Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 917652 (MMSA-2023-00249, MMSA-2023-00251, MMSA-2023-00255) - <net-im/mattermost-desktop-bin-5.5.1: multiple vulnerabilities
Summary: <net-im/mattermost-desktop-bin-5.5.1: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: MMSA-2023-00249, MMSA-2023-00251, MMSA-2023-00255
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks: CVE-2023-4863, CVE-2023-5129
  Show dependency tree
 
Reported: 2023-11-21 01:35 UTC by John Helmert III
Modified: 2023-11-21 01:36 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-11-21 01:35:26 UTC
MMSA-2023-00255:

(CWE-400) Fixed an issue where a RegExp was being built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service. Thanks to DoyenSec for contributing to this improvement under the Mattermost responsible disclosure policy.

MMSA-2023-00251:

(CWE-693) Fixed an issue where the application was not correctly handling permissions, or prompting the user for certain sensitive ones. Thanks to DoyenSec for contributing to this improvement under the Mattermost responsible disclosure policy.

MMSA-2023-00249:

(CWE-200) Fixed an issue where the application was not utilizing the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input. Thanks to DoyenSec for contributing to this improvement under the Mattermost responsible disclosure policy.

Plus one more that isn't tracked with an MMSA identifier which we're presumably vulnerable to due to our packaging of the binary:

"Mitigated the vulnerability CVE-2023-4863 of the third-party library libwebp by updating to Electron v26.2.1."
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-11-21 01:36:18 UTC
And we're already cleaned up so all done!