Summary: | <dev-qt/qtcore-5.15.3: QProcess path vulnerability | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | IN_PROGRESS --- | ||
Severity: | minor | CC: | qt |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
See Also: | https://invent.kde.org/qt/qt/qtbase/-/merge_requests/115 | ||
Whiteboard: | B3 [glsa?] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 835762 | ||
Bug Blocks: |
Description
Sam James
![]() ![]() ![]() ![]() KDE are currently waiting for upstream if they will fix the tests broken by this change. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e2f59199cbeb3897bb3089895b65c2a7f7d0a8c7 commit e2f59199cbeb3897bb3089895b65c2a7f7d0a8c7 Author: Ionen Wolkens <ionen@gentoo.org> AuthorDate: 2022-04-01 17:20:45 +0000 Commit: Ionen Wolkens <ionen@gentoo.org> CommitDate: 2022-04-01 17:46:36 +0000 www-client/qutebrowser: add 2.5.0 This includes a workaround for CVE-2022-25255 wrt bug #833583 Bug: https://bugs.gentoo.org/833583 Signed-off-by: Ionen Wolkens <ionen@gentoo.org> www-client/qutebrowser/Manifest | 1 + www-client/qutebrowser/qutebrowser-2.5.0.ebuild | 122 ++++++++++++++++++++++++ 2 files changed, 123 insertions(+) Cleanup done in commit 2e7a463a4c38e186585f1721fe20e99b304a3f95 then. |