Lucene search

K
osvGoogleOSV:OPENSUSE-SU-2024:0194-2
HistoryJul 08, 2024 - 6:01 p.m.

Security update for keybase-client

2024-07-0818:01:42
Google
osv.dev
1
keybase-client
security update
version 6.2.8
ca
image dependency
parallel test execution
kbfs integration
go version
systemd unit file.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

7.3

Confidence

Low

This update for keybase-client fixes the following issues:

Update to version 6.2.8

  • Update client CA
  • Fix incomplete locking in config file handling.
  • Update the Image dependency to address CVE-2023-29408 /
    boo#1213928. This is done via the new update-image-tiff.patch.
  • Limit parallel test execution as that seems to cause failing
    builds on OBS that don’t occur locally.
  • Integrate KBFS packages previously build via own source package
    • Upstream integrated these into the same source.
    • Also includes adding kbfs-related patches
      ensure-mount-dir-exists.patch and
      ensure-service-stop-unmounts-filesystem.patch.
  • Upgrade Go version used for compilation to 1.19.
  • Use Systemd unit file from upstream source.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

7.3

Confidence

Low