Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 662978 - <net-im/mattermost-desktop-bin-4.2.3: security version bump
Summary: <net-im/mattermost-desktop-bin-4.2.3: security version bump
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL:
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2018-08-06 19:54 UTC by Leho Kraav (:macmaN @lkraav)
Modified: 2019-08-12 22:45 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Leho Kraav (:macmaN @lkraav) 2018-08-06 19:54:26 UTC
As seen at https://github.com/mattermost/desktop/releases/tag/v4.1.2
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2019-05-23 19:26:15 UTC
Ping.  What's the progress?
Comment 2 Leho Kraav (:macmaN @lkraav) 2019-05-23 22:53:44 UTC
There's actually a well working source ebuild at https://gitlab.com/chaoslab/chaoslab-overlay/tree/master/net-im/mattermost-desktop also, if someone's up for adopting it.

@ianmoone seems to have dropped off the radar for a couple of months, I hope he's OK.
Comment 3 Leho Kraav (:macmaN @lkraav) 2019-08-07 19:07:00 UTC
This is now a security issue I think https://github.com/mattermost/desktop/releases/tag/v4.2.2
Comment 4 Mart Raudsepp gentoo-dev 2019-08-11 08:03:28 UTC
Looks like 4.2.2 wasn't announced with a full description or something, but shows up as a simple tag in https://github.com/mattermost/desktop/releases/
There is a 4.2.3 now that details security affect.
Converting to a security bug, albeit this is precompiled source with security details withheld for 30 days.
Comment 5 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2019-08-11 08:13:29 UTC
Proxied maintainer retired.  @monsieurp, now you're the primary maintainer.
Comment 6 Larry the Git Cow gentoo-dev 2019-08-11 08:51:42 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f96f304103ad89cbc4e1529a1b1c068eabbfa1f7

commit f96f304103ad89cbc4e1529a1b1c068eabbfa1f7
Author:     Patrice Clement <monsieurp@gentoo.org>
AuthorDate: 2019-08-11 08:50:54 +0000
Commit:     Patrice Clement <monsieurp@gentoo.org>
CommitDate: 2019-08-11 08:50:54 +0000

    net-im/mattermost-desktop-bin: drop maintainership.
    
    Bug: https://bugs.gentoo.org/662978
    Signed-off-by: Patrice Clement <monsieurp@gentoo.org>
    Package-Manager: Portage-2.3.62, Repoman-2.3.11

 net-im/mattermost-desktop-bin/metadata.xml | 5 +----
 1 file changed, 1 insertion(+), 4 deletions(-)
Comment 7 Patrice Clement (RETIRED) gentoo-dev 2019-08-11 08:52:33 UTC
(In reply to Michał Górny from comment #5)
> Proxied maintainer retired.  @monsieurp, now you're the primary maintainer.

Not anymore.
Comment 8 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2019-08-11 09:24:34 UTC
(In reply to Patrice Clement from comment #7)
> (In reply to Michał Górny from comment #5)
> > Proxied maintainer retired.  @monsieurp, now you're the primary maintainer.
> 
> Not anymore.

Where is the 'up for grabs' mail?
Comment 9 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2019-08-11 18:53:25 UTC
I bumped it, but should not be considered the maintainer
Comment 10 Larry the Git Cow gentoo-dev 2019-08-11 18:53:37 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=55a5981b722635a755ce9ea012666a735cddc4ff

commit 55a5981b722635a755ce9ea012666a735cddc4ff
Author:     Matthew Thode <prometheanfire@gentoo.org>
AuthorDate: 2019-08-11 18:53:16 +0000
Commit:     Matthew Thode <prometheanfire@gentoo.org>
CommitDate: 2019-08-11 18:53:32 +0000

    net-im/mattermost-desktop-bin: 4.0.0 removal
    
    Bug: https://bugs.gentoo.org/662978
    Package-Manager: Portage-2.3.69, Repoman-2.3.17
    Signed-off-by: Matthew Thode <prometheanfire@gentoo.org>

 net-im/mattermost-desktop-bin/Manifest             |  3 -
 .../mattermost-desktop-bin-4.0.0.ebuild            | 89 ----------------------
 2 files changed, 92 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=db390b19d8a74991ac44c81b8c900fac528aed61

commit db390b19d8a74991ac44c81b8c900fac528aed61
Author:     Matthew Thode <prometheanfire@gentoo.org>
AuthorDate: 2019-08-11 18:52:43 +0000
Commit:     Matthew Thode <prometheanfire@gentoo.org>
CommitDate: 2019-08-11 18:53:31 +0000

    net-im/mattermost-desktop-bin: 4.2.3 bump
    
    Bug: https://bugs.gentoo.org/662978
    Package-Manager: Portage-2.3.69, Repoman-2.3.17
    Signed-off-by: Matthew Thode <prometheanfire@gentoo.org>

 net-im/mattermost-desktop-bin/Manifest             |  3 +
 .../mattermost-desktop-bin-4.2.3.ebuild            | 93 ++++++++++++++++++++++
 2 files changed, 96 insertions(+)
Comment 11 Mart Raudsepp gentoo-dev 2019-08-12 05:03:19 UTC
I missed that this wasn't a stable package. So perhaps I shouldn't have bothered with the security@ loop?
Comment 12 Aaron Bauman (RETIRED) gentoo-dev 2019-08-12 22:44:51 UTC
(In reply to Mart Raudsepp from comment #11)
> I missed that this wasn't a stable package. So perhaps I shouldn't have
> bothered with the security@ loop?

Mart, we can still track it for cleanup etc. It just will not receive a GLSA.

Overall, meh. No CVE references upstream. etc.

Tree is clean.