2-4 security vulnerabilities discovered on April 2018 got never fixed
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
quassel (Ubuntu) |
New
|
Undecided
|
Unassigned |
Bug Description
According to the githubs changelog there were 2 security vulnerabilities fixed in 0.12.5 in April 2018
https:/
But Ubuntu 16.04 did never get an update or security fix.
The last update was according to xenials changelog on May 2015.
http://
The security fixes are also not in Ubuntu 18.04 bionic.
The last change was on February 2018:
http://
But Debian SID got these security fixes in April 2018:
https:/
Thus we can conclude, the vulnerabilities were never fixed. Neither in Ubuntu 16.04 LTS nor in Ubuntu 18.04 LTS.
BTW, Debian stable (stretch) got these fixes in April 2018 too:
https:/
The changelog entry in debian stable has the following entry:
"Backport upstream commit to implement a custom deserializer.
Fixes possible remote code execution. (Closes: #896914)
* Backport upstream commit to reject client logins before the core is
configured. Fixes a DoS vulnerability. (Closes: #896915)
* Backport upstream commit to fix OpenSSL detection with Qt 5.6 and GCC 5."
Also keep in mind, that webkit which quassel 12.2 is linked to might also have some vulnerability issues because of lack of maintenance. That's why the developer of quassel dropped the use of webkit for quassel in 12.5.
In Debian SID they stopped using Webkit with the quassel version update of 0.12.5-1.
The changelog entry does have the following text for this:
"Build against Qt WebEngine instead of QtWebKit, following upstream."
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https:/ /wiki.ubuntu. com/SecurityTea m/UpdateProcedu res