Bug 33712 - qbittorrent new security issue
Summary: qbittorrent new security issue
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-11-04 10:54 CET by Nicolas Salguero
Modified: 2024-11-12 21:27 CET (History)
3 users (show)

See Also:
Source RPM: qbittorrent-4.6.6-1.mga9.src.rpm
CVE:
Status comment:


Attachments

Description Nicolas Salguero 2024-11-04 10:54:52 CET
That problem was announced here:
https://www.openwall.com/lists/oss-security/2024/10/30/4
https://www.openwall.com/lists/oss-security/2024/10/31/3

Gentoo has a patch for version 4.6.7 (for Mageia 9).
Nicolas Salguero 2024-11-04 10:55:51 CET

Source RPM: (none) => qbittorrent-5.0.0-1.mga10.src.rpm, qbittorrent-4.6.6-1.mga9.src.rpm
Status comment: (none) => Fixed upstream in 5.0.1 and patch available from Gentoo
Whiteboard: (none) => MGA9TOO

Comment 1 Nicolas Salguero 2024-11-04 10:56:51 CET
The patch from Gentoo: https://942569.bugs.gentoo.org/attachment.cgi?id=907813
Comment 2 Lewis Smith 2024-11-04 20:44:19 CET
"Fixed upstream in 5.0.1" - this is already in Cauldron thanks to DavidG.

Once again, thanks NicolasS for the patch pointer.

Unsure who to assign this to, so globally.

Assignee: bugsquad => pkg-bugs

Comment 3 Nicolas Salguero 2024-11-07 11:51:00 CET
Suggested advisory:
========================

The updated packages fix some bugs and a security vulnerability.

References:
https://www.openwall.com/lists/oss-security/2024/10/30/4
https://www.openwall.com/lists/oss-security/2024/10/31/3
========================

Updated packages in core/updates_testing:
========================
qbittorrent-4.6.7-1.mga9
qbittorrent-nox-4.6.7-1.mga9

from SRPM:
qbittorrent-4.6.7-1.mga9.src.rpm

Whiteboard: MGA9TOO => (none)
Assignee: pkg-bugs => qa-bugs
Status comment: Fixed upstream in 5.0.1 and patch available from Gentoo => (none)
Source RPM: qbittorrent-5.0.0-1.mga10.src.rpm, qbittorrent-4.6.6-1.mga9.src.rpm => qbittorrent-4.6.6-1.mga9.src.rpm
Version: Cauldron => 9
Status: NEW => ASSIGNED

katnatek 2024-11-07 18:44:56 CET

Keywords: (none) => advisory

Comment 4 katnatek 2024-11-08 02:26:06 CET
RH x86_64

LC_ALL=C urpmi --auto --auto-update
medium "QA Testing (64-bit)" is up-to-date
medium "Core Release (distrib1)" is up-to-date
medium "Core Updates (distrib3)" is up-to-date
medium "Nonfree Release (distrib11)" is up-to-date
medium "Nonfree Updates (distrib13)" is up-to-date
medium "Tainted Release (distrib21)" is up-to-date
medium "Tainted Updates (distrib23)" is up-to-date
medium "Core 32bit Release (distrib31)" is up-to-date
medium "Core 32bit Updates (distrib32)" is up-to-date
medium "Nonfree 32bit Release (distrib36)" is up-to-date
medium "Nonfree 32bit Updates (distrib37)" is up-to-date
medium "Tainted 32bit Release (distrib41)" is up-to-date
medium "Tainted 32bit Updates (distrib42)" is up-to-date

installing qbittorrent-4.6.7-1.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ##################################################################################################
      1/1: qbittorrent           ##################################################################################################
      1/1: removing qbittorrent-4.6.6-1.mga9.x86_64
                                 ##################################################################################################

qbittorrent start and keep seeding files downloaded previously
Comment 5 Thomas Andrews 2024-11-10 21:28:21 CET
MGA9-64 Plasma. No installation issues.

Tested as in Bug 33479 comment 3, except that this time I downloaded the colorized version of The Day The Earth Stood Still. Movie downloaded without incident, and started seeding. Watched some of the movie, and it was OK for a colorized version, but I've seen better. This is one movie that should be watched in the original monochrome.

But I digress. This looks OK to me. Validating.

Whiteboard: (none) => MGA9-64-OK
CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Comment 6 Dan Fandrich 2024-11-12 07:14:22 CET
This package was pushed today but for some reason this bug wasn't automatically closed.

CC: (none) => dan

Comment 7 Dan Fandrich 2024-11-12 07:15:42 CET
closing

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED

Comment 8 Mageia Robot 2024-11-12 21:27:13 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0359.html

Note You need to log in before you can comment on or make changes to this bug.