[Bug 2065728] Re: CVE-2024-3044

2024-05-15 Thread Marc Deslauriers
Since they are new upstream versions, and are already going through the SRU process, I'll wait until they are verified-done, and I will do a no- change rebuild of them into the -security pocket. Does that sound reasonable? Thanks! -- You received this bug notification because you are a member

[Bug 2065728] Re: CVE-2024-3044

2024-05-15 Thread Marc Deslauriers
Thanks for the debdiffs, I will prepare packages in the security PPA and will comment back -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2065728 Title: CVE-2024-3044 To manage notifications about

[Bug 2062389] Re: [SRU] Fix segfault in systemdunitdependency probe

2024-04-26 Thread Marc Deslauriers
ACK on the debdiffs. Uploaded for processing by the SRU team. Thanks! ** Changed in: openscap (Ubuntu Focal) Status: New => In Progress ** Changed in: openscap (Ubuntu Jammy) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 2060880] Re: squid crashes after update to 4.10-1ubuntu1.10

2024-04-23 Thread Marc Deslauriers
The regression fix has now been published: https://ubuntu.com/security/notices/USN-6728-3 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2060880 Title: squid crashes after update to

[Bug 2062916] Re: evolution has undefined symbol in newest libwebkit2gtk

2024-04-22 Thread Marc Deslauriers
That is pretty odd, I can't reproduce this issue on jammy. what's the output of "ldd /lib/x86_64-linux- gnu/libwebkit2gtk-4.0.so.37"? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2062916 Title:

[Bug 2060880] Re: squid crashes after update to 4.10-1ubuntu1.10

2024-04-22 Thread Marc Deslauriers
Thanks for testing it, it's much appreciated! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2060880 Title: squid crashes after update to 4.10-1ubuntu1.10 To manage notifications about this bug go

[Bug 2060880] Re: squid crashes after update to 4.10-1ubuntu1.10

2024-04-19 Thread Marc Deslauriers
I have located the issue and have prepared an updated package that will reintroduce the fixes for CVE-2023-5824. I have uploaded the updated package to the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Once it has finished building, could

[Bug 2061816] Re: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired

2024-04-16 Thread Marc Deslauriers
That's good to see! Since this is a deliberate side-effect of the security change, I am marking this bug as "invalid". Thanks ** Changed in: apache2 (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 2061816] Re: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired

2024-04-16 Thread Marc Deslauriers
I think this is actually the correct new behaviour for the security update...could you please try using ap_trust_cgilike_cl as instructed here: https://bz.apache.org/bugzilla/show_bug.cgi?id=68872 ** Bug watch added: bz.apache.org/bugzilla/ #68872

[Bug 2061816] Re: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired

2024-04-16 Thread Marc Deslauriers
Thanks for testing, I'll keep digging... -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2061816 Title: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired To

[Bug 2061816] Re: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired

2024-04-16 Thread Marc Deslauriers
I have uploaded a package with a possible fix to the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Once it's finished building, could you please give it a try and see if it solves the issue for you? If so, I will publish it as a security

[Bug 2061816] Re: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired

2024-04-16 Thread Marc Deslauriers
I believe I've spotted the regression and will have a package to test soon. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2061816 Title: apache2 2.4.41-4ubuntu3.17 defaults to

[Bug 2061816] Re: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired

2024-04-16 Thread Marc Deslauriers
Thanks for filing this bug, I'll investigate the changes and will report back. Have you seen this behaviour on anything other than focal? ** Changed in: apache2 (Ubuntu) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Information type changed from Public to Public Secur

[Bug 2058023] Re: New versions of amavis with security fixes

2024-04-15 Thread Marc Deslauriers
There are packages for focal, jammy, and mantic available for testing in the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages If they work in your environment, please mention it in this bug. Thanks! -- You received this bug notification

[Bug 2053215] Re: postinst didn't ask for configuration → SECURITY ISSUE

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2054197] Re: update-manager crashed with TypeError in _look_busy(): constructor returned NULL

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2051543] Re: When I use a keyboard shortcut to lower a window, the window retains its keyboard focus.

2024-04-12 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2051543 Title: When I use a keyboard shortcut to lower a window, the window retains its

[Bug 2058023] Re: New versions of amavis with security fixes

2024-04-12 Thread Marc Deslauriers
** Changed in: amavisd-new (Ubuntu) Status: New => Confirmed ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2058023 Title:

[Bug 2059265] Re: Kubuntu bluetooth wireles keyboard not see.

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2058298] Re: intel-ipu6-dkms 0~git202211220708.278b7e3d-0ubuntu0.22.04.1: ipu6-drivers kernel module failed to build

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2059224] Re: package linux-image-5.15.0-101-generic 5.15.0-101.111~20.04.1 failed to install/upgrade: run-parts: /etc/kernel/postinst.d/initramfs-tools exited with return code 1

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2059883] Re: package unixodbc-common 2.3.9-5 failed to install/upgrade: trying to overwrite '/etc/odbc.ini', which is also in package odbcinst 2.3.11-1

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2059822] Re: package linux-intel-iotg-tools-common 5.15.0-1050.56 [modified: usr/share/man/man1/perf-annotate.1.gz usr/share/man/man1/perf-archive.1.gz usr/share/man/man1/perf-bench.1.gz usr/shar

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2060174] Re: i run a program at night and when i come back in the morning the system is unresponsive

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2060372] Re: Siempre me sale este error

2024-04-12 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 2060378] Re: ubuntu stuck at every day

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2060398] Re: xfsettingsd crashed with SIGTRAP in g_log_writer_default()

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2060438] Re: laptop internal stereo microphone not detected by ubuntu but detected by windows 11

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2060752] Re: package samba-common 2:4.15.13+dfsg-0ubuntu1.6 failed to install/upgrade: el subproceso instalado paquete samba-common script post-installation devolvió el código de salida de error

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2060859] Re: Xorg freeze

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2060900] Re: gst-plugin-scanner crashed with SIGABRT in __assert_fail_base()

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2060961] Re: package libc6 2.35-0ubuntu3.1 failed to install/upgrade: subproces van het nieuwe pakket libc6:amd64 het script pre-installation gaf de foutwaarde 2 terug

2024-04-12 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2060906] Re: attempt to add opensc using modutil suddenly fails

2024-04-11 Thread Marc Deslauriers
@adampankow: the bug only applied to focal and jammy, which are marked as "fix released", the "invalid" task is the development release noble, which isn't affected by this bug. This looks a bit odd, but it's how launchpad bugs work. -- You received this bug notification because you are a member

[Bug 2060906] Re: attempt to add opensc using modutil suddenly fails

2024-04-11 Thread Marc Deslauriers
https://ubuntu.com/security/notices/USN-6727-2 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2060906 Title: attempt to add opensc using modutil suddenly fails To manage notifications about this

[Bug 2060906] Re: attempt to add opensc using modutil suddenly fails

2024-04-11 Thread Marc Deslauriers
** Changed in: nss (Ubuntu) Status: Confirmed => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2060906 Title: attempt to add opensc using modutil suddenly fails To manage

[Bug 2060906] Re: attempt to add opensc using modutil suddenly fails

2024-04-11 Thread Marc Deslauriers
Thanks for testing, I'll publish the regression fix as soon as all archs have finished building. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2060906 Title: attempt to add opensc using modutil

[Bug 2060906] Re: attempt to add opensc using modutil suddenly fails

2024-04-11 Thread Marc Deslauriers
I have uploaded packages that fix this issue for focal and jammy to the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Once they have finished building, please test them to make sure they fix the issue for you, and I will publish them as a

[Bug 2060906] Re: attempt to add opensc using modutil suddenly fails

2024-04-11 Thread Marc Deslauriers
(Ubuntu Focal) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: nss (Ubuntu Jammy) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: nss (Ubuntu Focal) Status: New => In Progress ** Changed in: nss (Ubuntu Jammy) St

[Bug 2060968] Re: SafeNet Authentication Client eToken driver error

2024-04-11 Thread Marc Deslauriers
*** This bug is a duplicate of bug 2060906 *** https://bugs.launchpad.net/bugs/2060906 This is the same core issue as bug #2060906, so marking as a duplicate, please follow the progress in that bug. Thanks! ** This bug has been marked a duplicate of bug 2060906 attempt to add opensc using

[Bug 2060968] Re: SafeNet Authentication Client eToken driver error

2024-04-11 Thread Marc Deslauriers
** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2060968 Title: SafeNet Authentication Client eToken driver error To manage notifications

[Bug 2060906] Re: attempt to add opensc using modutil suddenly fails

2024-04-11 Thread Marc Deslauriers
** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2060906 Title: attempt to add opensc using modutil suddenly fails To manage notifications

[Bug 2060880] Re: squid crashes after update to 4.10-1ubuntu1.10

2024-04-11 Thread Marc Deslauriers
https://ubuntu.com/security/notices/USN-6728-2 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2060880 Title: squid crashes after update to 4.10-1ubuntu1.10 To manage notifications about this bug go

[Bug 2060880] Re: squid crashes after update to 4.10-1ubuntu1.10

2024-04-11 Thread Marc Deslauriers
Thanks for testing everyone, and thanks for the configuration details. I will attempt to reproduce this issue so that I can figure out what exactly caused the regression so that we can get CVE-2023-5824 fixed again soon. -- You received this bug notification because you are a member of Ubuntu

[Bug 2060880] Re: squid crashes after update to 4.10-1ubuntu1.10

2024-04-10 Thread Marc Deslauriers
** Information type changed from Public to Public Security ** Changed in: squid (Ubuntu) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: squid (Ubuntu) Importance: Undecided => Critical -- You received this bug notification because you are a member of Ubunt

[Bug 2060880] Re: squid crashes after update to 4.10-1ubuntu1.10

2024-04-10 Thread Marc Deslauriers
I have prepared an update with the patches for CVE-2023-5824 backed out as they were extensive and are the most likely cause of this regression. I have uploaded it to the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Once the package has

[Bug 2060880] Re: squid crashes after update to 4.10-1ubuntu1.10

2024-04-10 Thread Marc Deslauriers
Thanks for reporting this issue. What configuration is this squid server used in? I would like to reproduce the issue, but I need more details to set up a similar environment. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2041837] Re: squid:update to 6.4+ get fixes for CVEs

2024-04-10 Thread Marc Deslauriers
More CVE fixes have gone in here: https://ubuntu.com/security/notices/USN-6728-1 I believe there are no more open CVEs for Squid, so I am closing this bug. Thanks! ** Changed in: squid (Ubuntu Focal) Status: Confirmed => Fix Released ** Changed in: squid (Ubuntu Jammy) Status:

[Bug 2060014] Re: CVE-2024-2947 command injection when deleting a sosreport with a crafted name

2024-04-09 Thread Marc Deslauriers
@pitti: mantic will be EoL in a couple of months, I think if you want the fix in quickly, having the minimal fix would be the fastest way to do it, though you may decide it's not worth it seeing as the release will be ending soon. -- You received this bug notification because you are a member of

[Bug 1597017] Re: mount rules grant excessive permissions

2024-03-29 Thread Marc Deslauriers
FYI This is now in the jammy and focal upload queues to go to -proposed. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1597017 Title: mount rules grant excessive permissions To manage

[Bug 1976556] Re: [Lenovo 300e 2nd GEN] ELAN Touchpad not working

2024-03-27 Thread Marc Deslauriers
There's a relevant thread here: https://lore.kernel.org/all/27131a7fae2794a63f4f285a20e41116ba4198f3.ca...@gmail.com/T/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1976556 Title: [Lenovo 300e

[Bug 2058743] Re: systemd local DNS tests failing with timeout

2024-03-22 Thread Marc Deslauriers
It appears most of the systemd autopkgtest failures are because of this flaky test: https://autopkgtest.ubuntu.com/packages/systemd/jammy/amd64 The effort required to manually retrigger systemd autopkgtests because of that flaky test is substantial. We should disable that particular test unless

[Bug 2058743] Re: systemd local DNS tests failing with timeout

2024-03-22 Thread Marc Deslauriers
The same issue was present with the old dnsmasq package...for example: https://autopkgtest.ubuntu.com/results/autopkgtest- jammy/jammy/amd64/s/systemd/20240224_133847_88f29@/log.gz -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2058053] Re: Change sudo compile options from --with-all-insults to --with-pc-insults

2024-03-18 Thread Marc Deslauriers
t; Confirmed ** Changed in: sudo (Ubuntu Noble) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2058053 Title: Change sudo compile options

[Bug 2058053] Re: Change sudo compile options from --with-all-insults to --with-pc-insults

2024-03-18 Thread Marc Deslauriers
I'll fix this issue in noble. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2058053 Title: Change sudo compile options from --with-all-insults to --with-pc- insults To manage notifications about

[Bug 2058053] Re: Change sudo compile options from --with-all-insults to --with-pc-insults

2024-03-18 Thread Marc Deslauriers
Could you please file a bug upstream about the missing change, and let us know the bug number? https://bugzilla.sudo.ws/index.cgi -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2058053 Title:

[Bug 2058053] Re: Change sudo compile options from --with-all-insults to --with-pc-insults

2024-03-18 Thread Marc Deslauriers
Actually, I think you're right, the brains one does seem to be included because while that upstream patch does do the following to plugins/sudoers/ins_classic.h, it didn't apply the same change to plugins/sudoers/ins_csops.h: -#ifdef PC_INSULTS +#ifndef OFFENSIVE_INSULTS -- You received this

[Bug 2058053] Re: Change sudo compile options from --with-all-insults to --with-pc-insults

2024-03-15 Thread Marc Deslauriers
Great, I'll leave this bug open for now. Please let us know if there is anything that is enabled that shouldn't be. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2058053 Title: Change sudo

[Bug 2058053] Re: Change sudo compile options from --with-all-insults to --with-pc-insults

2024-03-15 Thread Marc Deslauriers
I'm not sure I understand this bug, the --with-pc-insults option is deprecated since 2017-09-18 as it is the default option. The noble package doesn't use --enable-offensive-insults. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2056690] Re: FFe: version 0.58 introduces a new field

2024-03-12 Thread Marc Deslauriers
Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2056690 Title: FFe: version 0.58 introduces a new field To manage notifications about this bug go to:

[Bug 2056690] Re: FFe: version 0.58 introduces a new field

2024-03-10 Thread Marc Deslauriers
** Attachment added: "Build log" https://bugs.launchpad.net/ubuntu/+source/pasaffe/+bug/2056690/+attachment/5754633/+files/pasaffe_0.58-0ubuntu1_amd64.build -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2056690] Re: FFe: version 0.58 introduces a new field

2024-03-10 Thread Marc Deslauriers
NEWS file: 0.58 (2024-03-09) * Enhancements: - Add email field - Updated translations * Bug fixes: - Fix some deprecation warnings in the test suite -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2056690] Re: FFe: version 0.58 introduces a new field

2024-03-10 Thread Marc Deslauriers
** Attachment added: "ChangeLog" https://bugs.launchpad.net/ubuntu/+source/pasaffe/+bug/2056690/+attachment/5754632/+files/ChangeLog -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2056690 Title:

[Bug 2056690] [NEW] FFe: version 0.58 introduces a new field

2024-03-10 Thread Marc Deslauriers
Public bug reported: I would like to request a FFe for version 0.58 of Pasaffe. The new version updates translations, and adds a single feature: displaying the email field from the password database which has been requested for a long time, but I had not had time to implement it until now. It's

[Bug 2055776] Re: After updating ubuntu, the network to which the subnet address is assigned does not become active in KVM.

2024-03-04 Thread Marc Deslauriers
I am marking this bug as "invalid" per your last comment. Thanks! ** Changed in: dnsmasq (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2055776 Title: After

[Bug 2055776] Re: After updating ubuntu, the network to which the subnet address is assigned does not become active in KVM.

2024-03-04 Thread Marc Deslauriers
By default bind will listen on all interfaces. I don't understand why we're not seeing anything listening on 192.168.122.1 but you are still getting the error message. I suggest adding a listen-on directive to your /etc/bind/named.conf.options file, restarting bind, and seeing if libvirt will now

[Bug 2055455] Re: dnsmasq-base causes network device virbr0 to shut down

2024-03-03 Thread Marc Deslauriers
That is great news, I'm glad we've identified the root cause of the problem and you have successfully resolved it. I will mark this bug as invalid since, while the dnsmasq update did change behaviour, the behaviour change revealed a configuration issue rather than being an actual regression.

[Bug 2055455] Re: dnsmasq-base causes network device virbr0 to shut down

2024-03-02 Thread Marc Deslauriers
So, it looks like you are running bind on this machine, and bind is listening on port 53 UDP: udp0 0 192.168.122.1:530.0.0.0:* 1521/named The old dnsmasq would ignore the error when it couldn't bind to a port, but the new dnsmasq will fail if the port is already used, which

[Bug 2055455] Re: dnsmasq-base causes network device virbr0 to shut down

2024-03-02 Thread Marc Deslauriers
What's the output of "sudo netstat --tcp --udp --listening --programs --numeric"? Thanks! ** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2055776] Re: After updating ubuntu, the network to which the subnet address is assigned does not become active in KVM.

2024-03-02 Thread Marc Deslauriers
** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2055776 Title: After updating ubuntu, the network to which the subnet address is assigned

[Bug 2055776] Re: After updating ubuntu, the network to which the subnet address is assigned does not become active in KVM.

2024-03-02 Thread Marc Deslauriers
Do you know what else could be listening on that interface? What's the output of "netstat --tcp --udp --listening --programs --numeric"? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2055776 Title:

[Bug 2055776] Re: After updating ubuntu, the network to which the subnet address is assigned does not become active in KVM.

2024-03-02 Thread Marc Deslauriers
I will prepare updates for testing with the problematic commit reverted. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2055776 Title: After updating ubuntu, the network to which the subnet address

[Bug 2055776] Re: After updating ubuntu, the network to which the subnet address is assigned does not become active in KVM.

2024-03-02 Thread Marc Deslauriers
Out of curiosity, what is the contents of your /etc/dnsmasq.d directory? Is there a symlink in there to /etc/dnsmasq.d-available/libvirt-daemon? What is the contents of that file? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2055455] Re: dnsmasq-base causes network device virbr0 to shut down

2024-03-02 Thread Marc Deslauriers
This may be caused by the same issue as bug 2055776. I am preparing updated packages with the problematic commit reverted for testing. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2055455 Title:

[Bug 2055776] Re: After updating ubuntu, the network to which the subnet address is assigned does not become active in KVM.

2024-03-02 Thread Marc Deslauriers
Thanks for filing this bug, and the excellent analysis. So it looks like the dnsmasq change was introduced here: https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=744231d99505cdead314d13506b5ff8c44a13088 That was in response to this mailing list discussion:

[Bug 2055455] Re: dnsmasq-base causes network device virbr0 to shut down

2024-03-01 Thread Marc Deslauriers
Hi, What the contents of the /etc/dnsmasq.d directory? Is there a symlink to /etc/dnsmasq.d-available/libvirt-daemon ? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2055455 Title: dnsmasq-base

[Bug 2052739] Re: tzdata 2024a release

2024-02-29 Thread Marc Deslauriers
+1 from security. Please remember to also release it to the -security pocket on all releases in addition to just -updates. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2052739 Title:

[Bug 2028413] Re: MRE updates of bind9 for focal, jammy and lunar

2024-02-28 Thread Marc Deslauriers
bind9 9.16.48 is now in focal with the latest security update. ** Changed in: bind-dyndb-ldap (Ubuntu Focal) Status: Triaged => Fix Released ** Changed in: bind9 (Ubuntu Focal) Status: Triaged => Fix Committed ** Changed in: bind-dyndb-ldap (Ubuntu Focal) Status: Fix

[Bug 2046609] Re: sync request: netatalk 3.1.18~ds-1 Debian sid main

2024-01-19 Thread Marc Deslauriers
** Changed in: netatalk (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/2046609 Title: sync request: netatalk 3.1.18~ds-1 Debian sid main To manage

[Bug 2007272]

2023-03-17 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 2007380] Re: Power manager locks screen but does not show lock-screen

2023-03-17 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 2009082] Re: SDK version in LTS EOL

2023-03-17 Thread Marc Deslauriers
Making this bug public to the Ubuntu community can see it and perhaps propose a fix for the issue. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/2009082 Title: SDK version in LTS

[Bug 2007456] Re: CVE-2023-20032: Fixed a possible remote code execution vulnerability in the HFS+ file parser.

2023-02-20 Thread Marc Deslauriers
We are currently working on updates, and they should be released within the next few days. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/2007456 Title: CVE-2023-20032: Fixed a possible

[Bug 2007456] Re: CVE-2023-20032: Fixed a possible remote code execution vulnerability in the HFS+ file parser.

2023-02-16 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Also affects: clamav (Ubuntu Kinetic) Importance: Undecided Status: New ** Also affects: clamav (Ubuntu Bionic) Importance: Undecided Status: New ** Also affects: clamav (Ubuntu Lunar) Importance:

[Bug 1997220] Re: CVE-2022-42898

2022-12-06 Thread Marc Deslauriers
** Changed in: samba (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1997220 Title: CVE-2022-42898 To manage notifications about this bug go to:

[Bug 1983778] Re: Major security issue in Ubuntu Desktop default config - Removable Media

2022-09-23 Thread Marc Deslauriers
I personally don't think the reasons you've listed above are good enough to change the default setting, but please file a bug with the upstream project and you can convince them to change them: https://gitlab.gnome.org/GNOME/gnome-control-center/-/issues Once you've filed a bug with the GNOME

[Bug 1930140] Re: GUI "Extract Here" bug - loop until disk is full

2022-08-24 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1838067] Re: made Ubuntu very slow then crash

2022-08-24 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1970779] Re: Upgrade to 2.36.6 for Focal and Jammy

2022-08-17 Thread Marc Deslauriers
I can't get cog to work on 20.04: $ cog -P x11 https://ubuntu.com ** (cog:4346): WARNING **: 14:11:55.892: Could not load: libcogplatform-x11.so (possible cause: Resource temporarily unavailable). wpe: could not load the impl library. Is there any backend installed?: libWPEBackend-default.so:

[Bug 1970779] Re: Upgrade to 2.36.6 for Focal and Jammy

2022-08-17 Thread Marc Deslauriers
Please give details on how you are testing these updates. We will not be sponsoring packages that haven't been tested, and that we are unable to test ourselves. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report.

[Bug 1974265] Re: `demangle_const` causes infinite recursion and stack overflow

2022-08-10 Thread Marc Deslauriers
** Changed in: binutils (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1974265 Title: `demangle_const` causes infinite recursion and stack overflow

[Bug 1978821] Re: libbrotli1 upgrade to 1.0.9 due to security

2022-06-23 Thread Marc Deslauriers
Ah yes, that CVE was fixed in all our releases, so I am marking this bug as invalid. Thanks! ** Changed in: brotli (Ubuntu) Status: Confirmed => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report.

[Bug 1978821] Re: libbrotli1 upgrade to 1.0.9 due to security

2022-06-22 Thread Marc Deslauriers
I'm making this bug public, since the issue is listed on a public page. Curiously, I could not find a CVE for this issue. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1978821 Title:

[Bug 1978821] Re: libbrotli1 upgrade to 1.0.9 due to security

2022-06-22 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Changed in: brotli (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1978821

[Bug 1970779] Re: Upgrade to 2.36.3 for Focal, Impish and Jammy

2022-06-17 Thread Marc Deslauriers
wpewebkit is basically the same source code as the webkit2gtk package. Since we do allow full version upgrades to webkit2gtk as security updates, it makes sense to allow them for wpewebkit also. That being said, what's the plan to test these updates? Nothing much in the archive seems to depend on

[Bug 1976631] Re: Update to 20211016 bundle

2022-06-02 Thread Marc Deslauriers
Changed in: ca-certificates (Ubuntu Bionic) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: ca-certificates (Ubuntu Focal) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: ca-certificates (Ubuntu Impish) Assignee: (unassigned) => Ma

[Bug 1976631] [NEW] Update to 20211016 bundle

2022-06-02 Thread Marc Deslauriers
) Importance: Undecided Assignee: Marc Deslauriers (mdeslaur) Status: In Progress ** Affects: ca-certificates (Ubuntu Focal) Importance: Undecided Assignee: Marc Deslauriers (mdeslaur) Status: In Progress ** Affects: ca-certificates (Ubuntu Impish) Importance

[Bug 1951988] Re: dpkg-source should fail if maintainer is not ubuntu and DEBEMAIL contains @canonical.com

2022-05-26 Thread Marc Deslauriers
These changes were included as part of the latest security update. ** Changed in: dpkg (Ubuntu Focal) Status: Fix Committed => Fix Released ** Changed in: dpkg (Ubuntu Impish) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of

[Bug 1975602] Re: 2.36.2 security update tracking bug

2022-05-24 Thread Marc Deslauriers
** Changed in: webkit2gtk (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1975602 Title: 2.36.2 security update tracking bug To manage notifications about

[Bug 1975602] [NEW] 2.36.2 security update tracking bug

2022-05-24 Thread Marc Deslauriers
*** This bug is a security vulnerability *** Public security bug reported: Bug to track the 2.36.2 security update. ** Affects: webkit2gtk (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1974250] Re: ~/.pam_environment gets created as owned by root

2022-05-24 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Also affects: accountsservice (Ubuntu Jammy) Importance: Undecided Status: New ** Also affects: accountsservice (Ubuntu Kinetic) Importance: High Status: Fix Released ** Changed in: accountsservice

  1   2   3   4   5   6   7   8   9   10   >