Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1019783 > unrolled thread
| Started by | Thomas Schmitt <scdbackup@gmx.net> |
|---|---|
| First post | 2020-07-30 13:10 +0200 |
| Last post | 2020-08-03 00:00 +0200 |
| Articles | 2 — 2 participants |
Back to article view | Back to linux.debian.bugs.dist
Bug#966538: firefox-esr: Firefox accuses debian-9.13.0-amd64-netinst.iso of containing malware Thomas Schmitt <scdbackup@gmx.net> - 2020-07-30 13:10 +0200
Bug#966538: firefox-esr: Firefox accuses debian-9.13.0-amd64-netinst.iso of containing malware "Thomas Schmitt" <scdbackup@gmx.net> - 2020-08-03 00:00 +0200
| From | Thomas Schmitt <scdbackup@gmx.net> |
|---|---|
| Date | 2020-07-30 13:10 +0200 |
| Subject | Bug#966538: firefox-esr: Firefox accuses debian-9.13.0-amd64-netinst.iso of containing malware |
| Message-ID | <AyeBI-4vu-15@gated-at.bofh.it> |
Package: firefox-esr Version: 68.10.0esr-1~deb10u1 Severity: normal Dear Maintainer, examining https://lists.debian.org/debian-cd/2020/07/msg00056.html i downloaded https://cdimage.debian.org/mirror/cdimage/archive/9.13.0/amd64/iso-cd/debian-9.13.0-amd64-netinst.iso by the Firefox of a 6 day old Debian 10 installation. Like the OP of the debian-cd mail, i experience on the first download of that file a warning, that it contains a virus. The downloaded ISO passes the usual verification by gpg and sha512sum. See https://lists.debian.org/debian-cd/2020/07/msg00057.html for the details of my verification. I could not get more info from the warning dialog window. Clicking on the "open" button brought me to a dialog which offers me to put the ISO image somewhere esle. I also failed to find any info about the virus scanner in firefox. -- Package-specific info: $ dpkg -s firefox-esr Package: firefox-esr Status: install ok installed ... Architecture: amd64 Version: 68.10.0esr-1~deb10u1 ... Conffiles: /etc/firefox-esr/firefox-esr.js cebd145f0dd82696213e50218ff1a1bf -- Addons package information -- System Information: Debian Release: 10.4 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 4.19.0-9-amd64 (SMP w/8 CPU cores) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /usr/bin/dash Init: systemd (via /run/systemd/system) LSM: AppArmor: enabled Versions of packages firefox-esr depends on: ii debianutils 4.8.6.1 ii fontconfig 2.13.1-2 ii libasound2 1.1.8-1 ii libatk1.0-0 2.30.0-2 ii libc6 2.28-10 ii libcairo-gobject2 1.16.0-4 ii libcairo2 1.16.0-4 ii libdbus-1-3 1.12.16-1 ii libdbus-glib-1-2 0.110-4 ii libevent-2.1-6 2.1.8-stable-4 ii libffi6 3.2.1-9 ii libfontconfig1 2.13.1-2 ii libfreetype6 2.9.1-3+deb10u1 ii libgcc1 1:8.3.0-6 ii libgdk-pixbuf2.0-0 2.38.1+dfsg-1 ii libglib2.0-0 2.58.3-2+deb10u2 ii libgtk-3-0 3.24.5-1 ii libjsoncpp1 1.7.4-3 ii libpango-1.0-0 1.42.4-8~deb10u1 ii libstartup-notification0 0.12-6 ii libstdc++6 8.3.0-6 ii libvpx5 1.7.0-3+deb10u1 ii libx11-6 2:1.6.7-1 ii libx11-xcb1 2:1.6.7-1 ii libxcb-shm0 1.13.1-2 ii libxcb1 1.13.1-2 ii libxcomposite1 1:0.4.4-2 ii libxdamage1 1:1.1.4-3+b3 ii libxext6 2:1.3.3-1+b2 ii libxfixes3 1:5.0.3-1 ii libxrender1 1:0.9.10-1 ii libxt6 1:1.1.5-1+b3 ii procps 2:3.3.15-2 ii zlib1g 1:1.2.11.dfsg-1 Versions of packages firefox-esr recommends: ii libavcodec58 7:4.1.6-1~deb10u1 Versions of packages firefox-esr suggests: ii fonts-lmodern 2.004.5-6 pn fonts-stix | otf-stix <none> ii libcanberra0 0.30-7 ii libgssapi-krb5-2 1.17-3 ii libgtk2.0-0 2.24.32-3 ii pulseaudio 12.2-4+deb10u1 -- no debconf information
[toc] | [next] | [standalone]
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2020-08-03 00:00 +0200 |
| Message-ID | <Azubp-2KT-3@gated-at.bofh.it> |
| In reply to | #1019783 |
Hi, the counterpart of this bug, which is assigned to debian-cd is https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=966608 "debian-cd: Daily iso flagged as virus/malware by Firefox" where the maintainer of the ISOs affirms "It *is* a false positive - we are happy that we do not have a problem with malware." and reports "We've had a slew of similar complaints this week, all apparently triggered by Google's "safe browsing" service. We're trying to get it fixed at their end." > This appears to be a bug with Firefox and possibly > something about the Debian ISOs for some reason, If the warning would only tell something about the location of the suspicious bytes inside the ISOs. Or if the warning would be repeatable. (Thanks for the screenshot) I'll try with your ISO URL tomorrow in the hope to get the warning again and to find some button ... A Debian ISO consists of hard to fake .deb packages embedded in a jelly of ISO 9660 metadata. This jelly further embraces data files (some executable like vmlinuz) and a Master Boot Record with x86 machine code, which stems from the SYSLINUX project. The jelly is generated by my program xorriso. So i wonder whether its about a particular Debian package, a file of other kind, the Master Boot Record, or about some metadata. Have a nice day :) Thomas
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web