Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1148916 > unrolled thread
| Started by | Nicholas D Steeves <sten@debian.org> |
|---|---|
| First post | 2023-06-07 05:10 +0200 |
| Last post | 2023-06-13 07:10 +0200 |
| Articles | 3 — 2 participants |
Back to article view | Back to linux.debian.bugs.dist
Bug#1037175: [preapproval] bullseye-pu: package org-mode/9.4.0+dfsg-1+deb11u1 Nicholas D Steeves <sten@debian.org> - 2023-06-07 05:10 +0200
Bug#1037175: [preapproval] bullseye-pu: package org-mode/9.4.0+dfsg-1+deb11u1 Salvatore Bonaccorso <carnil@debian.org> - 2023-06-07 21:20 +0200
Bug#1037175: [preapproval] bullseye-pu: package org-mode/9.4.0+dfsg-1+deb11u1 Salvatore Bonaccorso <carnil@debian.org> - 2023-06-13 07:10 +0200
| From | Nicholas D Steeves <sten@debian.org> |
|---|---|
| Date | 2023-06-07 05:10 +0200 |
| Subject | Bug#1037175: [preapproval] bullseye-pu: package org-mode/9.4.0+dfsg-1+deb11u1 |
| Message-ID | <GDRIB-ebZN-1@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian.org@packages.debian.org Usertags: pu Dear Release Team, [ Reason ] https://security-tracker.debian.org/tracker/CVE-2023-28617 Bug #1033341 latex in ob-latex.el in Org Mode (≤9.6.1) allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters. At this time, org-mode 9.1.14+dfsg-3 in buster continues to be affected. Bullseye's copy of Emacs also has a bundled version that is effected, and I'm willing to patch that copy too. Elpa-org-mode is a modular add-on that upgrades and shadows that copy, by the way, so the CVE should be fixed here first. [ Impact ] Security risk that is worth the effort to fix. Emacs has no sandboxing... Carnil asked me to "consider proposing a fix via the upcoming bullseye point release" (#1033341), so here I am! [ Tests ] For the version of src:org-mode, in bullseye, manual testing; however, the same fix has been tested in the bundled copy of Org-mode that is part of Emacs in bookworm. This fix has seen two months of testing. [ Risks ] It's a trivial and fairly obvious fix that was discussed upstream here: https://list.orgmode.org/tencent_04CF842704737012CCBCD63CD654DD41CA0A@qq.com/T/#m6ef8e7d34b25fe17b4cbb655b161edce18c6655e?cve=title [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable [ Changes ] A cherry picked patch that has been tested in bookworm for two months, an update to the series file, and a changelog entry. The patch replaces calls to the external "mv" command with Emacs internal function "rename-file", which has been in active use since the '80s. Thank you for all the work that you are doing for bookworm! Regards, Nicholas
[toc] | [next] | [standalone]
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2023-06-07 21:20 +0200 |
| Message-ID | <GE6Rj-ellO-1@gated-at.bofh.it> |
| In reply to | #1148916 |
Hi, On Tue, Jun 06, 2023 at 11:00:14PM -0400, Nicholas D Steeves wrote: > +org-mode (9.4.0+dfsg-1+deb11u1) bullseye-security; urgency=medium > + > + * Fix Org Mode command injection vulnerability CVE-2023-28617 by backporting > + 0004-Org-Mode-vulnerability-CVE-2023-28617-is-fixed.patch like src:emacs > + did (Closes: #1033341). Thanks to Rob Browning's work in that package, > + fixing org-mode was trivially easy! > + > + -- Nicholas D Steeves <sten@debian.org> Sun, 04 Jun 2023 13:26:52 -0400 Small remark, for the bullseye pu update please target at 'bullseye' not 'bullseye-security'. Regards, Salvatore
[toc] | [prev] | [next] | [standalone]
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2023-06-13 07:10 +0200 |
| Message-ID | <GG4s1-fytH-5@gated-at.bofh.it> |
| In reply to | #1148916 |
Hi Nicholas, On Mon, Jun 12, 2023 at 07:44:52PM -0400, Nicholas D Steeves wrote: > Control: block 1033341 by -1 > > Dear Salvatore and release team, > > Salvatore Bonaccorso <carnil@debian.org> writes: > > > On Tue, Jun 06, 2023 at 11:00:14PM -0400, Nicholas D Steeves wrote: > >> +org-mode (9.4.0+dfsg-1+deb11u1) bullseye-security; urgency=medium > >> + > >> + * Fix Org Mode command injection vulnerability CVE-2023-28617 by backporting > >> + 0004-Org-Mode-vulnerability-CVE-2023-28617-is-fixed.patch like src:emacs > >> + did (Closes: #1033341). Thanks to Rob Browning's work in that package, > >> + fixing org-mode was trivially easy! > >> + > >> + -- Nicholas D Steeves <sten@debian.org> Sun, 04 Jun 2023 13:26:52 -0400 > > > > Small remark, for the bullseye pu update please target at 'bullseye' > > not 'bullseye-security'. > > > > Done. That was actually my first instinct, but I thought the existence > of a CVE would destine the upload to the -security queue! I was wrong, > but this is a teaching/learning moment. > > Is it as simple as: Use the -security queue when a DSA is needed, > otherwise use the normal distribution code name and the foo-updates > queue? No need to explain if it's more complicated and if you're busy. > (I couldn't find documentation of this in the Dev Ref) What is as well different for the uploads is to which upload queue you would upload in the end. ftp-master for the proposed-updates via point release, security-master for the security uploads. There are two good entry points about the uploads for stable: https://www.debian.org/doc/manuals/developers-reference/pkgs.en.html#special-case-uploads-to-the-stable-and-oldstable-distributions https://www.debian.org/doc/manuals/developers-reference/pkgs.en.html#handling-security-related-bugs Hope this helps! Regards, Salvatore
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web