Bug 13742 - desurium bundles a lot of security vulnerabilities
Summary: desurium bundles a lot of security vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Rémi Verschelde
QA Contact: Sec team
URL:
Whiteboard: MGA4TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2014-07-15 00:21 CEST by David Walser
Modified: 2014-09-04 18:34 CEST (History)
0 users

See Also:
Source RPM: desurium
CVE:
Status comment:


Attachments

Description David Walser 2014-07-15 00:21:00 CEST
While looking into FFmpeg bundling issues, I read something that pointed out that Chromium bundles it into a file called libffmpegsumo.so.  I did a urpmf on this and noticed that desurium contains it as well.  Looking at the desurium source package, I see that it bundles the whole Chromium tarball (!) and v8, and the Chromium is a very old version (15).  This would imply that it contains an extraordinary number of unpatched security vulnerabilities.  This cannot be good.

Reproducible: 

Steps to Reproduce:
David Walser 2014-07-15 00:21:14 CEST

Whiteboard: (none) => MGA4TOO

Comment 1 Rémi Verschelde 2014-07-15 08:30:39 CEST
I'll look into it. Desurium was indeed a pain to package, I had to remove lots of bundled dependencies, but I couldn't do without CEF and v8.

The community development of Desurium has ceased since Desura was taken over by LindenLab; now a new LGPL version of the client is being developed professionally by one of the original developers as far as I understand: https://github.com/lindenlab/desura-app

From what I've heard on #desura, it seems the development of a Linux version depends on what LindenLab will decide, and it's not 100% sure they consider Linux users as a reliable source of income (though I think many users will stop using their platform if they drop Linux support when even Steam has it now).

So, I'll poke the desura-app dev to see if a Linux version (without known security vulnerabilities) can be expected soon, or if we should drop desurium altogether.
Comment 2 Rémi Verschelde 2014-09-04 18:34:36 CEST
I've dropped desurium from cauldron: http://svnweb.mageia.org/packages?view=revision&revision=672093
Sadly there's nothing we can do for Mageia 4.

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.