Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 601994 - <sys-apps/firejail-0.9.44.2, <sys-apps/firejail-lts-0.9.38.6: multiple vulnerabilities
Summary: <sys-apps/firejail-0.9.44.2, <sys-apps/firejail-lts-0.9.38.6: multiple vulner...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://firejail.wordpress.com/downlo...
Whiteboard: B2 [glsa cleanup]
Keywords: STABLEREQ
Depends on:
Blocks:
 
Reported: 2016-12-08 14:55 UTC by jamesrutledge
Modified: 2016-12-27 00:43 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description jamesrutledge 2016-12-08 14:55:54 UTC
sys-apps/firejail version 0.9.44.2 is now available at https://firejail.wordpress.com/

Quote from News at above website:
December 2016 – released Firejail 0.9.44.2 (Download). This is a maintenance and security release for version 0.9.44. We strongly encourage you to update the software.
Comment 1 Jonas Stein gentoo-dev 2016-12-08 15:47:02 UTC
is it correct, that we have old versions without fix for the CVE in the tree?
Comment 3 Amadeusz Żołnowski (RETIRED) gentoo-dev 2016-12-08 20:39:49 UTC
0.9.44.2 has been submitted.
Comment 4 Amadeusz Żołnowski (RETIRED) gentoo-dev 2016-12-08 20:43:11 UTC
Please stabilize.
Comment 5 Amadeusz Żołnowski (RETIRED) gentoo-dev 2016-12-08 20:44:03 UTC
I will remove 0.9.38.2 as soon as 0.9.38.4 is stabilized as well.
Comment 6 Agostino Sarubbo gentoo-dev 2016-12-13 11:07:01 UTC
amd64 stable.

Maintainer(s), please cleanup.
Security, please add it to the existing request, or file a new one.
Comment 7 Aaron Bauman (RETIRED) gentoo-dev 2016-12-13 12:06:29 UTC
GLSA requested.
Comment 8 Amadeusz Żołnowski (RETIRED) gentoo-dev 2016-12-15 20:40:11 UTC
Quoting netblue30 (firejail developer) about 0.9.38:

> The security problems fixed in 0.9.44.2 don't affect 0.9.38. They've
> been introduced introduced after 0.9.38 release. However, I do have some
> bug fixes, small things like vlc crashing and security improvements
> coming. Also, I started backporting some new security features. I hope
> to have the next LTS release out in early January.

I have bumped 0.9.42.2 and removed 0.9.42. There's no vulnerable version in the tree. 0.9.38.4 LTS is in the tree with ~amd64 keyword. I will reopen bug 602034 to stabilize LTS version as well, but it's not related to this bug any more.
Comment 9 Amadeusz Żołnowski (RETIRED) gentoo-dev 2016-12-15 21:29:18 UTC
It appears upstream might have forgotten about one fix. I have backported <https://github.com/netblue30/firejail/commit/4f4e59c7529888339fe2337dc893984eb7833d01> in 0.9.38.4-r1.
Comment 10 Aaron Bauman (RETIRED) gentoo-dev 2016-12-15 22:20:31 UTC
(In reply to Amadeusz Żołnowski from comment #9)
> It appears upstream might have forgotten about one fix. I have backported
> <https://github.com/netblue30/firejail/commit/
> 4f4e59c7529888339fe2337dc893984eb7833d01> in 0.9.38.4-r1.

Ready for stable?
Comment 11 Amadeusz Żołnowski (RETIRED) gentoo-dev 2016-12-16 23:08:41 UTC
Upstream said he's going to release this soon, maybe even today, so I think it's better wait for that. I'll update tomorrow.
Comment 12 Amadeusz Żołnowski (RETIRED) gentoo-dev 2016-12-18 11:17:25 UTC
Upstream has released 0.9.38.6 with the security fix. I have split firejail into sys-apps/firejail-lts and sys-apps/firejail (bleeding-edge). Please stabilize sys-apps/firejail-0.9.38.6.
Comment 13 Amadeusz Żołnowski (RETIRED) gentoo-dev 2016-12-18 11:18:28 UTC
Please stabilize sys-apps/firejail-lts-0.9.38.6, not sys-apps/firejail-0.9.38.6. Sorry.
Comment 14 Tobias Klausmann (RETIRED) gentoo-dev 2016-12-21 18:56:30 UTC
Stable on amd64.
Comment 15 GLSAMaker/CVETool Bot gentoo-dev 2016-12-27 00:43:49 UTC
This issue was resolved and addressed in
 GLSA 201612-48 at https://security.gentoo.org/glsa/201612-48
by GLSA coordinator Aaron Bauman (b-man).