Bug#780748: libqt5webkit5: QtWebKit logs visited URLs to WebpageIcons.db in private browsing mode
Package: libqt5webkit5
Version: 5.3.2+dfsg-3
Severity: important
Tags: upstream patch security
Dear Maintainer,
I've just submitted a change[1] to QtWebKit upstream to prevent it recording
visited URLs to its favicon database (WebpageIcons.db) while using private
browsing mode.
The change has been accepted in upstream's Gerrit and is currently integrating
in their CI.
Raw patch: [2]
I think this should be backported as it's a privacy issue.
Thanks,
Florian
[1] https://codereview.qt-project.org/#/c/108936/
[2] http://code.qt.io/cgit/qt/qtwebkit.git/patch/?id=101feb8867ba85b1615656669bbb3ecf8574aaab
-- System Information:
Debian Release: 8.0
APT prefers testing-updates
APT policy: (500, 'testing-updates'), (500, 'testing')
Architecture: amd64 (x86_64)
Kernel: Linux 3.16.0-4-amd64 (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
Versions of packages libqt5webkit5 depends on:
ii dpkg 1.17.24
ii libc6 2.19-15
ii libgl1-mesa-glx [libgl1] 10.3.2-1
ii libglib2.0-0 2.42.1-1
ii libgstreamer-plugins-base0.10-0 0.10.36-2
ii libgstreamer0.10-0 0.10.36-1.5
ii libicu52 52.1-7.1
ii libjpeg62-turbo 1:1.3.1-11+deb7u1
ii libpng12-0 1.2.50-2+b2
ii libqt5core5a [qtbase-abi-5-3-2] 5.3.2+dfsg-4+b1
ii libqt5gui5 5.3.2+dfsg-4+b1
ii libqt5network5 5.3.2+dfsg-4+b1
ii libqt5opengl5 5.3.2+dfsg-4+b1
ii libqt5printsupport5 5.3.2+dfsg-4+b1
ii libqt5qml5 [qtdeclarative-abi-5-3-2] 5.3.2-4
ii libqt5quick5 5.3.2-4
ii libqt5sql5 5.3.2+dfsg-4+b1
ii libqt5widgets5 5.3.2+dfsg-4+b1
ii libsqlite3-0 3.8.7.1-1
ii libstdc++6 4.9.2-10
ii libwebp5 0.4.1-1.2+b2
ii libx11-6 2:1.6.2-3
ii libxcomposite1 1:0.4.4-1
ii libxml2 2.9.1+dfsg1-5
ii libxrender1 1:0.9.8-1+b1
ii libxslt1.1 1.1.28-2+b2
ii multiarch-support 2.19-15
ii zlib1g 1:1.2.8.dfsg-2+b1
libqt5webkit5 recommends no packages.
libqt5webkit5 suggests no packages.
-- no debconf information
Reply to: