Bug 1532033 - Accelerate bodhi update process for high risk bug
Summary: Accelerate bodhi update process for high risk bug
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: electron-cash
Version: 27
Hardware: Unspecified
OS: Unspecified
urgent
urgent
Target Milestone: ---
Assignee: Jonny Heggheim
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-01-07 14:40 UTC by Germano Massullo
Modified: 2018-01-09 19:17 UTC (History)
2 users (show)

Fixed In Version: electron-cash-3.1.1-1.fc27
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-01-08 03:18:08 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Germano Massullo 2018-01-07 14:40:50 UTC
Description of problem:
https://github.com/fyookball/electrum/commit/f98955aa9594954669e1cbcc058435baf04af459
already in release 3.1.1, fixes a bug that allows any website to steal bitcoins.

Update
https://bodhi.fedoraproject.org/updates/FEDORA-2018-858f432a2d
fixes it, but since it is a very urgent update it should be marked with attributes:

- Type: security;
- Severity: urgent;
- Stable karma: 1.

Please edit the update in such way to shorten the amount of days the package should stay in updates-testing repository before it can be pushed to stable repository

Comment 1 Germano Massullo 2018-01-07 14:41:25 UTC
Thanks to Tavis Ormandy and TheZero (developer of KeepassXC)

Comment 2 Jonny Heggheim 2018-01-07 22:45:50 UTC
Thanks, will do it now. Do you know if this bug exists in 3.0?

Comment 3 Jonny Heggheim 2018-01-07 22:47:46 UTC
(In reply to Germano Massullo from comment #0) 
> Update
> https://bodhi.fedoraproject.org/updates/FEDORA-2018-858f432a2d
> fixes it, but since it is a very urgent update it should be marked with
> attributes:

FEDORA-2018-858f432a2d is for upgrading to 3.1 not 3.1.1

Comment 4 Jonny Heggheim 2018-01-07 22:57:27 UTC
Looks like Electrum have the same issue https://bitcointalk.org/index.php?topic=2702103.0

Comment 5 Fedora Update System 2018-01-07 23:03:21 UTC
electron-cash-3.1.1-1.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2018-f0ee5b818d

Comment 6 Germano Massullo 2018-01-07 23:53:06 UTC
(In reply to Jonny Heggheim from comment #3)
> (In reply to Germano Massullo from comment #0) 
> > Update
> > https://bodhi.fedoraproject.org/updates/FEDORA-2018-858f432a2d
> > fixes it, but since it is a very urgent update it should be marked with
> > attributes:
> 
> FEDORA-2018-858f432a2d is for upgrading to 3.1 not 3.1.1

Ah, you are right

Comment 7 Germano Massullo 2018-01-07 23:53:35 UTC
(In reply to Jonny Heggheim from comment #2)
> Thanks, will do it now. Do you know if this bug exists in 3.0?

it does

Comment 8 Fedora Update System 2018-01-08 03:18:08 UTC
electron-cash-3.1.1-1.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.

Comment 9 Jonny Heggheim 2018-01-09 19:17:43 UTC
There have been another security update, are you able to test that too?

https://bodhi.fedoraproject.org/updates/electron-cash-3.1.2-1.fc27


Note You need to log in before you can comment on or make changes to this bug.