[Bug 1848195] Re: Failed to start Network Time Synchronization

2019-10-18 Thread Marc Deslauriers
Thanks for your comments. This does not appear to be a bug report and we are closing it. We appreciate the difficulties you are facing, but it would make more sense to raise your question in the support tracker. Please visit https://answers.launchpad.net/ubuntu/+addquestion ** Information type

[Bug 1848309] Re: "Automatic Date & Time" is broken

2019-10-18 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1848458] Re: package grub-pc 2.02~beta2-36ubuntu3.22 failed to install/upgrade: el subproceso instalado el script post-installation devolvió el código de salida de error 127

2019-10-18 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1848222] Re: spam folder

2019-10-18 Thread Marc Deslauriers
Thanks for your comments. This does not appear to be a bug report and we are closing it. We appreciate the difficulties you are facing, but it would make more sense to raise your question in the support tracker. Please visit https://answers.launchpad.net/ubuntu/+addquestion ** Information type

[Bug 1835896] Re: Heap overflow if UDT type is used with protocol 5.0

2019-10-17 Thread Marc Deslauriers
ntu Focal) Status: New => Confirmed ** Changed in: freetds (Ubuntu Bionic) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: freetds (Ubuntu Disco) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: freetds (Ubuntu Eoan) Assignee: (u

[Bug 1847243] Re: Update Octavia-* packages as per OSSA-2019-005 / CVE-2019-17134

2019-10-10 Thread Marc Deslauriers
Thanks james-page, thanks fnordhal! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1847243 Title: Update Octavia-* packages as per OSSA-2019-005 / CVE-2019-17134 To manage notifications about this

[Bug 1847243] Re: Update Octavia-* packages as per OSSA-2019-005 / CVE-2019-17134

2019-10-09 Thread Marc Deslauriers
octavia is currently building in the security proposed PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Once it's done, could you please test it? I'll publish it as a security update once it's been tested. Thanks! -- You received this bug notification

[Bug 1822736] Re: Passwords longer than 255 characters break authentication

2019-10-05 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1845216] Re: OpenSCAP Error: Unable to open file: '/usr/share/openscap/cpe/openscap-cpe-dict.xml' [../../../src/source/oscap_source.c:284]

2019-10-04 Thread Marc Deslauriers
** Changed in: openscap (Ubuntu Xenial) Status: Confirmed => In Progress ** Changed in: openscap (Ubuntu Bionic) Status: Confirmed => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1845216] Re: OpenSCAP Error: Unable to open file: '/usr/share/openscap/cpe/openscap-cpe-dict.xml' [../../../src/source/oscap_source.c:284]

2019-10-04 Thread Marc Deslauriers
** Patch added: "Minimal fix for xenial" https://bugs.launchpad.net/ubuntu/+source/openscap/+bug/1845216/+attachment/5294356/+files/openscap_1.2.8-1ubuntu0.2.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1845216] Re: OpenSCAP Error: Unable to open file: '/usr/share/openscap/cpe/openscap-cpe-dict.xml' [../../../src/source/oscap_source.c:284]

2019-10-04 Thread Marc Deslauriers
** Patch added: "Minimal fix for bionic" https://bugs.launchpad.net/ubuntu/+source/openscap/+bug/1845216/+attachment/5294355/+files/openscap_1.2.15-1ubuntu0.1.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1845216] Re: OpenSCAP Error: Unable to open file: '/usr/share/openscap/cpe/openscap-cpe-dict.xml' [../../../src/source/oscap_source.c:284]

2019-10-04 Thread Marc Deslauriers
** Changed in: openscap (Ubuntu Disco) Status: New => Fix Released ** Changed in: openscap (Ubuntu Eoan) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1845216] Re: OpenSCAP Error: Unable to open file: '/usr/share/openscap/cpe/openscap-cpe-dict.xml' [../../../src/source/oscap_source.c:284]

2019-10-04 Thread Marc Deslauriers
** Also affects: openscap (Ubuntu Xenial) Importance: Undecided Status: New ** Also affects: openscap (Ubuntu Disco) Importance: Undecided Status: New ** Also affects: openscap (Ubuntu Eoan) Importance: Undecided Status: New ** Also affects: openscap (Ubuntu

[Bug 1452115] Re: Python interpreter binary is not compiled as PIE

2019-09-23 Thread Marc Deslauriers
** Changed in: python3.6 (Ubuntu) Assignee: (unassigned) => Ubuntu Security Team (ubuntu-security) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1452115 Title: Python interpreter binary is not

[Bug 1832356] Re: Upgrade OpenSSH to 7.9p1-10 or better in stable series

2019-09-20 Thread Marc Deslauriers
** Changed in: openssh (Ubuntu Cosmic) Status: Confirmed => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1832356 Title: Upgrade OpenSSH to 7.9p1-10 or better in stable series To

[Bug 1844790] [NEW] Update OpenSSH in bionic to (1:7.9p1-10) for FIPS

2019-09-20 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1832356 *** https://bugs.launchpad.net/bugs/1832356 *** This bug is a security vulnerability *** Public security bug reported: Now that OpenSSL 1.1.1 has been added to Bionic, we would like to update OpenSSH to a version that can be linked to OpenSSL

[Bug 1801383] Re: the WifiSyslog apport hook (used in firefox/tb) includes SSID informations

2019-09-19 Thread Marc Deslauriers
WifiSyslog does contain SSID information. While this will be removed from the thunderbird and firefox packages, I don't think it would be appropriate to remove it from the linux kernel apport reports. For linux packages, this information is helpful in debugging wireless driver issues. While a

[Bug 1838489] Re: adduser & deluser shell command injection

2019-09-17 Thread Marc Deslauriers
Thanks! ** Also affects: adduser (Debian) via https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=940577 Importance: Unknown Status: Unknown ** Changed in: adduser (Ubuntu) Status: Incomplete => Confirmed -- You received this bug notification because you are a member of

[Bug 1823419] Re: jbig-kit calls abort() on invalid data, crashing many programs

2019-09-17 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1823419 Title: jbig-kit calls abort() on invalid data, crashing many programs To

[Bug 1738259] Re: need to ensure microcode updates are available to all bare-metal installs of Ubuntu

2019-09-17 Thread Marc Deslauriers
** Changed in: linux-meta (Ubuntu Precise) Status: New => Won't Fix ** Changed in: linux-meta-hwe (Ubuntu) Status: New => Fix Released ** Changed in: linux-meta-hwe-edge (Ubuntu) Status: New => Fix Released ** Changed in: linux-meta-lts-xenial (Ubuntu Xenial) Status:

[Bug 1757416] Re: last update disabled -pie feature

2019-09-17 Thread Marc Deslauriers
Hi Otto. What's the status of this issue? Thanks! ** Changed in: mariadb-10.0 (Ubuntu) Assignee: (unassigned) => Leonidas S. Barbosa (leosilvab) ** Changed in: mariadb-10.0 (Ubuntu) Assignee: Leonidas S. Barbosa (leosilvab) => Otto Kekäläinen (otto) -- You received this bug

[Bug 1752417] Re: [ffe] including network-manager-openvpn-gnome, network-manager-l2tp-gnome, and network-manager-strongswan in the default installation

2019-09-17 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1752417 Title: [ffe] including network-manager-openvpn-gnome, network-manager-l2tp- gnome,

[Bug 1771196] Re: daap plugin opens port by default

2019-09-17 Thread Marc Deslauriers
While Rhythmbox does indeed open a port when started, the user needs to start it before the port becomes available. This is no different than opening a Bittorrent client application, or some other application that opens ports. That being said, perhaps the plugin should be disabled by default.

[Bug 1777776] Re: Ubuntu documentation for sssd/kerberos does not authenticate authentication server

2019-09-17 Thread Marc Deslauriers
Has there been any progress on this issue? Thanks! ** Changed in: sssd (Ubuntu) Status: New => Invalid ** Changed in: serverguide Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1775776] Re: GNU bc crashes on some inputs

2019-09-17 Thread Marc Deslauriers
** Changed in: bc (Ubuntu) Status: New => Confirmed ** Changed in: bc (Ubuntu) Importance: Undecided => Low ** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1782225] Re: Cache poisoning vulnerability on the OS level DNS cache in Ubuntu

2019-09-17 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Changed in: dnsmasq (Ubuntu) Status: New => Confirmed ** Changed in: systemd (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1780365] Re: Credentials located in gnome-keyring can be compromised easily

2019-09-17 Thread Marc Deslauriers
** Changed in: gnome-keyring (Ubuntu) Status: New => Confirmed ** Changed in: gnome-keyring (Ubuntu) Importance: Undecided => Low -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1780365

[Bug 1780506] Re: Password visible in systemd password prompt if user types too slow

2019-09-17 Thread Marc Deslauriers
Hi! Have you reported this issue to the upstream systemd developers? If not, could you please report it to them so that it can get fixed? Thanks! ** Changed in: systemd (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which

[Bug 1785687] Re: btrfs send can bypass DAC check with certain capability set

2019-09-17 Thread Marc Deslauriers
Hi, Have you reported this issue to the upstream developers? Thanks! ** Changed in: linux-signed (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1785687

[Bug 1791691] Re: PATH broken in systemd units

2019-09-17 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1791691 Title: PATH broken in systemd units To manage notifications about this bug go to:

[Bug 1801383] Re: the WifiSyslog apport hook (used in firefox/tb) includes SSID informations

2019-09-17 Thread Marc Deslauriers
Olivier, Did this fix make it to Thunderbird? Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1801383 Title: the WifiSyslog apport hook (used in firefox/tb) includes SSID

[Bug 1797161] Re: GNOME Image Viewer (EOG): invalid XPM file causes dynamic memory allocation

2019-09-17 Thread Marc Deslauriers
** Changed in: eog (Ubuntu) Status: New => Incomplete ** Changed in: eog (Ubuntu) Status: Incomplete => Invalid ** Changed in: gdk-pixbuf (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 1801383] Re: the WifiSyslog apport hook (used in firefox/tb) includes SSID informations

2019-09-17 Thread Marc Deslauriers
Hi Brian, Is this bug on your radar? Thanks! ** Changed in: apport (Ubuntu) Status: New => Confirmed ** Changed in: linux (Ubuntu) Status: Confirmed => Invalid ** Changed in: apport (Ubuntu) Assignee: (unassigned) => Brian Murray (brian-murray) -- You received this bug

[Bug 1797012] Re: Fingerprint login can be changed without authentication

2019-09-17 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1532264 *** https://bugs.launchpad.net/bugs/1532264 I am going to mark this as a dupe of bug 1532264 since it looks to be the same root cause. Thanks! ** Information type changed from Private Security to Public Security ** This bug has been marked a

[Bug 1792004] Re: built-in PATH seems to have sbin and bin out of order; and inconsistent

2019-09-17 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1792004 Title: built-in PATH seems to have sbin and bin out of order; and inconsistent To

[Bug 1812316] Re: systemd: lack of seat verification in PAM module permits spoofing active session to polkit

2019-09-17 Thread Marc Deslauriers
This was fixed a while ago: https://usn.ubuntu.com/3938-1/ Marking this bug as fix released. Thanks! ** Changed in: systemd (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report.

[Bug 1805640]

2019-09-17 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 1822218] Re: clear crashed with SIGSEGV in __libc_start_main()

2019-09-17 Thread Marc Deslauriers
** Attachment removed: "CoreDump.gz" https://bugs.launchpad.net/ubuntu/+source/ncurses/+bug/1822218/+attachment/5250342/+files/CoreDump.gz ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1834577] Re: [security] Consider upgrading mellon for Bionic to be able to change signature method (sha1 is used by default)

2019-09-17 Thread Marc Deslauriers
** Changed in: libapache2-mod-auth-mellon (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1834577 Title: [security] Consider upgrading mellon for Bionic to be

[Bug 1838489] Re: adduser & deluser shell command injection

2019-09-17 Thread Marc Deslauriers
Hi! Have you had a chance to report this issue to Debian? ** Changed in: adduser (Ubuntu) Status: New => Incomplete ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 1841713] Re: It is unlocking the screen when I type my password when caps lock is on

2019-09-17 Thread Marc Deslauriers
Hi, Are you able to reproduce this with a freshly installed Ubuntu? Thanks! ** Package changed: gnome-screensaver (Ubuntu) => gnome-shell (Ubuntu) ** Information type changed from Private Security to Public Security ** Changed in: gnome-shell (Ubuntu) Status: New => Incomplete -- You

[Bug 1841051] Re: gpg password cache is never cleared

2019-09-17 Thread Marc Deslauriers
Hi! Can you reproduce this issue on a freshly installed Ubuntu? ** Changed in: gnupg2 (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1841051 Title: gpg

[Bug 1842131] Re: ibus-ui-gtk3 crashed with SIGSEGV in ibus_bus_get_engines_by_names()

2019-09-17 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1842022 *** https://bugs.launchpad.net/bugs/1842022 ** This bug has been marked a duplicate of private bug 1842022 ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 1843718] Re: I can change password of one administrator from other

2019-09-17 Thread Marc Deslauriers
Closing this bug as per previous comment. Thanks! ** Changed in: gnome-control-center (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1843718 Title: I can

[Bug 1843717] Re: Resolution

2019-09-17 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 1842668] Re: Workspace view is showing before unlocking 19.04

2019-09-17 Thread Marc Deslauriers
** Package changed: ubuntu => gnome-shell (Ubuntu) ** Information type changed from Private Security to Public Security ** Changed in: gnome-shell (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 1844195] Re: beegfs-meta lockup with glibc 2.27 on bionic

2019-09-17 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1843829] Re: Incorrect Sudo configuration

2019-09-17 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Changed in: sudo (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1843829 Title:

[Bug 1841051] Re: gpg password cache is never cleared

2019-08-23 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1841051 Title: gpg password cache is never cleared To manage notifications about

[Bug 1830752] Re: Upstream security fixes in VirtualBox

2019-08-23 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Changed in: virtualbox (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1830752 Title:

[Bug 1840615] Re: Slow booting, slow start-up & once a week fsck issues in Ubuntu 19.04

2019-08-23 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1840587] Re: Código de error: ssl_error_no_cypher_overlap

2019-08-23 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1840786] Re: Xorg freeze

2019-08-23 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1840907] Re: W: Download is performed unsandboxed as root as file

2019-08-23 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 1840529] Re: System drop to emergency shell if encrypted home password was not provided

2019-08-23 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1841055] Re: Grub is not install in nouveau.modeset=0 acpi=off in ubuntu 19.04

2019-08-23 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1841044] Re: grub2 problem

2019-08-23 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1840404] Re: [regression] 1.14.0-0ubuntu1.4 security update enables TLS1.3 without a choice

2019-08-16 Thread Marc Deslauriers
I have tested the packages currently in bionic-proposed. and they pass the security team test script, and also no longer offer TLSv1.3 when not requested. ACK on releasing. ** Tags removed: verification-needed verification-needed-bionic ** Tags added: verification-done verification-done-bionic

[Bug 1840404] Re: [regression] 1.14.0-0ubuntu1.4 security update enables TLS1.3 without a choice

2019-08-16 Thread Marc Deslauriers
** Changed in: nginx (Ubuntu Bionic) Status: New => Confirmed ** Changed in: nginx (Ubuntu Bionic) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: nginx (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member

[Bug 1839596] Re: imagemagick 8:6.9.10.23+dfsg-2.1ubuntu3 broke reverse-deps

2019-08-13 Thread Marc Deslauriers
I will certainly help fix any packages that FTBFS because of this change, please feel free to assign me to bugs about them. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1839596 Title: imagemagick

[Bug 1839596] Re: imagemagick 8:6.9.10.23+dfsg-2.1ubuntu3 broke reverse-deps

2019-08-13 Thread Marc Deslauriers
We will not be reverting this. The security team does not wish for pdf support in imagemagick to be enabled by default. The best approach here is to disable the pdf generation in the two packages that now break because of this change. ** Changed in: imagemagick (Ubuntu Bionic) Status:

[Bug 1837734] Re: Firefox crash on a FIPS enabled machine due to libnss3

2019-07-24 Thread Marc Deslauriers
ACK on the debdiffs. Uploaded to eoan and to previous releases for processing by the SRU team, with slight versioning adjustment and the bug tag added to the changelog. Thanks! ** Changed in: nss (Ubuntu Xenial) Status: Confirmed => In Progress ** Changed in: nss (Ubuntu Bionic)

[Bug 1837734] Re: Firefox crash on a FIPS enabled machine due to libnss3

2019-07-24 Thread Marc Deslauriers
** Also affects: nss (Ubuntu Eoan) Importance: High Assignee: Vineetha Kamath (vineetha) Status: New ** Also affects: nss (Ubuntu Xenial) Importance: Undecided Status: New ** Also affects: nss (Ubuntu Disco) Importance: Undecided Status: New ** Also affects:

[Bug 1836067] Re: Consider reenabling png to eps conversion in ImageMagick in disco

2019-07-10 Thread Marc Deslauriers
We will not be re-enabling this. Parsing arbitrary postscript is too dangerous to leave it enabled by default. Newer versions of ImageMagick have disabled it by default also. In environments where this functionality is required, it can be turned back on by locally modifying the

[Bug 1835135] Re: FIPS OpenSSL crashes Python2 hashlib

2019-07-10 Thread Marc Deslauriers
ium ** Changed in: python3.5 (Ubuntu Xenial) Status: New => In Progress ** Changed in: python3.5 (Ubuntu Xenial) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: python2.7 (Ubuntu Xenial) Importance: Undecided => Medium ** Changed in: python2.7 (Ubuntu Xe

[Bug 1832919] Re: installed libssl1.1:amd64 package post-installation script subprocess returned error exit status 10

2019-07-08 Thread Marc Deslauriers
** Tags removed: verification-needed-bionic ** Tags added: verification-done-bionic -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1832919 Title: installed libssl1.1:amd64 package post-installation

[Bug 1834129] Re: Presence of sshd_config mandatory

2019-07-03 Thread Marc Deslauriers
Thanks for updating the bug! I'll close it now. ** Changed in: openssh (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1834129 Title: Presence of

[Bug 1834494] Re: latest bzip2 reports crc errors incorrectly

2019-06-28 Thread Marc Deslauriers
** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1834494 Title: latest bzip2 reports crc errors incorrectly To manage notifications about

[Bug 1819406] Re: Found broken a feature for fingerprint image obfuscation

2019-06-28 Thread Marc Deslauriers
** Changed in: libfprint (Ubuntu) Status: New => Confirmed ** Changed in: libfprint (Ubuntu) Importance: High => Low ** Changed in: libfprint (Ubuntu) Importance: Low => High ** Also affects: libfprint via https://gitlab.freedesktop.org/libfprint/fprintd/issues/16 Importance:

[Bug 1818596] Re: Inbuilt KORN Arithmetic & Test functions broken under Windows Subsystem for Linux

2019-06-28 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1818596 Title: Inbuilt KORN Arithmetic & Test functions broken under Windows Subsystem for

[Bug 1830987] Re: Cannot change directory owner or group

2019-06-28 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1830987 Title: Cannot change directory owner or group To manage notifications about

[Bug 1823574] Re: CVE-2018-3750: Prototype Pollution

2019-06-28 Thread Marc Deslauriers
** Changed in: node-deep-extend (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1823574 Title: CVE-2018-3750: Prototype Pollution To manage

[Bug 1828116] Re: Password works uppercase and lowercase

2019-06-28 Thread Marc Deslauriers
** Changed in: gdm3 (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1828116 Title: Password works uppercase and lowercase To manage notifications about this

[Bug 1825474] Re: Storing plain text private key password on the system (Security Issue)

2019-06-28 Thread Marc Deslauriers
** Changed in: network-manager-openvpn (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1825474 Title: Storing plain text private key password on the

[Bug 1829071] Re: Privilege escalation via LXD (local root exploit)

2019-06-28 Thread Marc Deslauriers
** Changed in: lxd (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1829071 Title: Privilege escalation via LXD (local root exploit) To manage notifications

[Bug 1833865] Re: ubuntu wont install on my chromebook. My chromebook is Dell chromebook 11 3120

2019-06-28 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1833809] Re: TouchPad and Mousepad not working

2019-06-28 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1833474] Re: Radom & frequent total crashes since upgrade to 19.04

2019-06-28 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1834549] Re: Wifi won't load

2019-06-28 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1833838] Re: package intel-microcode 3.20190618.0ubuntu0.16.04.1 failed to install/upgrade: package intel-microcode is already installed and configured

2019-06-28 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1832701] Re: kglobalaccel5 crashed with SIGABRT in raise()

2019-06-28 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1832701 Title: kglobalaccel5 crashed with SIGABRT in raise() To manage notifications about

[Bug 1834494] Re: latest bzip2 reports crc errors incorrectly

2019-06-28 Thread Marc Deslauriers
** Bug watch added: gitlab.com/federicomenaquintero/bzip2/issues #24 https://gitlab.com/federicomenaquintero/bzip2/issues/24 ** Also affects: bzip2 via https://gitlab.com/federicomenaquintero/bzip2/issues/24 Importance: Unknown Status: Unknown -- You received this bug

[Bug 1832337] Re: Require password when starting usb-creator

2019-06-18 Thread Marc Deslauriers
This will also require usb-creator to be modified to have a single policykit prompt. ** Also affects: usb-creator (Ubuntu) Importance: Undecided Status: New ** Changed in: usb-creator (Ubuntu) Assignee: (unassigned) => Ubuntu Security Team (ubuntu-security) ** Changed in:

[Bug 1828215] Re: openssl ca -spkac output regressed

2019-06-13 Thread Marc Deslauriers
I have run bionic-proposed cosmic-proposed and disco-proposed through the usual security team test procedure. They can be released with the fix for CVE-2019-1543. ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-1543 -- You received this bug notification because you are a

[Bug 1828215] Re: openssl ca -spkac output regressed

2019-06-13 Thread Marc Deslauriers
ACK from the security team on the low CVE being included in this SRU. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1828215 Title: openssl ca -spkac output regressed To manage notifications about

[Bug 1832522] Re: openssl maintainer scripts do not trigger services restart

2019-06-13 Thread Marc Deslauriers
ACK from the security team on the low CVE being included in this SRU. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1832522 Title: openssl maintainer scripts do not trigger services restart To

[Bug 1832397] Re: dbus errors and running older version

2019-06-12 Thread Marc Deslauriers
> If you go to It Linux kernel web page you see kernel is at 5.1.x Your issues are caused by the fact that you're running an unsupported kernel that isn't configured to work properly with Ubuntu. Please switch back to running a proper Ubuntu kernel. -- You received this bug notification because

[Bug 1832397] Re: dbus errors and running older version

2019-06-12 Thread Marc Deslauriers
Hi, > Linux bitfenix-server 5.1.6-050106-generic #201905311031 SMP Fri May 31 That's not an Ubuntu kernel. Did you install a custom kernel? > dbus[19216]: Failed to start message bus: Failed to open "/etc/selinux/default/contexts/dbus_contexts": No such file or directory It looks like dbus

[Bug 1832397] Re: dbus errors and running older version

2019-06-11 Thread Marc Deslauriers
Where exactly are you seeing that message? Does it work after rebooting? ** Changed in: dbus (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1832397 Title:

[Bug 1832257] Re: regression: sudo returns exit code 0 if child is killed with SIGTERM

2019-06-10 Thread Marc Deslauriers
I'll release it tomorrow. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1832257 Title: regression: sudo returns exit code 0 if child is killed with SIGTERM To manage notifications about this bug

[Bug 1832257] Re: regression: sudo returns exit code 0 if child is killed with SIGTERM

2019-06-10 Thread Marc Deslauriers
I've uploaded it to build in the following PPA: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages You can get it from there if you need it before tomorrow. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1832257] Re: regression: sudo returns exit code 0 if child is killed with SIGTERM

2019-06-10 Thread Marc Deslauriers
Oh wow, I'm not sure how that happened. I'll release an update for this. ** Changed in: sudo (Ubuntu) Status: New => Confirmed ** Changed in: sudo (Ubuntu) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Also affects: sudo (Ubuntu Xenial) Importance: Und

[Bug 1807983] Re: Update gnome-desktop3 to 3.30.2

2019-05-27 Thread Marc Deslauriers
This package has been superseded by the following security update: https://usn.ubuntu.com/3994-1/ The current packages in -proposed needs to be respun to include the security fix. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1807127] Re: Fixing bug #1795668 breaks thumbnail creation on 32-bit Ubuntu

2019-05-27 Thread Marc Deslauriers
This package has been superseded by the following security update: https://usn.ubuntu.com/3994-1/ The current packages in -proposed needs to be respun to include the security fix. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1827924] Re: Panic or segfault in Samba

2019-05-27 Thread Marc Deslauriers
** Changed in: samba (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1827924 Title: Panic or segfault in Samba To manage notifications about this

[Bug 1823872] Re: Fixing fsfreeze-hook can break unattended upgrades

2019-05-24 Thread Marc Deslauriers
There are qemu packages for testing in the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1823872

[Bug 1827924] Re: Panic or segfault in Samba

2019-05-23 Thread Marc Deslauriers
I have uploaded packages that contain the bugfix that likely solves this issue to the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Once they are finished building, please test the packages, and if they seem to resolve the issue, I will

[Bug 1827924] Re: Panic or segfault in Samba

2019-05-23 Thread Marc Deslauriers
** Also affects: samba via https://bugzilla.samba.org/show_bug.cgi?id=13315 Importance: Unknown Status: Unknown -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1827924 Title: Panic or

[Bug 1827924] Re: Panic or segfault in Samba

2019-05-23 Thread Marc Deslauriers
New => Confirmed ** Changed in: samba (Ubuntu Xenial) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: samba (Ubuntu Bionic) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) -- You received this bug notification because you are a member of Ubuntu

[Bug 1829754] Re: Panic or segfault in Samba after migration to Ubuntu 16.04.6

2019-05-23 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1827924 *** https://bugs.launchpad.net/bugs/1827924 ** This bug has been marked a duplicate of bug 1827924 Panic or segfault in Samba -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

<    4   5   6   7   8   9   10   11   12   13   >