Acknowledgement sent
to Moritz Mühlenhoff <jmm@inutil.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>.
(Fri, 15 Jul 2022 12:06:03 GMT) (full text, mbox, link).
Added tag(s) upstream.
Request was from Salvatore Bonaccorso <carnil@debian.org>
to control@bugs.debian.org.
(Fri, 15 Jul 2022 15:00:02 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>: Bug#1014966; Package src:onionshare.
(Sat, 22 Oct 2022 11:51:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>.
(Sat, 22 Oct 2022 11:51:02 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>: Bug#1014966; Package src:onionshare.
(Sat, 22 Oct 2022 12:51:06 GMT) (full text, mbox, link).
Acknowledgement sent
to Clément Hermann <clement.hermann@nodens.org>:
Extra info received and forwarded to list. Copy sent to Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>.
(Sat, 22 Oct 2022 12:51:06 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>: Bug#1014966; Package src:onionshare.
(Sat, 22 Oct 2022 13:03:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>.
(Sat, 22 Oct 2022 13:03:03 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>: Bug#1014966; Package src:onionshare.
(Sun, 23 Oct 2022 16:30:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Clément Hermann <clement.hermann@nodens.org>:
Extra info received and forwarded to list. Copy sent to Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>.
(Sun, 23 Oct 2022 16:30:03 GMT) (full text, mbox, link).
Hi,
Le 22/10/2022 à 15:01, Salvatore Bonaccorso a écrit :
> Thanks for the quick reply! (much appreciated). I think it would be
> good to get a confirmation from upstream and if possible to have
> those advisories updates. E.g.
> https://github.com/onionshare/onionshare/security/advisories/GHSA-x7wr-283h-5h2v
> while mentioning "affected versions < 2.4" the patched version remains
> "none". this might be that the < 2.4 just reflects the point in time
> when the advisory was filled. OTOH you have arguments with the v2.5
> release information that they might all be fixed.
>
> To be on safe side, explicitly confirming by upstream would be great.
Agreed. And asked upstream:
https://github.com/onionshare/onionshare/issues/1633.
Cheers,
--
nodens
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>: Bug#1014966; Package src:onionshare.
(Sun, 23 Oct 2022 18:45:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>.
(Sun, 23 Oct 2022 18:45:03 GMT) (full text, mbox, link).
Hi Clément,
On Sun, Oct 23, 2022 at 06:27:08PM +0200, Clément Hermann wrote:
> Hi,
>
> Le 22/10/2022 à 15:01, Salvatore Bonaccorso a écrit :
>
> > Thanks for the quick reply! (much appreciated). I think it would be
> > good to get a confirmation from upstream and if possible to have
> > those advisories updates. E.g.
> > https://github.com/onionshare/onionshare/security/advisories/GHSA-x7wr-283h-5h2v
> > while mentioning "affected versions < 2.4" the patched version remains
> > "none". this might be that the < 2.4 just reflects the point in time
> > when the advisory was filled. OTOH you have arguments with the v2.5
> > release information that they might all be fixed.
> >
> > To be on safe side, explicitly confirming by upstream would be great.
>
> Agreed. And asked upstream:
> https://github.com/onionshare/onionshare/issues/1633.
Thank you!
Regards,
Salvatore
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>: Bug#1014966; Package src:onionshare.
(Mon, 24 Oct 2022 16:33:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Clément Hermann <clement.hermann@nodens.org>, 1014966@bugs.debian.org:
Extra info received and forwarded to list. Copy sent to Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>.
(Mon, 24 Oct 2022 16:33:03 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>: Bug#1014966; Package src:onionshare.
(Mon, 24 Oct 2022 18:45:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Clément Hermann <clement.hermann@nodens.org>, 1014966@bugs.debian.org:
Extra info received and forwarded to list. Copy sent to Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>.
(Mon, 24 Oct 2022 18:45:03 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>: Bug#1014966; Package src:onionshare.
(Tue, 25 Oct 2022 07:06:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Clément Hermann <clement.hermann@nodens.org>, 1014966@bugs.debian.org, 1014966@bugs.debian.org:
Extra info received and forwarded to list. Copy sent to Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>.
(Tue, 25 Oct 2022 07:06:02 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>: Bug#1014966; Package src:onionshare.
(Tue, 25 Oct 2022 09:18:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Moritz Muehlenhoff <jmm@inutil.org>:
Extra info received and forwarded to list. Copy sent to Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>.
(Tue, 25 Oct 2022 09:18:03 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>: Bug#1014966; Package src:onionshare.
(Tue, 25 Oct 2022 11:57:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Clément Hermann <nodens@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>.
(Tue, 25 Oct 2022 11:57:02 GMT) (full text, mbox, link).
Hi Moritz,
Le 25/10/2022 à 11:15, Moritz Muehlenhoff a écrit :
> Hi Clément,
>
>> Sadly, upstream rectified and confirms it affects 2.2 [0], and has been
>> tested and reproduced on Bullseye. We do need to fix it. Upstream has a few
>> suggestions, but I guess our choices are either uploading 2.5 to stable, if
>> that's possible. python-stem at least will need to be updated as well, from
>> 1.8.0 to 1.8.1 which luckily is bugfix only.
> With the upstream confirmation about affected states I had a look at the remaining
> issues affecting Bullseye:
Thanks!
> CVE-2022-21694 (https://github.com/onionshare/onionshare/security/advisories/GHSA-h29c-wcm8-883h)
> is not a vulnerability by itself, it's a lack of a feature at most. We can ignore it for
> Bullseye.
Agreed, that's my reasoning too.
> CVE-2022-21688 (https://github.com/onionshare/onionshare/security/advisories/GHSA-x7wr-283h-5h2v)
> is just a stop gap, the actual issue is in QT and I'll reach out to upstream for more information
> when this was fixed in QT so that it can be backported to Bullseye's QT packages.
Agreed. The fix for CVE-2022-21690 will provide a workaround as well.
> This leaves:
> https://security-tracker.debian.org/tracker/CVE-2022-21690
> https://security-tracker.debian.org/tracker/CVE-2022-21689
> https://security-tracker.debian.org/tracker/CVE-2021-41868
>
> I think it's fair to ignore CVE-2021-41868 for Bullseye, it sounds like an edge case
> and invasive to fix.
I'm not sure how much of an edge case it is. But I agree it's fair. We
could provide a backport for users needing secure authentication, so
they could use onion v3 auth for this usage (I didn't check yet how easy
a backport would be, but I expect it'd be simple except maybe for the
poetry build system part).
>
> This leaves CVE-2022-21690 and CVE-2022-21689 which have isolated patches which could be backported?
Yes.
> Given that the primary use case for onionshare will be tails, my suggestion would be that CVE-2022-21689
> and CVE-2022-21690 get backported fixes for the next Bullseye point release (which Tails will sync up
> to). What do you think?
There are some users of onionshare beside in Tails, but that sounds like
a viable plan.
Cheers,
--
nodens
Marked as fixed in versions onionshare/2.5-1.
Request was from Clément Hermann <nodens@debian.org>
to control@bugs.debian.org.
(Sun, 13 Nov 2022 13:54:07 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>: Bug#1014966; Package src:onionshare.
(Sun, 27 Nov 2022 10:48:05 GMT) (full text, mbox, link).
Acknowledgement sent
to 1014966@bugs.debian.org:
Extra info received and forwarded to list. Copy sent to Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>.
(Sun, 27 Nov 2022 10:48:05 GMT) (full text, mbox, link).
Hi
Le 25/10/2022 à 13:53, Clément Hermann a écrit :
> Hi Moritz,
>
> Le 25/10/2022 à 11:15, Moritz Muehlenhoff a écrit :
>
>> Given that the primary use case for onionshare will be tails, my
>> suggestion would be that CVE-2022-21689
>> and CVE-2022-21690 get backported fixes for the next Bullseye point
>> release (which Tails will sync up
>> to). What do you think?
>
> There are some users of onionshare beside in Tails, but that sounds
> like a viable plan.
>
FYI, backported fixes have been uploaded and should be included in next
point release (#1023981)
Cheers,
--
nodens
Marked as fixed in versions onionshare/2.2-3+deb11u1.
Request was from Clément Hermann <nodens@debian.org>
to control@bugs.debian.org.
(Sun, 27 Nov 2022 10:48:07 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>: Bug#1014966; Package src:onionshare.
(Sun, 27 Nov 2022 16:15:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Moritz Mühlenhoff <jmm@inutil.org>:
Extra info received and forwarded to list. Copy sent to Debian Privacy Tools Maintainers <pkg-privacy-maintainers@lists.alioth.debian.org>.
(Sun, 27 Nov 2022 16:15:03 GMT) (full text, mbox, link).
Am Sun, Nov 27, 2022 at 11:45:27AM +0100 schrieb Clément Hermann:
> Hi
>
> Le 25/10/2022 à 13:53, Clément Hermann a écrit :
> > Hi Moritz,
> >
> > Le 25/10/2022 à 11:15, Moritz Muehlenhoff a écrit :
> >
> > > Given that the primary use case for onionshare will be tails, my
> > > suggestion would be that CVE-2022-21689
> > > and CVE-2022-21690 get backported fixes for the next Bullseye point
> > > release (which Tails will sync up
> > > to). What do you think?
> >
> > There are some users of onionshare beside in Tails, but that sounds like
> > a viable plan.
> >
> FYI, backported fixes have been uploaded and should be included in next
> point release (#1023981)
Saw that, thanks!
Cheers,
Moritz
Reply sent
to Paul Gevers <elbrus@debian.org>:
You have taken responsibility.
(Sat, 12 Oct 2024 15:21:02 GMT) (full text, mbox, link).
Notification sent
to Moritz Mühlenhoff <jmm@inutil.org>:
Bug acknowledged by developer.
(Sat, 12 Oct 2024 15:21:02 GMT) (full text, mbox, link).
Hi,
On Sun, 27 Nov 2022 11:45:27 +0100 =?UTF-8?Q?Cl=c3=a9ment_Hermann?=
<nodens@debian.org> wrote:
> FYI, backported fixes have been uploaded and should be included in next
> point release (#1023981)
And this happened long time ago, so let's close this bug. (The BTS
already knows it doesn't apply to stable, testing or unstable for a while).
Paul
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.