helmert III <ajak@gentoo.org>

 net-im/dino/Manifest          |  1 -
 net-im/dino/dino-0.2.0.ebuild | 92 -------------------------------------------
 2 files changed, 93 deletions(-)
Comment 5 NATTkA bot gentoo-dev 2022-02-16 21:28:52 UTC
Unable to check for sanity:

> no match for package: net-im/dino-0.2.1