Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 635636 - net-im/qtox: version bump (security fix)
Summary: net-im/qtox: version bump (security fix)
Status: RESOLVED NEEDINFO
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All All
: Normal normal
Assignee: Gentoo Security
URL: https://github.com/qTox/qTox/releases
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-10-27 21:52 UTC by Jaak Ristioja
Modified: 2018-11-30 00:24 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jaak Ristioja 2017-10-27 21:52:56 UTC
Version 1.12.1 is out. Please bump.
Comment 1 Enne Eziarc 2017-11-25 23:44:23 UTC
I noticed by chance that 1.13 is out as of a few hours ago.

The dependency list changed since 1.11: qtsql is gone, libexif was added. The -9999 ebuild also needs unbitrotting due to these; it hasn't worked for months.
Comment 2 Andrius Štikonas 2018-03-21 14:58:37 UTC
(In reply to Anthony Parsons from comment #1)
> I noticed by chance that 1.13 is out as of a few hours ago.
> 

Now 1.14 is out too.
Comment 3 Jaak Ristioja 2018-04-21 09:39:54 UTC
Version 1.15.0 is out. Please bump.
Comment 4 Andrius Štikonas 2018-04-22 09:14:17 UTC
(In reply to Jaak Ristioja from comment #3)
> Version 1.15.0 is out. Please bump.

Older <net-libs/tox-0.2.2 versions have security vulnerability (IP address leak)

https://blog.tox.chat/2018/04/security-vulnerability-and-new-toxcore-release/

Should we add security team to this bug?
Comment 5 Larry the Git Cow gentoo-dev 2018-08-12 16:58:18 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2b3880f361217486bc16187109f5bd6c71562909

commit 2b3880f361217486bc16187109f5bd6c71562909
Author:     François-Xavier Carton <fx.carton91@gmail.com>
AuthorDate: 2018-07-11 03:11:50 +0000
Commit:     Michał Górny <mgorny@gentoo.org>
CommitDate: 2018-08-12 16:58:12 +0000

    net-im/qtox: version bump to 1.16.3
    
    Bug: https://bugs.gentoo.org/635636
    Package-Manager: Portage-2.3.40, Repoman-2.3.9

 net-im/qtox/Manifest           |  1 +
 net-im/qtox/metadata.xml       |  2 +-
 net-im/qtox/qtox-1.16.3.ebuild | 76 ++++++++++++++++++++++++++++++++++++++++++
 net-im/qtox/qtox-9999.ebuild   | 30 ++++++++---------
 4 files changed, 91 insertions(+), 18 deletions(-)
Comment 6 Andrius Štikonas 2018-08-12 19:13:38 UTC
I believe this is now fixed. Can we close this bug?

tox was not stable anyway, so I think we don't need to keep it open for security team.
Comment 7 Pacho Ramos gentoo-dev 2018-09-15 13:30:55 UTC
master 9548b5503507] net-im/qtox: Drop old
 3 files changed, 1 insertion(+), 151 deletions(-)
 rewrite net-im/qtox/Manifest (66%)
 delete mode 100644 net-im/qtox/qtox-1.11.0.ebuild
 delete mode 100644 net-im/qtox/qtox-1.8.1.ebuild