Bug 25381 - gwenhywfar 4.20.0 can cause segmentation faults of kmymoney and gnucash when using aqbanking
Summary: gwenhywfar 4.20.0 can cause segmentation faults of kmymoney and gnucash when ...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-08-29 22:46 CEST by Martin Spiegel
Modified: 2019-09-06 23:10 CEST (History)
5 users (show)

See Also:
Source RPM: gwenhywfar-4.20.0-3.mga7.src.rpm
CVE:
Status comment:


Attachments

Description Martin Spiegel 2019-08-29 22:46:35 CEST
Description of problem:
When trying to retreive account information via aqbanking from a bank which has issued a new certificate (not known to gwenhywfar) acccepting the certificate will cause a segmentation fault of the accounting software (kmymoney or gnucash). Once the certificate has been accepted the accounting software will crash everytime you try to retrieve the account data. Updating to gwenhywfar-4.20.2 fixes the problem (probably because it contains an updated ca-bundle.crt file)

Version-Release number of selected component (if applicable):
gwenhywfar-4.20.0-3.mga7

How reproducible:
See above
Steps to Reproduce:
1.
2.
3.
Comment 1 David GEIGER 2019-08-30 06:04:14 CEST
Assigning to the registered maintainer!

Assignee: bugsquad => lists.jjorge
CC: (none) => geiger.david68210

Comment 2 José Jorge 2019-08-30 18:13:58 CEST
(In reply to Martin Spiegel from comment #0)
> (kmymoney or gnucash). Once the certificate has been accepted the accounting
> software will crash everytime you try to retrieve the account data. Updating
> to gwenhywfar-4.20.2 fixes the problem (probably because it contains an
> updated ca-bundle.crt file)
> 

Please test the gwenhywfar-4.20.2 in updates testing, to ensure it also fixes the bug for you. I have no use of aqbanking ;-)

CC: (none) => lists.jjorge

Comment 3 Martin Spiegel 2019-08-31 20:16:34 CEST
(In reply to José Jorge from comment #2)
> 
> Please test the gwenhywfar-4.20.2 in updates testing, to ensure it also
> fixes the bug for you. I have no use of aqbanking ;-)

I've tried the packages (gwenhywfar, lib64gwenhywfar60, libgwengui-cpp0 and libggwengui-qt5_0) from updates testing and they also fix the bug. No more segfautling when the account information is retrieved :-)
Comment 4 José Jorge 2019-08-31 22:31:45 CEST
To QA : the solution is tested and approved by bug reporter Martin Spiegel.

Suggested advisory:
When trying to retreive account information via aqbanking from a bank which has issued a new certificate (not known to gwenhywfar), accepting the certificate would cause a segmentation fault of the accounting software (kmymoney or gnucash). Once the certificate had been accepted the accounting software would crash everytime it tried to retrieve the account data.
Upstream has released gwenhywfar-4.20.2 to fix the problem.


RPMS :
gwenhywfar-4.20.2-1.mga7.i586.rpm
libgwenhywfar60-4.20.2-1.mga7.i586.rpm
libgwengui-qt4_0-4.20.2-1.mga7.i586.rpm
libgwengui-qt5_0-4.20.2-1.mga7.i586.rpm
libgwengui-gtk2_0-4.20.2-1.mga7.i586.rpm
libgwengui-cpp0-4.20.2-1.mga7.i586.rpm
libgwenhywfar-devel-4.20.2-1.mga7.i586.rpm

Assignee: lists.jjorge => qa-bugs

Comment 5 José Jorge 2019-08-31 22:32:19 CEST
(In reply to Martin Spiegel from comment #3)
> (In reply to José Jorge from comment #2)
> > 
> > Please test the gwenhywfar-4.20.2 in updates testing, to ensure it also
> > fixes the bug for you. I have no use of aqbanking ;-)
> 
> I've tried the packages (gwenhywfar, lib64gwenhywfar60, libgwengui-cpp0 and
> libggwengui-qt5_0) from updates testing and they also fix the bug. No more
> segfautling when the account information is retrieved :-)

Whiteboard: (none) => MGA7-64-OK

José Jorge 2019-08-31 22:33:16 CEST

Summary: outdated vesrsion of gwenhywfar can cause segmentation faults of kmymoney and gnucash when using aqbanking => gwenhywfar 4.20.0 can cause segmentation faults of kmymoney and gnucash when using aqbanking

Comment 6 Thomas Andrews 2019-09-05 14:31:23 CEST
Validating. Advisory in Comment 4.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Thomas Backlund 2019-09-06 19:07:17 CEST

CC: (none) => tmb
Keywords: (none) => advisory

Comment 7 Mageia Robot 2019-09-06 23:10:53 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGAA-2019-0118.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.