Summary: | <app-text/calibre-7.16.0: various exploits against the content server | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Eli Schwartz <eschwartz> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | eschwartz, zmedico |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
See Also: |
https://launchpad.net/bugs/2075130 https://launchpad.net/bugs/2075131 https://launchpad.net/bugs/2075125 https://launchpad.net/bugs/2075128 |
||
Whiteboard: | C1 [glsa+] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 936963, 936964 | ||
Bug Blocks: |
Description
Eli Schwartz
2024-07-31 03:43:01 UTC
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=34c67cbd5d13469221f14e46981a8e6a91fb2068 commit 34c67cbd5d13469221f14e46981a8e6a91fb2068 Author: Eli Schwartz <eschwartz@gentoo.org> AuthorDate: 2024-07-31 03:49:37 +0000 Commit: Eli Schwartz <eschwartz@gentoo.org> CommitDate: 2024-07-31 03:51:38 +0000 app-text/calibre: backport fix for CVE-2024-7008 to 5.44 Although 4 CVEs were fixed in 7.16.0, only one of them (relatively minor) is present in 5.x. Bug: https://bugs.gentoo.org/936961 Signed-off-by: Eli Schwartz <eschwartz@gentoo.org> ...e-5.44.0-r4.ebuild => calibre-5.44.0-r5.ebuild} | 2 ++ .../files/calibre-5.44.0-xss-backport.patch | 33 ++++++++++++++++++++++ 2 files changed, 35 insertions(+) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d31278435e4ad4d009120729d694cf3d06653e34 commit d31278435e4ad4d009120729d694cf3d06653e34 Author: Eli Schwartz <eschwartz@gentoo.org> AuthorDate: 2024-07-31 03:35:06 +0000 Commit: Eli Schwartz <eschwartz@gentoo.org> CommitDate: 2024-07-31 03:51:37 +0000 app-text/calibre: add 7.16.0 Bug: https://bugs.gentoo.org/936961 Signed-off-by: Eli Schwartz <eschwartz@gentoo.org> app-text/calibre/Manifest | 2 + app-text/calibre/calibre-7.16.0.ebuild | 243 +++++++++++++++++++++++++++++++++ 2 files changed, 245 insertions(+) The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=dd95a78b278fdb5caf1e1bd86d9c4cd72a1e56d8 commit dd95a78b278fdb5caf1e1bd86d9c4cd72a1e56d8 Author: Eli Schwartz <eschwartz@gentoo.org> AuthorDate: 2024-08-14 22:22:46 +0000 Commit: Eli Schwartz <eschwartz@gentoo.org> CommitDate: 2024-08-16 01:12:37 +0000 app-text/calibre: drop old for security cleanup Bug: https://bugs.gentoo.org/936961 Signed-off-by: Eli Schwartz <eschwartz@gentoo.org> app-text/calibre/Manifest | 2 - app-text/calibre/calibre-5.44.0-r3.ebuild | 273 ------------------------------ app-text/calibre/calibre-7.13.0.ebuild | 243 -------------------------- 3 files changed, 518 deletions(-) The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=f7ca4470b0c876ba704ac6e0ddc1bb84ecfdac31 commit f7ca4470b0c876ba704ac6e0ddc1bb84ecfdac31 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-09-22 05:54:09 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2024-09-22 05:54:22 +0000 [ GLSA 202409-04 ] calibre: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/918429 Bug: https://bugs.gentoo.org/936961 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202409-04.xml | 47 +++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) |