Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 794841 (CVE-2021-33896) - <net-im/dino-0.2.1: Path traversal in file transfers (CVE-2021-33896)
Summary: <net-im/dino-0.2.1: Path traversal in file transfers (CVE-2021-33896)
Status: IN_PROGRESS
Alias: CVE-2021-33896
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL: https://dino.im/security/cve-2021-33896/
Whiteboard: B3 [glsa?]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-06-07 21:59 UTC by Andriy Utkin (RETIRED)
Modified: 2022-06-02 22:01 UTC (History)
2 users (show)

See Also:
Package list:
net-im/dino-0.2.1
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andriy Utkin (RETIRED) gentoo-dev 2021-06-07 21:59:23 UTC
Dino has just sent out a security advisory.
https://dino.im/security/cve-2021-33896/

I have successfully built and am running 0.2.1 now.
v0.2 branch is clearly maintained well in a conservative manner, so I trust this may go to stable immediately.
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-06-07 23:09:47 UTC
amd64 done
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-06-08 04:03:23 UTC
arm64 done

all arches done
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-06-08 04:14:44 UTC
Please cleanup, thanks!
Comment 4 Larry the Git Cow gentoo-dev 2021-07-24 06:22:17 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ba60cb08a283cde422ddb503900da68b979bc5c5

commit ba60cb08a283cde422ddb503900da68b979bc5c5
Author:     John Helmert III <ajak@gentoo.org>
AuthorDate: 2021-07-24 06:16:46 +0000
Commit:     John Helmert III <ajak@gentoo.org>
CommitDate: 2021-07-24 06:21:45 +0000

    net-im/dino: drop 0.2.0
    
    Bug: https://bugs.gentoo.org/794841
    Signed-off-by: John Helmert III <ajak@gentoo.org>

 net-im/dino/Manifest          |  1 -
 net-im/dino/dino-0.2.0.ebuild | 92 -------------------------------------------
 2 files changed, 93 deletions(-)
Comment 5 NATTkA bot gentoo-dev 2022-02-16 21:28:52 UTC
Unable to check for sanity:

> no match for package: net-im/dino-0.2.1