Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 914926

Summary: <net-im/element-desktop-bin-1.11.45: remote code execution by sending a video
Product: Gentoo Security Reporter: tastytea <gentoo>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: critical CC: steils
Priority: Normal Keywords: PullRequest
Version: unspecified   
Hardware: All   
OS: Linux   
See Also: https://github.com/gentoo/gentoo/pull/33134
Whiteboard: ~2 [noglsa]
Package list:
Runtime testing required: ---
Bug Depends on: 915002    
Bug Blocks: 914874    

Comment 1 Larry the Git Cow gentoo-dev 2023-10-01 07:47:35 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=eea4ae7434b42a133fb4047f13703d4a9bbbefbe

commit eea4ae7434b42a133fb4047f13703d4a9bbbefbe
Author:     tastytea <gentoo@tastytea.de>
AuthorDate: 2023-09-30 10:47:38 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-10-01 07:43:09 +0000

    net-im/element-desktop-bin: add 1.11.45
    
    Bug: https://bugs.gentoo.org/914926
    Closes: https://bugs.gentoo.org/910067
    Closes: https://github.com/gentoo/gentoo/pull/31805
    Signed-off-by: tastytea <gentoo@tastytea.de>
    Closes: https://github.com/gentoo/gentoo/pull/33134
    Signed-off-by: Sam James <sam@gentoo.org>

 net-im/element-desktop-bin/Manifest                |  1 +
 .../element-desktop-bin-1.11.45.ebuild             | 83 ++++++++++++++++++++++
 2 files changed, 84 insertions(+)
Comment 2 Hans de Graaff gentoo-dev Security 2023-12-02 09:11:20 UTC
As far as I can tell this package never had any stable version. Adjusting whiteboard accordingly.
Comment 3 Hans de Graaff gentoo-dev Security 2023-12-17 10:50:37 UTC
commit a653ac02479f3f5fead931f2458c1e748d10ca7b
Author: Stefan Strogin <steils@gentoo.org>
Date:   Tue Dec 5 05:38:41 2023 +0200

    net-im/element-desktop-bin: drop 1.11.39, 1.11.45
    
    Signed-off-by: Stefan Strogin <steils@gentoo.org>