[Bug 2067742] Re: CVE-2024-36041: ksmserver: Unauthorized users can access session manager

2024-06-19 Thread Simon Quigley
Modified the test plan in the bug description to cover all our bases. Here are my results: - Successful on Noble with plasma-workspace 4:5.27.11-0ubuntu4.1. - Successful on Mantic with plasma-workspace 4:5.27.8-0ubuntu1.1. - Successful on Jammy with plasma-workspace 4:5.24.7-0ubuntu0.2 and the

[Bug 2067742] Re: CVE-2024-36041: ksmserver: Unauthorized users can access session manager

2024-06-19 Thread Simon Quigley
** Description changed: [ Impact ] On May 31, 2024, KDE published a security advisory for plasma-workspace: https://kde.org/info/security/advisory-20240531-1.txt This was assigned CVE-2024-36041, and affects all stable versions of Kubuntu (and the Ubuntu Studio releases with KDE

[Bug 2067742] Re: CVE-2024-36041: ksmserver: Unauthorized users can access session manager

2024-06-19 Thread Simon Quigley
** Description changed: [ Impact ] On May 31, 2024, KDE published a security advisory for plasma-workspace: https://kde.org/info/security/advisory-20240531-1.txt This was assigned CVE-2024-36041, and affects all stable versions of Kubuntu (and the Ubuntu Studio releases with KDE

[Bug 2067742] Re: [SRU] CVE-2024-36041 Fix ksmserver: Unauthorized users can access session manager

2024-06-19 Thread Simon Quigley
** Description changed: [ Impact ] - * ksmserver: Unauthorized users can access session manager + On May 31, 2024, KDE published a security advisory for plasma-workspace: + https://kde.org/info/security/advisory-20240531-1.txt - * CVE-2024-36041 security + This was assigned

[Bug 2067742] Re: [SRU] CVE-2024-36041 Fix ksmserver: Unauthorized users can access session manager

2024-06-19 Thread Marc Deslauriers
I have built packages in the security team proposed PPA for testing. Additional packages required no-change rebuilds in the -security pocket also. For Jammy, the additional packages are breeze, libksysguard, layer-shell-qt, kwin, kwayland-server. For Focal, the additional packages are kwin and