Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[17.09] quassel: 0.12.4 fix RCE & DOS #39644

Merged
merged 1 commit into from Apr 28, 2018

Conversation

andir
Copy link
Member

@andir andir commented Apr 28, 2018

Motivation for this change

It was found that Quassel could be remotely crashed and had an
unauthenticated RCE vulnerability. The public annoucement can be found
on the oss-sec archive [1]. The added patches are supposed fix both issues.

[1] http://seclists.org/oss-sec/2018/q2/77

(cherry picked from commit 8ae91ea)

Things done
  • Tested using sandboxing (nix.useSandbox on NixOS, or option build-use-sandbox in nix.conf on non-NixOS)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nox --run "nox-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Fits CONTRIBUTING.md.

It was found that Quassel could be remotely crashed and had an
unauthenticated RCE vulnerability. The public annoucement can be found
on the oss-sec archive [1]. The added patches are supposed fix both issues.

[1] http://seclists.org/oss-sec/2018/q2/77

(cherry picked from commit 8ae91ea)
@GrahamcOfBorg
Copy link

No attempt on x86_64-darwin (full log)

The following builds were skipped because they don't evaluate on x86_64-darwin: quassel

Partial log (click to expand)

Cannot nix-instantiate `quassel' because:
�[31;1merror:�[0m while evaluating 'callPackageWith' at �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/lib/customisation.nix�[0m:113:35, called from �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/pkgs/top-level/all-packages.nix�[0m:16115:13:
while evaluating 'makeOverridable' at �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/lib/customisation.nix�[0m:72:24, called from �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/lib/customisation.nix�[0m:117:8:
while evaluating anonymous function at �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/pkgs/applications/networking/irc/quassel/default.nix�[0m:1:1, called from �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/lib/customisation.nix�[0m:74:12:
assertion failed at �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/pkgs/applications/networking/irc/quassel/default.nix�[0m:27:1

@GrahamcOfBorg
Copy link

Success on x86_64-linux (full log)

Attempted: quassel

Partial log (click to expand)

-- Installing: /nix/store/8dysxkm887g9fxkv7mv44vg8hrfs868c-quassel-kf5-0.12.4/bin/quassel
glibPreFixupPhase
post-installation fixup
shrinking RPATHs of ELF executables and libraries in /nix/store/8dysxkm887g9fxkv7mv44vg8hrfs868c-quassel-kf5-0.12.4
shrinking /nix/store/8dysxkm887g9fxkv7mv44vg8hrfs868c-quassel-kf5-0.12.4/bin/.quassel-wrapped
stripping (with flags -S) in /nix/store/8dysxkm887g9fxkv7mv44vg8hrfs868c-quassel-kf5-0.12.4/bin
patching script interpreter paths in /nix/store/8dysxkm887g9fxkv7mv44vg8hrfs868c-quassel-kf5-0.12.4
/nix/store/8dysxkm887g9fxkv7mv44vg8hrfs868c-quassel-kf5-0.12.4/share/quassel/scripts/inxi: interpreter directive changed from "/usr/bin/env bash" to "/nix/store/jgw8hxx7wzkyhb2dr9hwsd9h2caaasdc-bash-4.4-p12/bin/bash"
checking for references to /build in /nix/store/8dysxkm887g9fxkv7mv44vg8hrfs868c-quassel-kf5-0.12.4...
/nix/store/8dysxkm887g9fxkv7mv44vg8hrfs868c-quassel-kf5-0.12.4

@andir andir merged commit a3a6dd7 into NixOS:release-17.09 Apr 28, 2018
@andir andir deleted the 17.09/quassel-rce-dos branch April 28, 2018 10:04
@GrahamcOfBorg
Copy link

Failure on aarch64-linux (full log)

Attempted: quassel

Partial log (click to expand)

cannot build derivation '/nix/store/s3k1y9bzy0fda0f0wzmjvrlw4bl2bd43-kglobalaccel-5.37.0.drv': 9 dependencies couldn't be built
cannot build derivation '/nix/store/l525wmi1yvqb0lsis933bl7c2ipnr6kp-kiconthemes-5.37.0.drv': 8 dependencies couldn't be built
cannot build derivation '/nix/store/jqdba59hf24c6bra29y1hrkjx6i1czxf-ktextwidgets-5.37.0.drv': 9 dependencies couldn't be built
cannot build derivation '/nix/store/g2crngsd2y1gmhwvxg5jav4fn1mhi3n2-kwallet-5.37.0.drv': 13 dependencies couldn't be built
cannot build derivation '/nix/store/m6p5s1liz4miaps8bw64907xs1p91wlz-kxmlgui-5.37.0.drv': 11 dependencies couldn't be built
cannot build derivation '/nix/store/a0f1z6arf0d9k4fyijg53ih34bnq0mf1-kbookmarks-5.37.0.drv': 9 dependencies couldn't be built
cannot build derivation '/nix/store/v71nw02b8r6y3z4918dlj91s4glw1w9j-kio-5.37.0.drv': 23 dependencies couldn't be built
cannot build derivation '/nix/store/dp0fjjaqk28z7ff9sn1gzlpxp4d3a4y9-knotifyconfig-5.37.0.drv': 6 dependencies couldn't be built
cannot build derivation '/nix/store/2qbii4zwfv5lwvy3f379xl1dn9na1pv2-quassel-kf5-0.12.4.drv': 13 dependencies couldn't be built
�[31;1merror:�[0m build of '/nix/store/2qbii4zwfv5lwvy3f379xl1dn9na1pv2-quassel-kf5-0.12.4.drv' failed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants