Bug#968311: gnome-shell in stretch/buster as not affected by CVE-2020-17489

2020-09-13 Thread Simon McVittie
On Sat, 29 Aug 2020 at 14:27:06 +, Mike Gabriel wrote: > Here two MRs, one for buster, one for stretch: > > https://salsa.debian.org/gnome-team/gnome-shell/-/merge_requests/40 (buster) > https://salsa.debian.org/gnome-team/gnome-shell/-/merge_requests/41 (stretch) > > Looking forward to

Bug#968311: gnome-shell in stretch/buster as not affected by CVE-2020-17489

2020-08-29 Thread Mike Gabriel
Hi Simon, thanks for your reply. On Sa 29 Aug 2020 12:47:00 CEST, Simon McVittie wrote: On Sat, 29 Aug 2020 at 10:16:28 +, Mike Gabriel wrote: here is a summary of what we discussed on IRC. * gnome-shell in stretch+buster reveal password length * CVE-2020-17489/buster -> bach to

Bug#968311: gnome-shell in stretch/buster as not affected by CVE-2020-17489

2020-08-29 Thread Simon McVittie
On Sat, 29 Aug 2020 at 10:16:28 +, Mike Gabriel wrote: > here is a summary of what we discussed on IRC. > > * gnome-shell in stretch+buster reveal password length > * CVE-2020-17489/buster -> bach to (fix via buster-pu) > * CVE-2020-17489/stretch -> back to "vulnerable" (fix via LTS in

Bug#968311: gnome-shell in stretch/buster as not affected by CVE-2020-17489

2020-08-29 Thread Mike Gabriel
Hi Salvatore, On Sa 29 Aug 2020 09:33:01 CEST, Salvatore Bonaccorso wrote: Hi Mike, thanks for triaging the issue further. On Sat, Aug 29, 2020 at 06:08:06AM +, Mike Gabriel wrote: Hi Simon, I just looked into CVE-2020-17489/gnome-shell for stretch and buster. It seems that the

Bug#968311: gnome-shell in stretch/buster as not affected by CVE-2020-17489

2020-08-29 Thread Salvatore Bonaccorso
Hi Mike, thanks for triaging the issue further. On Sat, Aug 29, 2020 at 06:08:06AM +, Mike Gabriel wrote: > Hi Simon, > > I just looked into CVE-2020-17489/gnome-shell for stretch and buster. It > seems that the cleartext password feature has only become available in > gnome-shell 3.36.x. >