tracker-miners: CVE-2023-5557

Related Vulnerabilities: CVE-2023-5557  

Debian Bug report logs - #1053881
tracker-miners: CVE-2023-5557

version graph

Reported by: Moritz Mühlenhoff <jmm@inutil.org>

Date: Fri, 13 Oct 2023 13:27:11 UTC

Severity: important

Tags: security

Found in version tracker-miners/3.4.3-1

Fixed in version tracker-miners/3.4.5-1

Fix blocked by 1053238: tracker-miners: Fails to build on many architectures, failed to load seccomp rules

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>:
Bug#1053881; Package src:tracker-miners. (Fri, 13 Oct 2023 13:27:13 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Mühlenhoff <jmm@inutil.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>. (Fri, 13 Oct 2023 13:27:13 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Mühlenhoff <jmm@inutil.org>
To: submit@bugs.debian.org
Subject: tracker-miners: CVE-2023-5557
Date: Fri, 13 Oct 2023 15:25:20 +0200
Source: tracker-miners
X-Debbugs-CC: team@security.debian.org
Severity: important
Tags: security

Hi,

The following vulnerability was published for tracker-miners.

CVE-2023-5557[0]:
| A flaw was found in the tracker-miners package. A weakness in the
| sandbox allows a maliciously-crafted file to execute code outside
| the sandbox if the tracker-extract process has first been
| compromised by a separate vulnerability.

https://gitlab.gnome.org/GNOME/tracker-miners/-/issues/277
https://gitlab.gnome.org/GNOME/tracker-miners/-/merge_requests/480

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-5557
    https://www.cve.org/CVERecord?id=CVE-2023-5557

Please adjust the affected versions in the BTS as needed.



Information forwarded to debian-bugs-dist@lists.debian.org, Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>:
Bug#1053881; Package src:tracker-miners. (Fri, 13 Oct 2023 14:09:03 GMT) (full text, mbox, link).


Acknowledgement sent to Jeremy Bícha <jeremy.bicha@canonical.com>:
Extra info received and forwarded to list. Copy sent to Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>. (Fri, 13 Oct 2023 14:09:03 GMT) (full text, mbox, link).


Message #10 received at 1053881@bugs.debian.org (full text, mbox, reply):

From: Jeremy Bícha <jeremy.bicha@canonical.com>
To: Moritz Mühlenhoff <jmm@inutil.org>, 1053881@bugs.debian.org
Subject: Re: Bug#1053881: tracker-miners: CVE-2023-5557
Date: Fri, 13 Oct 2023 10:03:59 -0400
Control: fixed -1 3.4.5-1
Control: block -1 by 1053238

On Fri, Oct 13, 2023 at 9:27 AM Moritz Mühlenhoff <jmm@inutil.org> wrote:
> The following vulnerability was published for tracker-miners.
>
> CVE-2023-5557[0]:

My first attempt at packaging the update for Unstable ran into build
test failures on 32-bit architectures and ppc64el.

Thank you,
Jeremy Bícha



Marked as fixed in versions tracker-miners/3.4.5-1. Request was from Jeremy Bícha <jeremy.bicha@canonical.com> to 1053881-submit@bugs.debian.org. (Fri, 13 Oct 2023 14:09:03 GMT) (full text, mbox, link).


Added blocking bug(s) of 1053881: 1053238 Request was from Jeremy Bícha <jeremy.bicha@canonical.com> to 1053881-submit@bugs.debian.org. (Fri, 13 Oct 2023 14:09:03 GMT) (full text, mbox, link).


Marked as found in versions tracker-miners/3.4.3-1. Request was from Jeremy Bícha <jeremy.bicha@canonical.com> to control@bugs.debian.org. (Fri, 13 Oct 2023 15:33:05 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Fri Oct 13 17:53:37 2023; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.