rinse broken due to cpio fix for CVE-2015-1197

Bug #1446468 reported by Ashish Kulkarni
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
rinse (Debian)
Fix Released
Unknown
rinse (Ubuntu)
Fix Released
High
Unassigned

Bug Description

The version of rinse in Vivid is broken due to the fix for CVE-2015-1197 in the "cpio" package. See the upstream comments [1] on how this makes it mostly unusable and classified as an RC bug for jessie. This was also unblocked [2] by the release team for jessie.

I recommend that
(1) either the new version should be uploaded before the release, or
(2) the package be removed for the current release

[1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=768501#27
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=782520#22

CVE References

Changed in rinse (Debian):
status: Unknown → Fix Released
Revision history for this message
Micah Gersten (micahg) wrote :

Thank you for keeping Ubuntu up to date. I'll sync this over.

Changed in rinse (Ubuntu):
assignee: nobody → Micah Gersten (micahg)
status: New → In Progress
importance: Undecided → High
assignee: Micah Gersten (micahg) → nobody
Revision history for this message
Micah Gersten (micahg) wrote :

This is building now, thanks.

Changed in rinse (Ubuntu):
status: In Progress → Fix Committed
status: Fix Committed → Fix Released
Revision history for this message
Micah Gersten (micahg) wrote :

This bug was fixed in the package rinse - 3.0.9
Sponsored for Ashish Kulkarni (ashkulz)

---------------
rinse (3.0.9) unstable; urgency=high

  * add dependency on new cpio version
  * fix date of 3.0.7 entry, Closes: #782518

 -- Thomas Lange <email address hidden> Tue, 14 Apr 2015 09:03:48 +0200

rinse (3.0.8) unstable; urgency=high

  * add --extract-over-symlinks to cpio call, Closes: #768501
    this restores the old behaviour of cpio, which changed because of
    CVE-2015-1197 (see #774669)
  * add check if cpio call failed

 -- Thomas Lange <email address hidden> Mon, 13 Apr 2015 14:51:41 +0200

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.