Bug 14013 - gtk+3.0 new security issue CVE-2014-1949
Summary: gtk+3.0 new security issue CVE-2014-1949
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/609959/
Whiteboard: has_procedure advisory MGA4-64-OK mga...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2014-08-29 18:00 CEST by David Walser
Modified: 2014-09-09 11:34 CEST (History)
4 users (show)

See Also:
Source RPM: gtk+3.0-3.10.6-4.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2014-08-29 18:00:53 CEST
Fedora has issued an advisory on August 27:
https://lists.fedoraproject.org/pipermail/package-announce/2014-August/137123.html

The issue is already fixed in the version we have in Cauldron, and was not yet introduced in the version in Mageia 3, so only Mageia 4 is affected.

I've added the patch in Mageia 4 SVN.

Thomas, I haven't pushed this to the build system yet, as I noticed that you added a few other patches from upstream, but they are not actually applied in the SPEC.  I wanted to verify if that was your intention.

Reproducible: 

Steps to Reproduce:
Comment 1 Thomas Backlund 2014-08-29 18:47:06 CEST
Ah, crap... seems I never committed the fixed spec :/

Thanks for noticing... Patches now applied and pushed to the BS
David Walser 2014-08-29 18:49:50 CEST

CC: (none) => tmb
Assignee: tmb => qa-bugs

Comment 2 David Walser 2014-08-29 18:50:23 CEST
Thanks Thomas.  Pushed to QA.  I'll post an advisory later.  Gotta go.

gtk+3.0-3.10.6-4.1.mga4.src.rpm is the update.
Comment 3 David Walser 2014-08-30 19:59:50 CEST
Advisory:
========================

Updated gtk+3.0 packages fix security vulnerability:

Clemens Fries reported that, when using Cinnamon, it was possible to bypass
the screensaver lock. An attacker with physical access to the machine could
use this flaw to take over the locked desktop session (CVE-2014-1949).

This was fixed by including a patch for the root cause of the issue in
gtk+3.0, which came from the implementation of popup menus in GtkWindow
(bgo#722106).

This update also includes other patches from upstream to fix bugs affecting
GtkFileChooser (bgo#386569, bgo#719977) and GtkSpinButton (bgo#709491), and a
crash related to clipboard handling (bgo#719314).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1949
https://bugzilla.gnome.org/show_bug.cgi?id=386569
https://bugzilla.gnome.org/show_bug.cgi?id=709491
https://bugzilla.gnome.org/show_bug.cgi?id=719314
https://bugzilla.gnome.org/show_bug.cgi?id=719977
https://bugzilla.gnome.org/show_bug.cgi?id=722106
https://lists.fedoraproject.org/pipermail/package-announce/2014-August/137123.html
========================

Updated packages in core/updates_testing:
========================
gtk+3.0-3.10.6-4.1.mga4
libgtk+3_0-3.10.6-4.1.mga4
libgtk-gir3.0-3.10.6-4.1.mga4
libgtk+3.0-devel-3.10.6-4.1.mga4
libgail3_0-3.10.6-4.1.mga4
libgail3.0-devel-3.10.6-4.1.mga4

from gtk+3.0-3.10.6-4.1.mga4.src.rpm
Comment 4 Samuel Verschelde 2014-09-04 14:07:23 CEST
Package installed on MGA4 64, reboot, no visible problem for now.

CC: (none) => stormi

Comment 5 Samuel Verschelde 2014-09-04 21:42:29 CEST
(In reply to Samuel VERSCHELDE from comment #4)
> Package installed on MGA4 64, reboot, no visible problem for now.

same on another computer, I guess I can dare a MGA4-64-OK

Whiteboard: (none) => MGA4-64-OK

Comment 6 Lewis Smith 2014-09-05 09:26:26 CEST
(In reply to Samuel VERSCHELDE from comment #5)
> Package installed on MGA4 64, reboot, no visible problem for now.
> same on another computer, I guess I can dare a MGA4-64-OK
To support this OK, testing MGA4 on real hardware with AMD/Radeon video.

The following updated from Updates Testing to:
 gtk+3.0-3.10.6-4.1.mga4
 lib64gtk+3_0-3.10.6-4.1.mga4
 lib64gtk-gir3.0-3.10.6-4.1.mga4
 lib64gail3_0-3.10.6-4.1.mga4
Generally, no regressions noted.
Specifically, using Cinnamon desktop, with the screen blanked & locked by the screensaver, neither LH nor RH Windows key by-passes the user password dialogue to unlock the screen. I believe this was a fault corrected. MGA4-64-OK again.

CC: (none) => lewyssmith

Comment 7 claire robinson 2014-09-08 18:29:23 CEST
Testing complete mga4 32

Testing cinnamon and mate to ensure the screen lock worked as expected.
No regression noticed in use of either desktop.

Whiteboard: MGA4-64-OK => has_procedure MGA4-64-OK mga4-32-ok

Comment 8 claire robinson 2014-09-08 18:39:32 CEST
Validating. Advisory uploaded.

Could sysadmin please push to 4 updates

Thanks

Keywords: (none) => validated_update
Whiteboard: has_procedure MGA4-64-OK mga4-32-ok => has_procedure advisory MGA4-64-OK mga4-32-ok
CC: (none) => sysadmin-bugs

Comment 9 Mageia Robot 2014-09-09 11:34:41 CEST
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2014-0374.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.