[Bug 2056767] Re: FFe: Sync gnome-software 46.0-4 (universe) from Debian unstable (main) with gnome-software packaging split

2024-04-02 Thread Joshua Peisach
This should not impact Ubuntu Cinnamon as I don't believe there are any
components that specifically rely heavily on gnome-software.
ubuntucinnamon-meta will need to add the new entry for gnome-software-
plugin-deb, but that's about it.

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to gnome-software in Ubuntu.
https://bugs.launchpad.net/bugs/2056767

Title:
  FFe: Sync gnome-software 46.0-4 (universe) from Debian unstable (main)
  with gnome-software packaging split

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/gnome-software/+bug/2056767/+subscriptions


-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1998060] Re: CVE-2022-37290: Pasted zip archive/invalid file causes NPD

2023-02-17 Thread Joshua Peisach
Yep! (Hostname says "2210Test". I meant to say Kinetic but it doesn't
happen on Lunar. Want me to try backporting to other releases?

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to nautilus in Ubuntu.
https://bugs.launchpad.net/bugs/1998060

Title:
  CVE-2022-37290: Pasted zip archive/invalid file causes NPD

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caja/+bug/1998060/+subscriptions


-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1998060] Re: CVE-2022-37290: Pasted zip archive/invalid file causes NPD

2023-02-11 Thread Joshua Peisach
No reproduction on Lunar for Nemo. Syslog does not show any errors

** Attachment added: "Screenshot from 2023-02-11 18-09-13.png"
   
https://bugs.launchpad.net/ubuntu/+source/nemo/+bug/1998060/+attachment/5646439/+files/Screenshot%20from%202023-02-11%2018-09-13.png

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to nautilus in Ubuntu.
https://bugs.launchpad.net/bugs/1998060

Title:
  CVE-2022-37290: Pasted zip archive/invalid file causes NPD

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caja/+bug/1998060/+subscriptions


-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1998060] Re: CVE-2022-37290: Pasted zip archive/invalid file causes NPD

2023-01-06 Thread Joshua Peisach
Applied the patches, not getting any nasty messages in /var/log/syslog

** Patch added: "nemo_5.4.3-2ubuntu0.1.debdiff"
   
https://bugs.launchpad.net/ubuntu/+source/nautilus/+bug/1998060/+attachment/5639800/+files/nemo_5.4.3-2ubuntu0.1.debdiff

** Changed in: nemo (Ubuntu Kinetic)
   Status: New => In Progress

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to nautilus in Ubuntu.
https://bugs.launchpad.net/bugs/1998060

Title:
  CVE-2022-37290: Pasted zip archive/invalid file causes NPD

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caja/+bug/1998060/+subscriptions


-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1998060] Re: CVE-2022-37290: Pasted zip archive/invalid file causes NPD

2023-01-05 Thread Joshua Peisach
Fix released for nautilus 1:43.0-1ubuntu2.1

nautilus (1:43.0-1ubuntu2.1) kinetic-security; urgency=medium

  * SECURITY UPDATE: crash via invalid zip file
- debian/patches/CVE-2022-37290.patch: fix crash when copying an
  invalid file in src/nautilus-dbus-manager.c,
  src/nautilus-file-operations.c.
- CVE-2022-37290

 -- Marc Deslauriers   Tue, 03 Jan 2023
12:27:45 -0500

** Changed in: nautilus (Ubuntu Kinetic)
   Status: New => Fix Released

** Changed in: nautilus (Ubuntu Lunar)
   Status: New => Fix Released

** Changed in: nautilus (Ubuntu Jammy)
   Status: New => Fix Released

** Changed in: nautilus (Ubuntu Focal)
   Status: New => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to nautilus in Ubuntu.
https://bugs.launchpad.net/bugs/1998060

Title:
  CVE-2022-37290: Pasted zip archive/invalid file causes NPD

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caja/+bug/1998060/+subscriptions


-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1998060] Re: CVE-2022-37290: Pasted zip archive/invalid file causes NPD

2023-01-05 Thread Joshua Peisach
Fix in version 5.6.1, sitting in proposed

** Changed in: nemo (Ubuntu Lunar)
   Status: New => Fix Committed

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to nautilus in Ubuntu.
https://bugs.launchpad.net/bugs/1998060

Title:
  CVE-2022-37290: Pasted zip archive/invalid file causes NPD

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caja/+bug/1998060/+subscriptions


-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1998060] Re: CVE-2022-37290: Pasted zip archive/invalid file causes NPD

2022-11-30 Thread Joshua Peisach
taking responsibility for SRU

** Changed in: nemo (Ubuntu Jammy)
 Assignee: (unassigned) => Joshua Peisach (itzswirlz)

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to nautilus in Ubuntu.
https://bugs.launchpad.net/bugs/1998060

Title:
  CVE-2022-37290: Pasted zip archive/invalid file causes NPD

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caja/+bug/1998060/+subscriptions


-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1998060] Re: CVE-2022-37290: Pasted zip archive/invalid file causes NPD

2022-11-30 Thread Joshua Peisach
taking responsibility for SRU

** Changed in: nemo (Ubuntu Kinetic)
 Assignee: (unassigned) => Joshua Peisach (itzswirlz)

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to nautilus in Ubuntu.
https://bugs.launchpad.net/bugs/1998060

Title:
  CVE-2022-37290: Pasted zip archive/invalid file causes NPD

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caja/+bug/1998060/+subscriptions


-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1998060] Re: CVE-2022-37290: Pasted zip archive/invalid file causes NPD

2022-11-30 Thread Joshua Peisach
taking responsibility for SRU

** Changed in: nemo (Ubuntu Focal)
 Assignee: (unassigned) => Joshua Peisach (itzswirlz)

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to nautilus in Ubuntu.
https://bugs.launchpad.net/bugs/1998060

Title:
  CVE-2022-37290: Pasted zip archive/invalid file causes NPD

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caja/+bug/1998060/+subscriptions


-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1998060] Re: CVE-2022-37290: Pasted zip archive/invalid file causes NPD

2022-11-30 Thread Joshua Peisach
Part of Debian Cinnamon Team - assign latest release with fix to me

** Changed in: nemo (Ubuntu Lunar)
 Assignee: (unassigned) => Joshua Peisach (itzswirlz)

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to nautilus in Ubuntu.
https://bugs.launchpad.net/bugs/1998060

Title:
  CVE-2022-37290: Pasted zip archive/invalid file causes NPD

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caja/+bug/1998060/+subscriptions


-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1991474] Re: GIMP 2.99 crashes on file load

2022-10-02 Thread Joshua Peisach
This is interesting - can you install the gimp debug symbols and try
reproducing this? Also, can you attach the image?

https://wiki.ubuntu.com/Debug%20Symbol%20Packages

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to gimp in Ubuntu.
https://bugs.launchpad.net/bugs/1991474

Title:
  GIMP 2.99 crashes on file load

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/gimp/+bug/1991474/+subscriptions


-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2022-05-29 Thread Joshua Peisach
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-3567

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions


-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-05-17 Thread Joshua Peisach
And focal verification done, same process/results

** Tags added: verification-done verification-done-focal

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-05-17 Thread Joshua Peisach
All done - Groovy patch does work.

How to reproduce bug pre-patch:
1) Lock screen
2) Navigate to advanced characters in virtual keyboard
3) Press the euro sign and cinnamon-screensaver crashes. In the screenshot I 
post you can see the clear Xorg error it posts.

After patch, no issues what so ever. Since this is easier than I thought
to reproduce I'll spin up focal test too.

** Attachment added: "Screenshot from 2021-05-17 11-02-37.png"
   
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+attachment/5498256/+files/Screenshot%20from%202021-05-17%2011-02-37.png

** Tags added: verification-done-groovy

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-05-17 Thread Joshua Peisach
I have not. I'm bad

I just tested and I found even using the normal characters using the
virtual keyboard like the euro sign crashes the screensaver. Yikes!

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-03-22 Thread Joshua Peisach
Final groovy patch :)

** Patch added: "caribou_0.4.21-7ubuntu0.1.debdiff"
   
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+attachment/5479354/+files/caribou_0.4.21-7ubuntu0.1.debdiff

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-03-01 Thread Joshua Peisach
I guess I can separate it. I'm sorry for being slow about this, doing
other stuff at the same time. :P

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-02-22 Thread Joshua Peisach
(Yes the other commit is needed)

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-02-05 Thread Joshua Peisach
Final Groovy Patch

** Patch added: "Final groovy patch"
   
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+attachment/5460621/+files/caribou_0.4.21-7ubuntu0.1.debdiff

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-02-05 Thread Joshua Peisach
** Patch removed: "Groovy Patch"
   
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+attachment/5457755/+files/caribou_0.4.21-7ubuntu0.1.debdiff

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-01-28 Thread Joshua Peisach
Fixed groovy patch so it doesn't include extra junk

** Patch added: "Fixed and Smaller Groovy Patch"
   
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+attachment/5457775/+files/caribou_0.4.21-7ubuntu0.1.debdiff

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-01-28 Thread Joshua Peisach
** Patch added: "Groovy Patch"
   
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+attachment/5457755/+files/caribou_0.4.21-7ubuntu0.1.debdiff

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-01-27 Thread Joshua Peisach
Note to self during testing: Pay attention to libcaribou-gtk-module,
dpkg-shlibdeps warning:

dh_shlibdeps -- -xlibgtk2.0-0
dpkg-shlibdeps: warning: 
debian/libcaribou-gtk-module/usr/lib/x86_64-linux-gnu/gtk-2.0/modules/libcaribou-gtk-module.so
 contains an unresolvable reference to symbol g_module_make_resident: it's 
probably a plugin
dpkg-shlibdeps: warning: 
debian/libcaribou-gtk3-module/usr/lib/x86_64-linux-gnu/gtk-3.0/modules/libcaribou-gtk-module.so
 contains an unresolvable reference to symbol g_module_make_resident: it's 
probably a plugin

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-01-27 Thread Joshua Peisach
Fantu: The upstream patch fixes have been put in upstream and a few vala
version changes were made.. I suggest checking
https://gitlab.gnome.org/GNOME/caribou/-/commit/11da0e0b21867921ba2f6d2af45af16a7db1ab92
and seeing if the debian patch is the same, ensure the patch is the same
and includes this commit.

You can also assign yourself for Hirsute

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-01-26 Thread Joshua Peisach
Coolio. I'll setup a groovy patch and get it testing then I'll try and
hook up a sponsor for us. :)

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-01-25 Thread Joshua Peisach
I'll test Groovy I guess.. I just think that instead of a patch it may
be better to just backport the new upstream debian version to both
focal/groovy

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix)
  cause security issue for cinnamon

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: Segfault with gir1.2-caribou-1.0 keyboard device info regression

2021-01-23 Thread Joshua Peisach
Awesome. I guess we could patch but I think it may be more necessary
since the versions in Focal and Groovy of caribou are the same to just
backport.

I also need to do some testing

** Changed in: caribou (Ubuntu Focal)
   Status: Confirmed => In Progress

** Changed in: caribou (Ubuntu Groovy)
   Status: Confirmed => In Progress

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  Segfault with gir1.2-caribou-1.0 keyboard device info regression

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: Segfault with gir1.2-caribou-1.0 keyboard device info regression

2021-01-19 Thread Joshua Peisach
The main patch has been merged upstream in caribou, but build fails.

https://gitlab.com/linuxmint/pins/mint/caribou/-/commit/72fd18b747aea7bb9cf134dc62f2a85b2b4698dc
- a new patch is needed too (it will in the debdiffs for Focal and
Groovy be in the same patch) so hopefully that'll get merged and
hopefully soon a release.

** Changed in: caribou (Ubuntu Hirsute)
   Status: New => In Progress

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  Segfault with gir1.2-caribou-1.0 keyboard device info regression

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: Segfault with gir1.2-caribou-1.0 keyboard device info regression

2021-01-16 Thread Joshua Peisach
** Changed in: caribou (Ubuntu Focal)
 Assignee: (unassigned) => Joshua Peisach (itzswirlz)

** Changed in: caribou (Ubuntu Groovy)
 Assignee: (unassigned) => Joshua Peisach (itzswirlz)

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  Segfault with gir1.2-caribou-1.0 keyboard device info regression

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] Re: Segfault with gir1.2-caribou-1.0 keyboard device info regression

2021-01-16 Thread Joshua Peisach
** Description changed:

  It was found in cinnamon-screensaver that pressing ē can crash the
  screensaver and Cinnamon DE itself.
  
  This is a regression of solving CVE-2020-25712 (https://cve.mitre.org
  /cgi-bin/cvename.cgi?name=CVE-2020-25712) in xserver
  
(https://gitlab.freedesktop.org/xorg/xserver/-/commit/87c64fc5b0db9f62f4e361444f4b60501ebf67b9)
+ 
+ Supposed patch:
+ https://gitlab.gnome.org/GNOME/caribou/-/merge_requests/3
  
  The following versions of Cinnamon are affected:
  4.4 - Focal
  4.6 - Groovy
  4.8 - Hirsute (unstable)
  
  Upstream caribou doesn't seem very maintained anymore. Hopefully patch
  will be put upstream so Hirsute can be solved. After that I will SRU
  Focal and Groovy.
  
  TL;DR: Caribou segfaults on pressing ē which can cause a screensaver
  bypass to cinnamon-screensaver and possibly any screensaver application
  using gir1.2-caribou-1.0.
  
  ProblemType: Bug
  DistroRelease: Ubuntu 20.10
  Package: gir1.2-caribou-1.0 0.4.21-7
  ProcVersionSignature: Ubuntu 5.8.0-33.36-generic 5.8.17
  Uname: Linux 5.8.0-33-generic x86_64
  ApportVersion: 2.20.11-0ubuntu50.3
  Architecture: amd64
  CasperMD5CheckResult: skip
  CurrentDesktop: ubuntu:GNOME
  Date: Sat Jan 16 10:36:59 2021
  InstallationDate: Installed on 2020-10-23 (85 days ago)
  InstallationMedia: Ubuntu 20.10 "Groovy Gorilla" - Release amd64 (20201022)
  ProcEnviron:
-  TERM=xterm-256color
-  PATH=(custom, no user)
-  XDG_RUNTIME_DIR=
-  LANG=en_US.UTF-8
-  SHELL=/bin/bash
+  TERM=xterm-256color
+  PATH=(custom, no user)
+  XDG_RUNTIME_DIR=
+  LANG=en_US.UTF-8
+  SHELL=/bin/bash
  RebootRequiredPkgs:
-  linux-image-5.8.0-38-generic
-  linux-base
+  linux-image-5.8.0-38-generic
+  linux-base
  SourcePackage: caribou
  UpgradeStatus: No upgrade log present (probably fresh install)

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  Segfault with gir1.2-caribou-1.0 keyboard device info regression

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1912060] [NEW] Segfault with gir1.2-caribou-1.0 keyboard device info regression

2021-01-16 Thread Joshua Peisach
*** This bug is a security vulnerability ***

Public security bug reported:

It was found in cinnamon-screensaver that pressing ē can crash the
screensaver and Cinnamon DE itself.

This is a regression of solving CVE-2020-25712 (https://cve.mitre.org
/cgi-bin/cvename.cgi?name=CVE-2020-25712) in xserver
(https://gitlab.freedesktop.org/xorg/xserver/-/commit/87c64fc5b0db9f62f4e361444f4b60501ebf67b9)

The following versions of Cinnamon are affected:
4.4 - Focal
4.6 - Groovy
4.8 - Hirsute (unstable)

Upstream caribou doesn't seem very maintained anymore. Hopefully patch
will be put upstream so Hirsute can be solved. After that I will SRU
Focal and Groovy.

TL;DR: Caribou segfaults on pressing ē which can cause a screensaver
bypass to cinnamon-screensaver and possibly any screensaver application
using gir1.2-caribou-1.0.

ProblemType: Bug
DistroRelease: Ubuntu 20.10
Package: gir1.2-caribou-1.0 0.4.21-7
ProcVersionSignature: Ubuntu 5.8.0-33.36-generic 5.8.17
Uname: Linux 5.8.0-33-generic x86_64
ApportVersion: 2.20.11-0ubuntu50.3
Architecture: amd64
CasperMD5CheckResult: skip
CurrentDesktop: ubuntu:GNOME
Date: Sat Jan 16 10:36:59 2021
InstallationDate: Installed on 2020-10-23 (85 days ago)
InstallationMedia: Ubuntu 20.10 "Groovy Gorilla" - Release amd64 (20201022)
ProcEnviron:
 TERM=xterm-256color
 PATH=(custom, no user)
 XDG_RUNTIME_DIR=
 LANG=en_US.UTF-8
 SHELL=/bin/bash
RebootRequiredPkgs:
 linux-image-5.8.0-38-generic
 linux-base
SourcePackage: caribou
UpgradeStatus: No upgrade log present (probably fresh install)

** Affects: caribou (Ubuntu)
 Importance: Undecided
 Status: New


** Tags: amd64 apport-bug focal groovy hirsute regression

** Information type changed from Private Security to Public Security

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to caribou in Ubuntu.
https://bugs.launchpad.net/bugs/1912060

Title:
  Segfault with gir1.2-caribou-1.0 keyboard device info regression

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/caribou/+bug/1912060/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1905153] [NEW] Brightness only works on one display, not two

2020-11-21 Thread Joshua Peisach
Public bug reported:

Dell Inspiron 15-3567, Hirsute

My display setup is the laptop and on the right a monitor.

As I change my brightness, lower or higher, on the laptop the brightness
will change but on the monitor it won't.

Not the physical monitor brightness-that obviously can't be controlled-
but the content of what the monitor shows should be dimming/brightening.
(For example if theoretically I turned the brightness to 0, to an all
dark screen, it should be all dark on the monitor aswell, even if the
monitor brightness is max, the OS is showing nothing)

Yes, I looked through GNOME's settings daemon and this is most likely
the package this occurs in.

ProblemType: Bug
DistroRelease: Ubuntu 21.04
Package: gnome-control-center 1:3.38.1-1ubuntu1
ProcVersionSignature: Ubuntu 5.8.0-25.26-generic 5.8.14
Uname: Linux 5.8.0-25-generic x86_64
NonfreeKernelModules: zfs zunicode zavl icp zcommon znvpair
ApportVersion: 2.20.11-0ubuntu51
Architecture: amd64
CasperMD5CheckResult: pass
CasperVersion: 1.455
CurrentDesktop: ubuntu:GNOME
Date: Sun Nov 22 02:03:00 2020
LiveMediaBuild: Ubuntu 21.04 "Hirsute Hippo" - Alpha amd64 (20201120)
ProcEnviron:
 TERM=xterm-256color
 PATH=(custom, no user)
 XDG_RUNTIME_DIR=
 LANG=en_US.UTF-8
 SHELL=/bin/bash
SourcePackage: gnome-control-center
UpgradeStatus: No upgrade log present (probably fresh install)

** Affects: gnome-control-center (Ubuntu)
 Importance: Undecided
 Status: New


** Tags: amd64 apport-bug hirsute

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to gnome-control-center in Ubuntu.
https://bugs.launchpad.net/bugs/1905153

Title:
  Brightness only works on one display, not two

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/gnome-control-center/+bug/1905153/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1030022] Re: Port from legacy Xlib to modern XCB

2020-07-15 Thread Joshua Peisach
It looks like this was already changed more recently in 2019/2020 with
4.4 - 4.6

** Changed in: muffin (Ubuntu)
   Status: New => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to metacity in Ubuntu.
https://bugs.launchpad.net/bugs/1030022

Title:
  Port from legacy Xlib to modern XCB

To manage notifications about this bug go to:
https://bugs.launchpad.net/compiz/+bug/1030022/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1880346] Re: Zooming in requires Ctrl + Shift + Plus-zoom out doesn't require shift

2020-05-23 Thread Joshua Peisach
You do need to shift-it's intentional

** Summary changed:

- Zooming in requires Ctrl + Shift + Plus-zoom out doesn't require shift
+ [INVALID] Zooming in requires Ctrl + Shift + Plus-zoom out doesn't require 
shift

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to gnome-terminal in Ubuntu.
https://bugs.launchpad.net/bugs/1880346

Title:
  [INVALID] Zooming in requires Ctrl + Shift + Plus-zoom out doesn't
  require shift

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/gnome-terminal/+bug/1880346/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

[Bug 1880346] [NEW] Zooming in requires Ctrl + Shift + Plus-zoom out doesn't require shift

2020-05-23 Thread Joshua Peisach
Public bug reported:

The keybindings for gnome-terminal:

Zoom In: Ctrl++
Zoom Out: Ctrl+-

Zooming out works fine-however when Zooming in you must use Shift. When
zooming out you do not need to shift. Ubuntu is affected by this and I
found a problem in Tilix, which I will edit and post here.

ProblemType: Bug
DistroRelease: Ubuntu 20.10
Package: gnome-terminal 3.36.1.1-1ubuntu1
ProcVersionSignature: Ubuntu 5.4.0-26.30-generic 5.4.30
Uname: Linux 5.4.0-26-generic x86_64
ApportVersion: 2.20.11-0ubuntu36
Architecture: amd64
CasperMD5CheckResult: skip
CurrentDesktop: X-Cinnamon
Date: Sat May 23 19:37:22 2020
ExecutablePath: /usr/libexec/gnome-terminal-server
InstallationDate: Installed on 2020-05-22 (1 days ago)
InstallationMedia: cinnamon-remix "groovy" (20200512)
SourcePackage: gnome-terminal
UpgradeStatus: No upgrade log present (probably fresh install)

** Affects: gnome-terminal (Ubuntu)
 Importance: Undecided
 Status: Invalid


** Tags: amd64 apport-bug groovy

** Changed in: gnome-terminal (Ubuntu)
   Status: New => Invalid

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to gnome-terminal in Ubuntu.
https://bugs.launchpad.net/bugs/1880346

Title:
  Zooming in requires Ctrl + Shift + Plus-zoom out doesn't require shift

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/gnome-terminal/+bug/1880346/+subscriptions

-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs