Bug 31159 - tumbler new security issue fixed upstream in 4.16.1
Summary: tumbler new security issue fixed upstream in 4.16.1
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-11-21 04:58 CET by David Walser
Modified: 2022-11-24 23:22 CET (History)
5 users (show)

See Also:
Source RPM: tumbler-4.16.0-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Comment 1 Jani Välimaa 2022-11-21 20:01:26 CET
Pushed tumbler-4.16.1-1.mga8 to core/updates_testing.

SRPMS:
tumbler-4.16.1-1.mga8

RPMS:
tumbler-4.16.1-1.mga8
lib(64)tumbler1_0-4.16.1-1.mga8
lib(64)tumbler-devel-4.16.1-1.mga8

CC: (none) => jani.valimaa
Assignee: jani.valimaa => qa-bugs

Comment 2 Herman Viaene 2022-11-22 17:07:12 CET
MGA8-64 MATE on Acer Aspire 5253
No installation issues.
No wiki or previous updates, so googled a bit and found references to a tumblerd service. Confirmed by finding such file listed in MCC and its presence in /usr/lib64/tumbler-1
but
# systemctl start tumblerd
Failed to start tumblerd.service: Unit tumblerd.service not found.

CC: (none) => herman.viaene

Comment 3 David Walser 2022-11-22 17:13:14 CET
If it was a service, it would be in /lib/systemd/system/
Comment 4 Jani Välimaa 2022-11-22 17:24:23 CET
Tumblerd is D-Bus activated user service used by e.g. Thunar and Ristretto.

https://docs.xfce.org/xfce/tumbler/start
Comment 5 Jani Välimaa 2022-11-22 17:59:45 CET
(In reply to Jani Välimaa from comment #4)
> Tumblerd is D-Bus activated user service used by e.g. Thunar and Ristretto.
> 

Easy steps to see if tumblerd is launched:

1. $ systemctl status --user tumblerd

2. Continue to step 3 if tumblerd is not active. Wait a bit and repeat step 1 if tumblerd is active.

3. $ ristretto /usr/share/icons/hicolor/scalable/apps/

4. $ systemctl status --user tumblerd
Comment 6 Dave Hodgins 2022-11-22 19:25:55 CET
It's a dbus service, not a systemd service.

Due to security reasons tracing of system level dbus calls is disabled.

The easiest way to test this is to delete ~/.cache/thumbnails/
and then run ristretto. If you see the thumbnails appear in the left
part of the panel, then it's working.

Then install the update and repeat the test looking for any regressions.

CC: (none) => davidwhodgins

Comment 7 Herman Viaene 2022-11-23 10:10:58 CET
Tried to follow the suggestions above:
$ systemctl status --user tumblerd
Unit tumblerd.service could not be found.
This is inline with Dave's remark above.
Deleted ~/.cache/thumbnails/
then
$ ristretto /usr/share/icons/hicolor/scalable/apps/
After the usual warning about missing windows decorations, no further feedback and ristretto comes up with default thumbnails in the left panel, and those get gradually (slow old laptop) filled up. ~/.cache/thumbnails/ has been created
So OK for me.

Whiteboard: (none) => MGA8-64-OK

Comment 8 Thomas Andrews 2022-11-23 16:39:08 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 9 Jani Välimaa 2022-11-23 17:36:00 CET
(In reply to Dave Hodgins from comment #6)
> It's a dbus service, not a systemd service.
> 
> Due to security reasons tracing of system level dbus calls is disabled.
> 
> The easiest way to test this is to delete ~/.cache/thumbnails/
> and then run ristretto. If you see the thumbnails appear in the left
> part of the panel, then it's working.
> 
> Then install the update and repeat the test looking for any regressions.

Indeed, systemd user service file was added to 4.17.0.
Dave Hodgins 2022-11-24 04:19:24 CET

Keywords: (none) => advisory

Comment 10 Mageia Robot 2022-11-24 23:22:53 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0439.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.