Bug 20685 - qtwebengine5 several new security issues fixed in 5.8.0, 5.9.0, 5.9.2, 5.9.3, 5.9.4, 5.11.3
Summary: qtwebengine5 several new security issues fixed in 5.8.0, 5.9.0, 5.9.2, 5.9.3,...
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: KDE maintainers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: 22657
  Show dependency treegraph
 
Reported: 2017-04-16 17:16 CEST by David Walser
Modified: 2019-11-06 13:14 CET (History)
4 users (show)

See Also:
Source RPM: qtwebengine5-5.6.2-5.mga6.src.rpm
CVE:
Status comment: Will be fixed in 5.6.3, fixes could possibly be backported


Attachments

Description David Walser 2017-04-16 17:16:13 CEST
Fedora has issued an advisory on April 16:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/NC6RAT5BS2LMSN5UE3DUX3SVIR6USC4H/

I don't know what, of any, of this is fixable while we're on Qt 5.6.
Comment 1 Nicolas Lécureuil 2017-04-16 23:29:47 CEST
qt 5.6 is a LTS, so i hope sec issues will be backported :)

CC: (none) => mageia

David Walser 2017-04-17 22:39:46 CEST

QA Contact: (none) => security
Component: RPM Packages => Security

Comment 2 Nicolas Lécureuil 2017-04-29 23:37:31 CEST
i am looking to this one.
Nicolas Lécureuil 2017-04-29 23:37:41 CEST

Status: NEW => ASSIGNED

Comment 3 Nicolas Lécureuil 2017-05-01 21:44:48 CEST
i looked and this will be fixed with version 5.6.3. 
I will look later if we can backport those fixes
Comment 4 David Walser 2017-06-05 00:48:17 CEST
So we either need backported fixes, an update to 5.6.3, or an update to 5.9.1 later on.

Status comment: (none) => Will be fixed in 5.6.3, fixes could possibly be backported

Comment 5 Nicolas Lécureuil 2017-06-05 09:13:11 CEST
i plan both. Update to qt 5.6.3 when released, and later jump to newer qt LTS but this will need test, test, test so no hurry ;)
Comment 6 Rémi Verschelde 2017-07-01 09:32:26 CEST
I'd say that if Qt upstream doesn't care enough about those security issues to roll out a 5.6.3 in a timely manner (5.6.2 was in October 2016, 5.6.3 planned for August 2017... what is that for an LTS?), or a 5.6.2.1 with only the critical security fixes, we can probably just wait for them to do their job.

Either the issues are not critical enough, or Qt upstream is reckless and doesn't care about its customers' security, but in both cases I don't see us doing the QA work that Digia doesn't seem willing to do.

So IMO, this will be fixed in August (if there are no delays for 5.6.3...).
David Walser 2017-07-07 04:24:16 CEST

Whiteboard: (none) => MGA6TOO

Comment 7 David Walser 2017-07-07 05:16:51 CEST
Fedora has issued an advisory today (July 6):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/EV3BI7JDO6W3R2LDREE4IAN5PQU3IPFH/

They fixed several more issues by upgrading to 5.9.0.

Summary: qtwebengine5 several new security issues fixed in 5.8.0 => qtwebengine5 several new security issues fixed in 5.8.0 and 5.9.0

Comment 8 Nicolas Lécureuil 2017-07-07 10:57:01 CEST
i plan to update mga 6 to qt 5.9.0 later, but plasma 5.8.x does not work with qt 5.9 so this is a work i will do but after mga6 release :)
Comment 9 Nicolas Lécureuil 2017-08-11 10:06:59 CEST
Fixed in cauldron

Version: Cauldron => 6
Whiteboard: MGA6TOO => (none)

Comment 10 David Walser 2017-11-18 01:07:39 CET
Fedora has issued an advisory today (November 17):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/A7N3JOITXZYKROVZDADU3G3GPC7OPLLD/

They fixed several more issues by upgrading to 5.9.2.

Summary: qtwebengine5 several new security issues fixed in 5.8.0 and 5.9.0 => qtwebengine5 several new security issues fixed in 5.8.0, 5.9.0, and 5.9.2

Comment 11 Nicolas Lécureuil 2017-11-18 17:55:31 CET
we will update mageia  6 to qt 5.9.x at the end of december
Comment 12 David Walser 2017-12-05 23:23:56 CET
Fedora has issued an advisory on December 4:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MTQUMCWRYF6W2XTBHKA7YFUANPLTCWGN/

They fixed several more issues by upgrading to 5.9.3.

Summary: qtwebengine5 several new security issues fixed in 5.8.0, 5.9.0, and 5.9.2 => qtwebengine5 several new security issues fixed in 5.8.0, 5.9.0, 5.9.2, and 5.9.3

Comment 13 Olivier Delaune 2018-02-07 22:27:03 CET
I installed qt 5.9.3 packages on Mageia 6 64-bits and everything works fine so far.

CC: (none) => olivier.delaune

Comment 14 David Walser 2018-02-11 17:08:52 CET
qtwebengine5-5.9.3-2.mga6
qtwebengine5-doc-5.9.3-2.mga6
libqt5webengine5-5.9.3-2.mga6
libqt5webenginecore5-5.9.3-2.mga6
libqt5webenginewidgets5-5.9.3-2.mga6
libqt5webengine-devel-5.9.3-2.mga6

from qtwebengine5-5.9.3-2.mga6.src.rpm

built for the Qt5/KF5/Plasma5 update.
Ulrich Beckmann 2018-02-11 18:36:15 CET

CC: (none) => bequimao.de

Comment 15 David Walser 2018-02-26 02:06:33 CET
Fedora has issued an advisory today (February 25):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/LGDSXXPN73LMQRMWCOGQL5XQFGUWIC7D/

Now they've updated to 5.10.1.
Comment 16 David Walser 2018-03-05 17:24:47 CET
This still needs an update to 5.9.4 or 5.10.1.

Summary: qtwebengine5 several new security issues fixed in 5.8.0, 5.9.0, 5.9.2, and 5.9.3 => qtwebengine5 several new security issues fixed in 5.8.0, 5.9.0, 5.9.2, 5.9.3, and 5.9.4
Blocks: (none) => 22657

Comment 17 David Walser 2018-03-06 14:15:28 CET
qtwebengine5-5.9.4-1.mga6
qtwebengine5-doc-5.9.4-1.mga6
libqt5webengine5-5.9.4-1.mga6
libqt5webenginecore5-5.9.4-1.mga6
libqt5webenginewidgets5-5.9.4-1.mga6
libqt5webengine-devel-5.9.4-1.mga6

from qtwebengine5-5.9.4-1.mga6.src.rpm
Comment 19 David Walser 2018-12-25 21:44:06 CET
Fedora has issued an advisory on December 19:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/7MR5MDFEUCNVBCGVTWVEMGQXACIDFR46/

Summary: qtwebengine5 several new security issues fixed in 5.8.0, 5.9.0, 5.9.2, 5.9.3, and 5.9.4 => qtwebengine5 several new security issues fixed in 5.8.0, 5.9.0, 5.9.2, 5.9.3, 5.9.4, 5.11.3

Comment 20 Mike Rambo 2019-11-06 13:14:36 CET
Mageia 6 is EOL.

CC: (none) => mrambo
Resolution: (none) => OLD
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.