Your message dated Sat, 06 Jun 2020 15:22:11 +0000
with message-id <[email protected]>
and subject line Bug#960465: fixed in thunderbird 1:68.9.0-1
has caused the Debian Bug report #960465,
regarding thunderbird: Xfce "preferred browser" setting ignored when AppArmor
profile is enabled
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
960465: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=960465
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: thunderbird
Version: 1:68.8.0-1~deb10u1
Severity: minor
When running Thunderbird under Xfce with
/etc/apparmor.d/usr.bin.thunderbird enabled, Thunderbird always opens
URLs with sensible-browser, even if that is not the "preferred browser"
selected in Xfce's "Preferred Applications" settings panel
(exo-preferred-applications). After `aa-disable /usr/bin/thunderbird`,
Thunderbird henceforth opens URLs in the right browser.
I suspect this is because the AppArmor profile prohibits exo-open (when
spawned by Thunderbird) from reading ~/.config/xfce4/helpers.rc, which
apparently is where Xfce keeps the user's application selections. When
apparmor is enabled, opening a URL gives me this on Thunderbird's
stderr:
> (exo-helper-1:2307): libxfce4util-CRITICAL **: 17:43:07.428: Failed to parse
> file /home/gnoutchd/.config/xfce4/helpers.rc, ignoring.
And I get this in the journal:
> May 12 17:43:07 tbirdtest audit[2307]: AVC apparmor="DENIED" operation="open"
> profile="thunderbird" name="/home/gnoutchd/.config/xfce4/helpers.rc" pid=2307
> comm="exo-helper-1" requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
> May 12 17:43:07 tbirdtest kernel: audit: type=1400 audit(1589319787.417:43):
> apparmor="DENIED" operation="open" profile="thunderbird"
> name="/home/gnoutchd/.config/xfce4/helpers.rc" pid=2307 comm="exo-helper-1"
> requested_mask="r" denied_mask="r" fsuid=1000 ouid=1000
-- System Information:
Debian Release: 10.4
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 4.19.0-9-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8),
LANGUAGE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages thunderbird depends on:
ii debianutils 4.8.6.1
ii fontconfig 2.13.1-2
ii libatk1.0-0 2.30.0-2
ii libc6 2.28-10
ii libcairo-gobject2 1.16.0-4
ii libcairo2 1.16.0-4
ii libdbus-1-3 1.12.16-1
ii libdbus-glib-1-2 0.110-4
ii libevent-2.1-6 2.1.8-stable-4
ii libffi6 3.2.1-9
ii libfontconfig1 2.13.1-2
ii libfreetype6 2.9.1-3+deb10u1
ii libgcc1 1:8.3.0-6
ii libgdk-pixbuf2.0-0 2.38.1+dfsg-1
ii libglib2.0-0 2.58.3-2+deb10u2
ii libgtk-3-0 3.24.5-1
ii libgtk2.0-0 2.24.32-3
ii libjsoncpp1 1.7.4-3
ii libpango-1.0-0 1.42.4-8~deb10u1
ii libstartup-notification0 0.12-6
ii libstdc++6 8.3.0-6
ii libvpx5 1.7.0-3+deb10u1
ii libx11-6 2:1.6.7-1
ii libx11-xcb1 2:1.6.7-1
ii libxcb-shm0 1.13.1-2
ii libxcb1 1.13.1-2
ii libxext6 2:1.3.3-1+b2
ii libxrender1 1:0.9.10-1
ii libxt6 1:1.1.5-1+b3
ii psmisc 23.2-1
ii x11-utils 7.7+4
ii zlib1g 1:1.2.11.dfsg-1
Versions of packages thunderbird recommends:
ii hunspell-en-us [hunspell-dictionary] 1:2018.04.16-1
pn lightning <none>
Versions of packages thunderbird suggests:
ii apparmor 2.13.2-10
ii fonts-lyx 2.3.2-1
ii libgssapi-krb5-2 1.17-3
-- no debconf information
signature.asc
Description: OpenPGP digital signature
--- End Message ---
--- Begin Message ---
Source: thunderbird
Source-Version: 1:68.9.0-1
Done: Carsten Schoenert <[email protected]>
We believe that the bug you reported is fixed in the latest version of
thunderbird, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Carsten Schoenert <[email protected]> (supplier of updated thunderbird
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 05 Jun 2020 20:29:35 +0200
Source: thunderbird
Architecture: source
Version: 1:68.9.0-1
Distribution: unstable
Urgency: medium
Maintainer: Carsten Schoenert <[email protected]>
Changed-By: Carsten Schoenert <[email protected]>
Closes: 960465
Changes:
thunderbird (1:68.9.0-1) unstable; urgency=medium
.
[ intrigeri ]
* [fd13825] AppArmor: update profile from upstream at commit 860d2d9
(Closes: #960465)
.
[ Carsten Schoenert ]
* [c310c40] New upstream version 68.9.0
Fixed CVE issues in upstream version 68.9.0 (MFSA 2020-22):
CVE-2020-12399: Timing attack on DSA signatures in NSS library
CVE-2020-12405: Use-after-free in SharedWorkerService
CVE-2020-12406: JavaScript Type confusion with NativeTypes
CVE-2020-12410: Memory safety bugs fixed in Thunderbird 68.9.0
CVE-2020-12398: Security downgrade with IMAP STARTTLS leads to
information leakage
Checksums-Sha1:
800a6637e9dae590315aaa043cba7f6b2acf15d9 8310 thunderbird_68.9.0-1.dsc
c9e415a13e14dc86a24d528a70221780c3997748 1030016
thunderbird_68.9.0.orig-lightning-l10n.tar.xz
ce3af96b51fec98584ebeef4135ba41c94d80732 10012652
thunderbird_68.9.0.orig-thunderbird-l10n.tar.xz
c3dca46932529b99242ef26119b07717a2afeb64 354899736
thunderbird_68.9.0.orig.tar.xz
b359d7d7b1b52dea28549b0d668b2aee879e3024 547012
thunderbird_68.9.0-1.debian.tar.xz
5b15e3e15864f3539ab4b2313098207af851777c 35389
thunderbird_68.9.0-1_amd64.buildinfo
Checksums-Sha256:
df113191eebcca570a4e51851efbc973e38c2dc6819bcdd0f48b7350c60fffaa 8310
thunderbird_68.9.0-1.dsc
5aebf93aae21975c63220a9930d3d378ef651a488f51fce099bbab29b726413a 1030016
thunderbird_68.9.0.orig-lightning-l10n.tar.xz
7d4628a0175a13bc1c6f0469b6824cdff9b410a5410257ffdfd844250906d750 10012652
thunderbird_68.9.0.orig-thunderbird-l10n.tar.xz
9f898c066f8854b1a914cd4196448163b46c7072df3dad55f4784d6b5a19807f 354899736
thunderbird_68.9.0.orig.tar.xz
52925d066189fa56df8da7675280116825f963e5914834fe597b3e7d5f80c822 547012
thunderbird_68.9.0-1.debian.tar.xz
24f5ca99024344dbb05909df9b68e18eff61144489433ea624ec2e435de8b116 35389
thunderbird_68.9.0-1_amd64.buildinfo
Files:
4f49ad01af47fb91c4d8423109043a50 8310 mail optional thunderbird_68.9.0-1.dsc
dfd9bba62829d537bd48e3d174aad871 1030016 mail optional
thunderbird_68.9.0.orig-lightning-l10n.tar.xz
5afabd03d7fb0165f1cc1bbb546e16b9 10012652 mail optional
thunderbird_68.9.0.orig-thunderbird-l10n.tar.xz
8f6cb172cbd96bc9c9975967bd915b6e 354899736 mail optional
thunderbird_68.9.0.orig.tar.xz
00cfd9a343a8e2eb148705bf5d0320bb 547012 mail optional
thunderbird_68.9.0-1.debian.tar.xz
97ac6a91f0905c10d25f44890d5f52c9 35389 mail optional
thunderbird_68.9.0-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJMBAEBCgA2FiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAl7brScYHGMuc2Nob2Vu
ZXJ0QHQtb25saW5lLmRlAAoJEIMBYBQlHR2wWccP/3rdMpd1X5skX9PGSL2vA/kO
wDyC/lCYYtgkxtHJcpeZIorIW2/ERGYFebZfJujve0wNBXeyhAJnGnFNnBeUf8XY
Gam2fIDnFjDr+ootxicQxzbFVIFSV4TPLWywCJKLtkwfj2gSTt1jh+hVZdJlB6iv
W98dJR/R7tcTyoH4N4VN+Vnf6n1LidZ6ssfdmckOpZOJoBJ0GwxAuSRdvX6zeR2X
9iy0pp59Qk6RVb8Lyq+iRiUjHieCheaNBhL6T83qj61VugOg8E7AQxHsa+FzvX1a
sbMStbzW4N6BiPtiBFSv064ppM9//wSxdHdTQ6axCLrer1GNkoDuMx9DOxOleSXn
noNpDxzRL0hAy0bCcmFVXY0Je+RQ+JX9/yrdZSl9a6kxZ7PC71/8Ren4Uyfo09d4
El65XQGG9JDEnunEizGHcG3nlHa3PzcYbN2WY+TVFVzVXYIgf+uuZXiP4nqCpjf+
jf28b6GEcPCAH/eUM0n31pSzGN2OEeedRAK5IePbZ/RBeoUhHZrckhWRKauWVh+Y
k47KXcusMgkZ5g/mBJ77QMvEB7m+HRrS9J3nlsB5EdywbQBMgHC0/3i7sSiUVXoD
3lKuHRyh0YHxPmZx/xQrRkOjt2Is7nfsA0i/9rRA5eSnzLlW7nkLaD2LEhIKzwsJ
OkdIpYSBQcY8OkjdIWB3
=uonH
-----END PGP SIGNATURE-----
--- End Message ---