Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

quassel: 0.12.4 -> 0.12.5 (fixes RCE & remote crash) #39643

Merged
merged 1 commit into from Apr 28, 2018

Conversation

andir
Copy link
Member

@andir andir commented Apr 28, 2018

Motivation for this change

It was found that Quassel could be remotely crashed and had an
unauthenticated RCE vulnerability. The public annoucement can be found
on the oss-sec archive [1]. The bump to 0.12.5 is supposed fix both issues.

[1] http://seclists.org/oss-sec/2018/q2/77

Things done
  • Tested using sandboxing (nix.useSandbox on NixOS, or option build-use-sandbox in nix.conf on non-NixOS)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nox --run "nox-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Fits CONTRIBUTING.md.

It was found that Quassel could be remotely crashed and had an
unauthenticated RCE vulnerability. The public annoucement can be found
on the oss-sec archive [1]. The bump to 0.12.5 is supposed fixe both issues.

[1] http://seclists.org/oss-sec/2018/q2/77
@GrahamcOfBorg
Copy link

No attempt on x86_64-darwin (full log)

The following builds were skipped because they don't evaluate on x86_64-darwin: quassel

Partial log (click to expand)

Cannot nix-instantiate `quassel' because:
�[31;1merror:�[0m while evaluating 'callPackageWith' at �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/lib/customisation.nix�[0m:113:35, called from �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/pkgs/top-level/all-packages.nix�[0m:17471:13:
while evaluating 'makeOverridable' at �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/lib/customisation.nix�[0m:72:24, called from �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/lib/customisation.nix�[0m:117:8:
while evaluating anonymous function at �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/pkgs/applications/networking/irc/quassel/default.nix�[0m:1:1, called from �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/lib/customisation.nix�[0m:74:12:
assertion failed at �[1m/private/var/lib/ofborg/builds/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-ndnd/pkgs/applications/networking/irc/quassel/default.nix�[0m:27:1

@GrahamcOfBorg
Copy link

Success on aarch64-linux (full log)

Attempted: quassel

Partial log (click to expand)

post-installation fixup
shrinking RPATHs of ELF executables and libraries in /nix/store/f1sx7y4gz4rsac0fgly2rm64l3nlmv6s-quassel-kf5-0.12.5
shrinking /nix/store/f1sx7y4gz4rsac0fgly2rm64l3nlmv6s-quassel-kf5-0.12.5/bin/.quassel-wrapped
strip is /nix/store/j7d4mr0ikv974ig7yzhknpsq288js4bs-binutils-2.30/bin/strip
stripping (with command strip and flags -S) in /nix/store/f1sx7y4gz4rsac0fgly2rm64l3nlmv6s-quassel-kf5-0.12.5/bin
patching script interpreter paths in /nix/store/f1sx7y4gz4rsac0fgly2rm64l3nlmv6s-quassel-kf5-0.12.5
/nix/store/f1sx7y4gz4rsac0fgly2rm64l3nlmv6s-quassel-kf5-0.12.5/share/quassel/scripts/inxi: interpreter directive changed from "/usr/bin/env bash" to "/nix/store/adw9jx59wnrh5659wz43nbjya3m4b3gl-bash-4.4-p19/bin/bash"
checking for references to /build in /nix/store/f1sx7y4gz4rsac0fgly2rm64l3nlmv6s-quassel-kf5-0.12.5...
postPatchMkspecs
/nix/store/f1sx7y4gz4rsac0fgly2rm64l3nlmv6s-quassel-kf5-0.12.5

@GrahamcOfBorg
Copy link

Success on x86_64-linux (full log)

Attempted: quassel

Partial log (click to expand)

post-installation fixup
shrinking RPATHs of ELF executables and libraries in /nix/store/l8hnhm0hj5xzma7m3dxnpc46syi9rlbb-quassel-kf5-0.12.5
shrinking /nix/store/l8hnhm0hj5xzma7m3dxnpc46syi9rlbb-quassel-kf5-0.12.5/bin/.quassel-wrapped
strip is /nix/store/j75dgadrff2d1fyc4fczmcgqkid2imdx-binutils-2.30/bin/strip
stripping (with command strip and flags -S) in /nix/store/l8hnhm0hj5xzma7m3dxnpc46syi9rlbb-quassel-kf5-0.12.5/bin
patching script interpreter paths in /nix/store/l8hnhm0hj5xzma7m3dxnpc46syi9rlbb-quassel-kf5-0.12.5
/nix/store/l8hnhm0hj5xzma7m3dxnpc46syi9rlbb-quassel-kf5-0.12.5/share/quassel/scripts/inxi: interpreter directive changed from "/usr/bin/env bash" to "/nix/store/xn5gv3lpfy91yvfy9b0i7klfcxh9xskz-bash-4.4-p19/bin/bash"
checking for references to /build in /nix/store/l8hnhm0hj5xzma7m3dxnpc46syi9rlbb-quassel-kf5-0.12.5...
postPatchMkspecs
/nix/store/l8hnhm0hj5xzma7m3dxnpc46syi9rlbb-quassel-kf5-0.12.5

@andir andir merged commit 7c05ada into NixOS:master Apr 28, 2018
@andir andir deleted the quassel-0.12.5 branch April 28, 2018 10:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants