Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 843008 - <games-arcade/supertux-0.6.3-r2: squirrel: multiple vulnerabilities
Summary: <games-arcade/supertux-0.6.3-r2: squirrel: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ?? [noglsa]
Keywords:
Depends on:
Blocks: CVE-2021-41556, CVE-2022-30292
  Show dependency tree
 
Reported: 2022-05-06 12:58 UTC by Pacho Ramos
Modified: 2022-12-10 17:55 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-05-07 15:01:44 UTC
Thanks! If supertux is bundling squirrel, we should also try to unbundle it.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-10-26 21:34:50 UTC
Thanks for taking upstream. Any idea about impact?
Comment 3 Larry the Git Cow gentoo-dev 2022-12-04 14:50:47 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=866ce00a7cae59ca2c77650addabc3128127ecb8

commit 866ce00a7cae59ca2c77650addabc3128127ecb8
Author:     Pacho Ramos <pacho@gentoo.org>
AuthorDate: 2022-12-04 14:47:55 +0000
Commit:     Pacho Ramos <pacho@gentoo.org>
CommitDate: 2022-12-04 14:49:22 +0000

    games-arcade/supertux: Fix CVE-2022-30292
    
    For 0.6.3 we need to patch the bundled squirrel copy, in next upstream
    versions it should be possible to finally build it against system copy.
    
    Bug: https://bugs.gentoo.org/843008
    Signed-off-by: Pacho Ramos <pacho@gentoo.org>

 .../supertux-0.6.3-squirrel-CVE-2022-30292.patch   | 21 ++++++++
 games-arcade/supertux/supertux-0.6.3-r1.ebuild     | 63 ++++++++++++++++++++++
 2 files changed, 84 insertions(+)
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-12-04 19:28:03 UTC
What of CVE-2021-41556?
Comment 5 Pacho Ramos gentoo-dev 2022-12-04 20:52:36 UTC
I don't know why they didn't fix it in Fedora:
https://bugzilla.redhat.com/show_bug.cgi?id=2112798

I will try to backport it too
Comment 6 Larry the Git Cow gentoo-dev 2022-12-04 21:23:36 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6975aded48ce0b855445ead7203905795daee608

commit 6975aded48ce0b855445ead7203905795daee608
Author:     Pacho Ramos <pacho@gentoo.org>
AuthorDate: 2022-12-04 21:16:56 +0000
Commit:     Pacho Ramos <pacho@gentoo.org>
CommitDate: 2022-12-04 21:23:20 +0000

    games-arcade/supertux: Fix CVE-2021-41556
    
    Bug: https://bugs.gentoo.org/843008
    Signed-off-by: Pacho Ramos <pacho@gentoo.org>

 .../supertux-0.6.3-squirrel-CVE-2021-41556.patch   | 36 ++++++++++++
 games-arcade/supertux/supertux-0.6.3-r2.ebuild     | 64 ++++++++++++++++++++++
 2 files changed, 100 insertions(+)
Comment 7 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-12-04 22:20:16 UTC
Thanks! Please cleanup when ready
Comment 8 Larry the Git Cow gentoo-dev 2022-12-10 15:11:53 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6f5bed3ec8d0b10218ba7b8257c73fd30769faa5

commit 6f5bed3ec8d0b10218ba7b8257c73fd30769faa5
Author:     Pacho Ramos <pacho@gentoo.org>
AuthorDate: 2022-12-10 15:06:24 +0000
Commit:     Pacho Ramos <pacho@gentoo.org>
CommitDate: 2022-12-10 15:09:28 +0000

    games-arcade/supertux: drop 0.6.3
    
    Bug: https://bugs.gentoo.org/843008
    Signed-off-by: Pacho Ramos <pacho@gentoo.org>

 games-arcade/supertux/supertux-0.6.3.ebuild | 62 -----------------------------
 1 file changed, 62 deletions(-)
Comment 9 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-12-10 17:55:19 UTC
Ah, right, no stable versions. All done, thanks!