Bug 204407 - deskutils/owncloudclient: Missing VUXML entry for CVE-2015-7298
Summary: deskutils/owncloudclient: Missing VUXML entry for CVE-2015-7298
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Guido Falsi
URL:
Keywords: security
Depends on:
Blocks:
 
Reported: 2015-11-09 20:18 UTC by Sevan Janiyan
Modified: 2015-11-13 03:25 UTC (History)
3 users (show)

See Also:
bugzilla: maintainer-feedback? (yonas)


Attachments
Update owncloudclient from 2.0.1 to 2.0.2 (7.86 KB, patch)
2015-11-11 08:15 UTC, Yonas Yanfa
no flags Details | Diff
Update owncloudclient from 2.0.1 to 2.0.2 (5.23 KB, patch)
2015-11-11 08:23 UTC, Yonas Yanfa
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Sevan Janiyan 2015-11-09 20:18:36 UTC
CVE-2015-7298 - applicable if built with qt option
Comment 1 Yonas Yanfa 2015-11-10 17:52:53 UTC
@Kubilay What needs to happen here?

In general, how do we handle security issues? Is this suppose to be publicly viewable, or is it ok since the CVE is already published?
Comment 2 Kubilay Kocak freebsd_committer freebsd_triage 2015-11-11 03:53:07 UTC
Vulnerabilities not under embargo (public) are fine as public issues, and perhaps better as public issues for transparency/accountability

Security issues require:

* An entry in security/vuxml
* A changeset (needs-patch) to address the vulnerability in HEAD and the quarterly branch if the version in ports is/remains vulnerable

The issue summary at the moment only states a missing vuxml entry, but comment 0 eludes that there's still a vulnerability vector in the port.

@Sevan please clarify.
Comment 3 Yonas Yanfa 2015-11-11 08:15:36 UTC
Created attachment 162999 [details]
Update owncloudclient from 2.0.1 to 2.0.2

I've attached a patch that will update this port from 2.0.1 to 2.0.2.
Comment 4 Yonas Yanfa 2015-11-11 08:23:31 UTC
Created attachment 163000 [details]
Update owncloudclient from 2.0.1 to 2.0.2
Comment 5 commit-hook freebsd_committer freebsd_triage 2015-11-11 11:20:02 UTC
A commit references this bug:

Author: madpilot
Date: Wed Nov 11 11:19:18 UTC 2015
New revision: 401235
URL: https://svnweb.freebsd.org/changeset/ports/401235

Log:
  Document owncloudclient vulnerability

  PR:		204407
  Submitted by:	Sevan Janiyan <venture37 at geeklan.co.uk>
  Security:	CVE-2015-7298

Changes:
  head/security/vuxml/vuln.xml
Comment 6 Guido Falsi freebsd_committer freebsd_triage 2015-11-11 11:23:18 UTC
(In reply to Kubilay Kocak from comment #2)

The reported entry in the CVE database and the vendor report state the vulnerability was against 2.0.0, so the port at 2.0.1 is not vulnerable.

I'm now testing the update anyway.
Comment 7 Sevan Janiyan 2015-11-11 11:28:04 UTC
(In reply to Kubilay Kocak from comment #2)
I was just clarifying in what scenario/component the issue is.

While the version in ports may not be vulnerable, a vuxml entry is needed to indicate to users of previous versions that there is an issue & they need to upgrade. Otherwise, the issue may go undetected unless the user actively monitors the project and realises there is either an update in ports or realises from upstream or another source.
Comment 8 Yonas Yanfa 2015-11-11 21:10:27 UTC
(In reply to Guido Falsi from comment #6)

Does the update (2.0.2) work for you?
Comment 9 Guido Falsi freebsd_committer freebsd_triage 2015-11-11 21:28:17 UTC
(In reply to Yonas Yanfa from comment #8)

It's going through poudriere with other ports I'm testing, since its' got to rebuild many dependencies for all of them it still requires a little to finish for the various FreeBSD versions.

It looks good though. I plan to commit it tomorrow if everything goes right.

A few details abut your patch, please keep the plist sorted and PORTREVISION needs to be reset(removed in most cases) when updating version.

Following these guidelines helps speeding patch management.

Thanks for your work!
Comment 10 Guido Falsi freebsd_committer freebsd_triage 2015-11-12 20:03:20 UTC
Vuln entry added and update committed. Thanks all!
Comment 11 commit-hook freebsd_committer freebsd_triage 2015-11-12 20:03:50 UTC
A commit references this bug:

Author: madpilot
Date: Thu Nov 12 20:02:56 UTC 2015
New revision: 401393
URL: https://svnweb.freebsd.org/changeset/ports/401393

Log:
  Update to 2.0.2

  PR:		204407
  Submitted by:	Sevan Janiyan <venture37 at geeklan.co.uk>
  Patch by:	Yonas Yanfa <yonas at fizk.net> (maintainer)

Changes:
  head/deskutils/owncloudclient/Makefile
  head/deskutils/owncloudclient/distinfo
  head/deskutils/owncloudclient/pkg-plist
Comment 12 Yonas Yanfa 2015-11-13 03:25:07 UTC
(In reply to Guido Falsi from comment #10)

Awesome, and thanks for the tips.