Bug#1033160: bullseye-pu: package flatpak/1.10.8-0+deb11u1

2023-04-02 Thread Simon McVittie
On Sat, 01 Apr 2023 at 19:57:32 +0100, Adam D. Barratt wrote: > On Sat, 2023-03-18 at 16:20 +, Simon McVittie wrote: > > CVE-2023-28101 (#1033098) > > CVE-2023-28100 (#1033099) > > Please go ahead. Uploaded.

Bug#1033160: bullseye-pu: package flatpak/1.10.8-0+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2023-03-18 at 16:20 +, Simon McVittie wrote: > CVE-2023-28101: A malicious Flatpak app could prevent the flatpak(1) > CLI > from displaying its permissions as intended, by having crafted > permissions > or other metadata containing terminal escape

Bug#1033160: bullseye-pu: package flatpak/1.10.8-0+deb11u1

2023-03-18 Thread Simon McVittie
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: flat...@packages.debian.org Control: affects -1 + src:flatpak [ Reason ] New upstream stable release fixing a security issue. [ Impact ] The same two CVEs that were