Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 608962 (CVE-2017-5593) - kde-apps/kopete-16.12.2: User Impersonation Vulnerability in Jabber protocol
Summary: kde-apps/kopete-16.12.2: User Impersonation Vulnerability in Jabber protocol
Status: RESOLVED FIXED
Alias: CVE-2017-5593
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugs.kde.org/show_bug.cgi?id=...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-02-11 14:16 UTC by Johannes Huber (RETIRED)
Modified: 2020-04-17 03:46 UTC (History)
0 users

See Also:
Package list:
=kde-apps/kopete-16.12.2-r2
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Huber (RETIRED) gentoo-dev 2017-02-11 14:16:10 UTC
According to upstream bug report:

Pali Rohár 2017-02-11 12:21:58 UTC
Kopete since 16.11.80 is vulnerable for CVE 2017-5593 (User Impersonation Vulnerability) as it uses same XMPP library as Psi (libiris).

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5593
http://seclists.org/oss-sec/2017/q1/373

Fix for libiris:
https://github.com/psi-im/iris/pull/47/commits/02e976d4426a1319a7af7d26d7aba9d8c6077570
Comment 2 Kristian Fiskerstrand (RETIRED) gentoo-dev 2017-02-11 14:20:27 UTC
Thank you for report. 

Issue does not affect versions that have been in stable, as such does not require stabilisation and GLSA will not be issued. The bug can be closed after CVE is assigned in CVETool and whiteboard contains cve tag
Comment 3 Andreas Sturmlechner gentoo-dev 2017-02-11 15:41:58 UTC
16.12.0 is stable and affected, which means 16.12.2-r1 should get stabilised.
Comment 4 Johannes Huber (RETIRED) gentoo-dev 2017-02-11 19:43:37 UTC
Arches please stabilize =kde-apps/kopete-16.12.2-r1. Thanks in advance.

Target: amd64 x86
Comment 5 Stabilization helper bot gentoo-dev 2017-02-11 20:00:31 UTC
An automated check of this bug failed - the following atom is unknown:

kde-apps/kopete-16.12.2-r1

Please verify the atom list.
Comment 6 Stabilization helper bot gentoo-dev 2017-02-12 01:00:28 UTC
An automated check of this bug failed - the following atom is unknown:

kde-apps/kopete-16.12.2-r1

Please verify the atom list.
Comment 7 Stabilization helper bot gentoo-dev 2017-02-12 02:00:45 UTC
An automated check of this bug succeeded - the previous repoman errors are now resolved.
Comment 8 Agostino Sarubbo gentoo-dev 2017-02-12 14:50:12 UTC
amd64 stable
Comment 9 Agostino Sarubbo gentoo-dev 2017-02-12 15:49:34 UTC
x86 stable.

Maintainer(s), please cleanup.
Comment 10 Johannes Huber (RETIRED) gentoo-dev 2017-02-12 15:53:20 UTC
Last vulnerable version removed.

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1b8e68319d85f680bdc02706c57c3fc41132609d
Comment 11 Thomas Deutschmann (RETIRED) gentoo-dev 2017-02-13 02:13:04 UTC
GLSA Vote: No

Repository is clean, all done.