Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1019783 > unrolled thread

Bug#966538: firefox-esr: Firefox accuses debian-9.13.0-amd64-netinst.iso of containing malware

Started byThomas Schmitt <scdbackup@gmx.net>
First post2020-07-30 13:10 +0200
Last post2020-08-03 00:00 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#966538: firefox-esr: Firefox accuses debian-9.13.0-amd64-netinst.iso of containing malware Thomas Schmitt <scdbackup@gmx.net> - 2020-07-30 13:10 +0200
    Bug#966538: firefox-esr: Firefox accuses debian-9.13.0-amd64-netinst.iso of containing malware "Thomas Schmitt" <scdbackup@gmx.net> - 2020-08-03 00:00 +0200

#1019783 — Bug#966538: firefox-esr: Firefox accuses debian-9.13.0-amd64-netinst.iso of containing malware

FromThomas Schmitt <scdbackup@gmx.net>
Date2020-07-30 13:10 +0200
SubjectBug#966538: firefox-esr: Firefox accuses debian-9.13.0-amd64-netinst.iso of containing malware
Message-ID<AyeBI-4vu-15@gated-at.bofh.it>
Package: firefox-esr
Version: 68.10.0esr-1~deb10u1
Severity: normal

Dear Maintainer,

examining
  https://lists.debian.org/debian-cd/2020/07/msg00056.html
i downloaded
  https://cdimage.debian.org/mirror/cdimage/archive/9.13.0/amd64/iso-cd/debian-9.13.0-amd64-netinst.iso
by the Firefox of a 6 day old Debian 10 installation.
Like the OP of the debian-cd mail, i experience on the first download of
that file a warning, that it contains a virus.

The downloaded ISO passes the usual verification by gpg and sha512sum.
See
  https://lists.debian.org/debian-cd/2020/07/msg00057.html
for the details of my verification.

I could not get more info from the warning dialog window. Clicking on
the "open" button brought me to a dialog which offers me to put the
ISO image somewhere esle.
I also failed to find any info about the virus scanner in firefox.

-- Package-specific info:

$ dpkg -s firefox-esr
Package: firefox-esr
Status: install ok installed
...
Architecture: amd64
Version: 68.10.0esr-1~deb10u1
...
Conffiles:
 /etc/firefox-esr/firefox-esr.js cebd145f0dd82696213e50218ff1a1bf

-- Addons package information

-- System Information:
Debian Release: 10.4
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.19.0-9-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages firefox-esr depends on:
ii  debianutils               4.8.6.1
ii  fontconfig                2.13.1-2
ii  libasound2                1.1.8-1
ii  libatk1.0-0               2.30.0-2
ii  libc6                     2.28-10
ii  libcairo-gobject2         1.16.0-4
ii  libcairo2                 1.16.0-4
ii  libdbus-1-3               1.12.16-1
ii  libdbus-glib-1-2          0.110-4
ii  libevent-2.1-6            2.1.8-stable-4
ii  libffi6                   3.2.1-9
ii  libfontconfig1            2.13.1-2
ii  libfreetype6              2.9.1-3+deb10u1
ii  libgcc1                   1:8.3.0-6
ii  libgdk-pixbuf2.0-0        2.38.1+dfsg-1
ii  libglib2.0-0              2.58.3-2+deb10u2
ii  libgtk-3-0                3.24.5-1
ii  libjsoncpp1               1.7.4-3
ii  libpango-1.0-0            1.42.4-8~deb10u1
ii  libstartup-notification0  0.12-6
ii  libstdc++6                8.3.0-6
ii  libvpx5                   1.7.0-3+deb10u1
ii  libx11-6                  2:1.6.7-1
ii  libx11-xcb1               2:1.6.7-1
ii  libxcb-shm0               1.13.1-2
ii  libxcb1                   1.13.1-2
ii  libxcomposite1            1:0.4.4-2
ii  libxdamage1               1:1.1.4-3+b3
ii  libxext6                  2:1.3.3-1+b2
ii  libxfixes3                1:5.0.3-1
ii  libxrender1               1:0.9.10-1
ii  libxt6                    1:1.1.5-1+b3
ii  procps                    2:3.3.15-2
ii  zlib1g                    1:1.2.11.dfsg-1

Versions of packages firefox-esr recommends:
ii  libavcodec58  7:4.1.6-1~deb10u1

Versions of packages firefox-esr suggests:
ii  fonts-lmodern          2.004.5-6
pn  fonts-stix | otf-stix  <none>
ii  libcanberra0           0.30-7
ii  libgssapi-krb5-2       1.17-3
ii  libgtk2.0-0            2.24.32-3
ii  pulseaudio             12.2-4+deb10u1

-- no debconf information

[toc] | [next] | [standalone]


#1020221

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2020-08-03 00:00 +0200
Message-ID<Azubp-2KT-3@gated-at.bofh.it>
In reply to#1019783
Hi,

the counterpart of this bug, which is assigned to debian-cd is
  https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=966608
  "debian-cd: Daily iso flagged as virus/malware by Firefox"
where the maintainer of the ISOs affirms
  "It *is* a false positive - we are happy
   that we do not have a problem with malware."
and reports
  "We've had a slew of similar complaints this week, all apparently
   triggered by Google's "safe browsing" service. We're trying to get it
   fixed at their end."

> This appears to be a bug with Firefox and possibly
> something about the Debian ISOs for some reason,

If the warning would only tell something about the location of the
suspicious bytes inside the ISOs.
Or if the warning would be repeatable. (Thanks for the screenshot)
I'll try with your ISO URL tomorrow in the hope to get the warning
again and to find some button ...

A Debian ISO consists of hard to fake .deb packages embedded in a jelly
of ISO 9660 metadata. This jelly further embraces data files (some executable
like vmlinuz) and a Master Boot Record with x86 machine code, which stems
from the SYSLINUX project.
The jelly is generated by my program xorriso. So i wonder whether its about
a particular Debian package, a file of other kind, the Master Boot Record,
or about some metadata.


Have a nice day :)

Thomas

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web