[Touch-packages] [Bug 1669601] Re: tracker-store crashed with SIGSEGV in tracker_db_interface_lock()

2017-03-31 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to tracker in Ubuntu. https://bugs.launchpad.net/bugs/1669601 Title: tracker-store crashed with SIGSEGV in tracker_db_

[Touch-packages] [Bug 1668679] Re: indicator-network-secret-agent crashed with SIGSEGV in do_lookup_x()

2017-03-31 Thread Marc Deslauriers
** Attachment removed: "CoreDump.gz" https://bugs.launchpad.net/ubuntu/+source/indicator-network/+bug/1668679/+attachment/4828372/+files/CoreDump.gz ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seed

[Touch-packages] [Bug 1676382] Re: package cups-daemon 2.1.3-4 failed to install/upgrade: sub-processo novo script pre-removal retornou estado de saída de erro 1

2017-03-31 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1608200] Re: please merge openssl from Debian

2017-03-31 Thread Marc Deslauriers
Please don't merge this for zesty. There is no point as most of the changes have already been backported, and merging it will just make maintenance harder. Let's wait until z+1 and do openssl 1.1 instead. -- You received this bug notification because you are a member of Ubuntu Touch seeded packa

[Touch-packages] [Bug 1674399] Re: OpenSSL CPU detection for AMD Ryzen CPUs

2017-04-27 Thread Marc Deslauriers
** Changed in: openssl (Ubuntu Artful) Status: In Progress => Triaged ** Changed in: openssl (Ubuntu Artful) Status: Triaged => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. ht

[Touch-packages] [Bug 1657882] Re: wine

2017-01-20 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1657495] Re: package libperl5.22 5.22.1-9 failed to install/upgrade: el subproceso script pre-installation nuevo devolvió el código de salida de error 1

2017-01-20 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1656621] Re: package libgssapi3-heimdal:i386 1.6~rc2+dfsg-10ubuntu1 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attemp

2017-01-20 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1652835] Re: [MUST FIX]package kde-config-telepathy-accounts (not installed) failed to install/upgrade: Package System Critical and Wrecked from previous issues encountered

2017-01-20 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1643467] Re: Firefox 50 blocks Ubuntu 12.04 and 14.04 LTS's version of libavcodec

2017-01-21 Thread Marc Deslauriers
For this to be resolved in Ubuntu 12.04 LTS, an appropriate fix needs to be written for libav 0.8. Updating to a newer libav isn't an option as the API has changed and that would break compatibility with all the software using libav in the archive. Once a fix has been written, Mozilla would then ne

[Touch-packages] [Bug 1672838] Re: Please sync libxml2 version 2.9.4 into Ubuntu 16.04.3

2017-03-14 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1652325 *** https://bugs.launchpad.net/bugs/1652325 ** This bug has been marked a duplicate of bug 1652325 Libxml2 2.9.3 fails to parse multi-byte character in large CDATA section that is split across buffer -- You received this bug notification because

[Touch-packages] [Bug 1652325] Re: Libxml2 2.9.3 fails to parse multi-byte character in large CDATA section that is split across buffer

2017-03-14 Thread Marc Deslauriers
** Bug watch added: GNOME Bug Tracker #760183 https://bugzilla.gnome.org/show_bug.cgi?id=760183 ** Also affects: libxml2 via https://bugzilla.gnome.org/show_bug.cgi?id=760183 Importance: Unknown Status: Unknown -- You received this bug notification because you are a member of Ubu

[Touch-packages] [Bug 1630544] Re: CVE-2016-7444 vulnerability

2017-03-22 Thread Marc Deslauriers
The vulnerable code isn't in 2.12.x, so the gnutls26 package isn't vulnerable. ** Changed in: gnutls26 (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to gnutls26 in Ubuntu. https://bugs.la

[Touch-packages] [Bug 1709193] Re: Unable to use TLSv1.1 or 1.2 with OpenSSL compat layer

2017-08-11 Thread Marc Deslauriers
** Also affects: ssmtp (Ubuntu Artful) Importance: Undecided Status: Invalid ** Also affects: gnutls26 (Ubuntu Artful) Importance: Undecided Status: New ** Also affects: gnutls28 (Ubuntu Artful) Importance: Undecided Status: New ** Also affects: ssmtp (Ubuntu Trusty

[Touch-packages] [Bug 1709193] Re: Unable to use TLSv1.1 or 1.2 with OpenSSL compat layer

2017-08-11 Thread Marc Deslauriers
ACK on the artful debdiff. I've uploaded it now with a slight adjustment to put the bug numbers in the patch tags. Thanks! ** Changed in: gnutls28 (Ubuntu Artful) Status: Confirmed => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded pack

[Touch-packages] [Bug 1709193] Re: Unable to use TLSv1.1 or 1.2 with OpenSSL compat layer

2017-08-11 Thread Marc Deslauriers
ACK on the trusty, xenial and zesty debdiffs. Uploaded for processing by the SRU team. Thanks! ** Changed in: gnutls26 (Ubuntu Trusty) Status: Confirmed => In Progress ** Changed in: gnutls28 (Ubuntu Xenial) Status: Confirmed => In Progress ** Changed in: gnutls28 (Ubuntu Zesty)

[Touch-packages] [Bug 1711107] Re: package apport 2.20.4-0ubuntu4 failed to install/upgrade: サブプロセス 新しい pre-removal スクリプト はエラー終了ステータス 127 を返しました

2017-08-18 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1711132] Re: make crashed with SIGSEGV in variable_hash_1()

2017-08-18 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1711033] Re: errors

2017-08-18 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1711020] Re: package linux-image-extra-4.4.0-91-generic 4.4.0-91.114 failed to install/upgrade: run-parts: /etc/kernel/postinst.d/initramfs-tools exited with return code 1

2017-08-18 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1704981] Re: I don't know

2017-08-18 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to xorg in Ubuntu. https://bugs.launchpad.net/bugs/1704981 Title: I don't know Status in xorg package in Ubuntu:

[Touch-packages] [Bug 1700937] Re: Heap-buffer overflow in nodeAcquire

2017-08-18 Thread Marc Deslauriers
** Changed in: sqlite3 (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to sqlite3 in Ubuntu. https://bugs.launchpad.net/bugs/1700937 Title: Heap-buffer overflow in nodeAcquire Status i

[Touch-packages] [Bug 1652381] Re: systematic way to refresh the random-seed again and again

2017-08-18 Thread Marc Deslauriers
Hi John, We get the current random seed unit from systemd. Please file a bug with the upstream systemd project, or discuss these changes on the systemd mailing list. Once your changes are accepted by systemd, we will inherit them. Thanks! ** Changed in: systemd (Ubuntu) Status: New => Co

[Touch-packages] [Bug 1591672] Re: update-manager does not obey require-password policy

2017-08-18 Thread Marc Deslauriers
** No longer affects: policykit-1 (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to policykit-1 in Ubuntu. https://bugs.launchpad.net/bugs/1591672 Title: update-manager does not obey require-password policy Status i

[Touch-packages] [Bug 1697283] Re: Denial of Service Vulnerability in Librsvg

2017-08-18 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Changed in: librsvg (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to librsvg in Ubuntu. https://bugs.launchpad.ne

[Touch-packages] [Bug 1667659] Re: signon-ui crashed with SIGSEGV in QWindow::show()

2017-02-24 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to signon-ui in Ubuntu. https://bugs.launchpad.net/bugs/1667659 Title: signon-ui crashed with SIGSEGV in QWindow::show

[Touch-packages] [Bug 1667658] Re: signon-ui crashed with SIGSEGV in QWindow::show()

2017-02-24 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to signon-ui in Ubuntu. https://bugs.launchpad.net/bugs/1667658 Title: signon-ui crashed with SIGSEGV in QWindow::show

[Touch-packages] [Bug 1667562] Re: package systemd 229-4ubuntu16 [modified: usr/share/dbus-1/system-services/org.freedesktop.systemd1.service] failed to install/upgrade: subprocess installed pre-remov

2017-02-24 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1667569] Re: package linux-image-4.4.0-64-generic 4.4.0-64.85 failed to install/upgrade: run-parts: /etc/kernel/postinst.d/apt-auto-removal exited with return code 2

2017-02-24 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1667372] Re: package python-decorator 4.0.6-1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 127

2017-02-24 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1667218] Re: Help bugs/system crashes

2017-02-24 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see https://wiki.ubuntu.

[Touch-packages] [Bug 1667503] Re: El sistema es muy lento

2017-02-24 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1666049] Re: I cant download the apps i want

2017-02-24 Thread Marc Deslauriers
Thanks for your comments. This does not appear to be a bug report and we are closing it. We appreciate the difficulties you are facing, but it would make more sense to raise your question in the support tracker. Please visit https://answers.launchpad.net/ubuntu/+addquestion ** Information type cha

[Touch-packages] [Bug 1663481] Re: webbrowser-app crashed with SIGABRT in __run_exit_handlers()

2017-02-24 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1664489] Re: Rootkit

2017-02-24 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see https://wiki.ubuntu.

[Touch-packages] [Bug 1664093] Re: iv had so many issues since upgrading to the new ubuntu 16.04 lts but this is just a quick start of what just a few are for now..

2017-02-24 Thread Marc Deslauriers
Thanks for your comments. This does not appear to be a bug report and we are closing it. We appreciate the difficulties you are facing, but it would make more sense to raise your question in the support tracker. Please visit https://answers.launchpad.net/ubuntu/+addquestion ** Information type cha

[Touch-packages] [Bug 1705166] Re: package apport 2.20.4-0ubuntu4 failed to install/upgrade: subprocess new pre-removal script returned error exit status 1

2017-07-19 Thread Marc Deslauriers
Hi. Could you please paste the result of the following command? ls -l /usr/bin/python Thanks! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apport in Ubuntu. https://bugs.launchpad.net/bugs/1705166 Title: package apport

[Touch-packages] [Bug 1705166] Re: package apport 2.20.4-0ubuntu4 failed to install/upgrade: subprocess new pre-removal script returned error exit status 1

2017-07-20 Thread Marc Deslauriers
Hi, That's weird. Did you install some third-party python package, or changed that symlink yourself? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apport in Ubuntu. https://bugs.launchpad.net/bugs/1705166 Title: package

[Touch-packages] [Bug 1687372] Re: This error are occures

2017-05-05 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1684902] Re: browser unity app crashes apparmor profile

2017-05-05 Thread Marc Deslauriers
Hi Carl, it looks like you're missing the apparmor-easyprof-ubuntu package. That package is necessary for proper operation. Could you please reinstall it and try again? Thanks! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1681077] Re: ideviceinfo (libimobiledevice): GnuTLS error: Error in the pull function

2017-05-05 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to libimobiledevice in Ubuntu. https://bugs.launchpad.net/bugs/1681077 Title: ideviceinfo (libimobiledevice): GnuTLS e

[Touch-packages] [Bug 1679989] Re: CVE-2016-10165: heap OOB read parsing crafted ICC profile

2017-05-05 Thread Marc Deslauriers
** Also affects: lcms2 (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: lcms2 (Ubuntu Trusty) Importance: Undecided Status: New ** Also affects: lcms2 (Ubuntu Zesty) Importance: Undecided Status: New ** Also affects: lcms2 (Ubuntu Yakkety) Impo

[Touch-packages] [Bug 1662513] Re: Update to 9.21 in Trusty

2017-05-05 Thread Marc Deslauriers
** Changed in: libav (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to libav in Ubuntu. https://bugs.launchpad.net/bugs/1662513 Title: Update to 9.21 in Trusty Status in libav package

[Touch-packages] [Bug 1650818] Re: Clipboard contents accessible outside user session potentially giving the attacker root access

2017-05-05 Thread Marc Deslauriers
** Changed in: unity8 (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to unity8 in Ubuntu. https://bugs.launchpad.net/bugs/1650818 Title: Clipboard contents accessible outside user sess

[Touch-packages] [Bug 1649097] Re: any source package signature is not valid

2017-05-05 Thread Marc Deslauriers
I am closing this bug report as there is no actionable item. As mentioned above, source packages are verified using the Ubuntu archive key, not by using the developer's signature. ** Changed in: apt (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a m

[Touch-packages] [Bug 1684902] Re: browser unity app crashes apparmor profile

2017-05-05 Thread Marc Deslauriers
** Changed in: webbrowser-app (Ubuntu) Status: New => Invalid ** Changed in: apparmor (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad

[Touch-packages] [Bug 1643379] Re: ca-certificates in xenial still trusts CNNIC

2017-05-05 Thread Marc Deslauriers
** Changed in: ca-certificates (Ubuntu) Status: New => Confirmed ** Changed in: ca-certificates (Ubuntu) Importance: Undecided => Wishlist -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ca-certificates in Ubuntu. h

[Touch-packages] [Bug 1690820] Re: killing su does not kill subprocess (SIGTERM not propagated)

2017-05-15 Thread Marc Deslauriers
** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to shadow in Ubuntu. https://bugs.launchpad.net/bugs/1690820 Title: killing su does not kill subprocess (SIGTERM not pr

[Touch-packages] [Bug 1824498] Re: Unable to connect to wifi since wpasupplicant_2.4-0ubuntu6.4_amd64.deb update

2019-04-12 Thread Marc Deslauriers
What happens when you try to connect? What kind of wireless connection are you using? Do you have anything relevant in your log files? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to wpa in Ubuntu. https://bugs.launchpad.net/b

[Touch-packages] [Bug 1824961] Re: AppArmor blocks apport python hook from working

2019-04-16 Thread Marc Deslauriers
Reassigning to the kopanocore package as that is what contains the problematic profile. ** Package changed: apparmor (Ubuntu) => kopanocore (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://

[Touch-packages] [Bug 1781699] Re: DHCPv6 server crashes regularly (bionic)

2019-05-06 Thread Marc Deslauriers
) Importance: Undecided Status: New ** Changed in: isc-dhcp (Ubuntu Bionic) Status: New => In Progress ** Changed in: isc-dhcp (Ubuntu Bionic) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: isc-dhcp (Ubuntu Cosmic) Status: New => In

[Touch-packages] [Bug 1781699] Re: DHCPv6 server crashes regularly (bionic)

2019-05-06 Thread Marc Deslauriers
Packages for this issue are now available in the security team test ppa here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Could someone please try them out and make sure they resolve the issue? Thanks! -- You received this bug notification because you are a m

[Touch-packages] [Bug 1828439] Re: false error message displaying printer out of paper

2019-05-09 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1828401 *** https://bugs.launchpad.net/bugs/1828401 ** This bug has been marked a duplicate of bug 1828401 9.26~dfsg+0-0ubuntu0.18.04.9 breaks cups printing of pdf -- You received this bug notification because you are a member of Ubuntu Touch seeded pack

[Touch-packages] [Bug 1781699] Re: DHCPv6 server crashes regularly (bionic)

2019-05-10 Thread Marc Deslauriers
Great, thanks for testing, I'll release these early next week! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to isc-dhcp in Ubuntu. https://bugs.launchpad.net/bugs/1781699 Title: DHCPv6 server crashes regularly (bionic) Sta

[Touch-packages] [Bug 1872560] Re: integer overflow in whoopsie 0.2.69

2020-06-17 Thread Marc Deslauriers
I still can't reproduce this issue. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to whoopsie in Ubuntu. https://bugs.launchpad.net/bugs/1872560 Title: integer overflow in whoopsie 0.2.69 Status in whoopsie package in Ubunt

[Touch-packages] [Bug 1881982] Re: DoS vulnerability: cause resource exhaustion

2020-07-09 Thread Marc Deslauriers
** Changed in: whoopsie (Ubuntu) Assignee: Alex Murray (alexmurray) => Marc Deslauriers (mdeslaur) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to whoopsie in Ubuntu. https://bugs.launchpad.net/bugs/1881982 Title:

[Touch-packages] [Bug 1872560] Re: integer overflow in whoopsie 0.2.69

2020-07-09 Thread Marc Deslauriers
** Changed in: whoopsie (Ubuntu) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: whoopsie (Ubuntu) Status: Incomplete => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to whoop

[Touch-packages] [Bug 1882180] Re: DoS vulnerability: fail to allocate

2020-07-09 Thread Marc Deslauriers
https://github.com/sungjungk/whoopsie_killer2 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to whoopsie in Ubuntu. https://bugs.launchpad.net/bugs/1882180 Title: DoS vulnerability: fail to allocate Status in whoopsie packag

[Touch-packages] [Bug 1882180] Re: DoS vulnerability: fail to allocate

2020-07-09 Thread Marc Deslauriers
Looks like this is CVE-2020-15570 ** Changed in: whoopsie (Ubuntu Xenial) Assignee: Alex Murray (alexmurray) => Marc Deslauriers (mdeslaur) ** Changed in: whoopsie (Ubuntu Bionic) Assignee: Alex Murray (alexmurray) => Marc Deslauriers (mdeslaur) ** Changed in: whoopsie (Ubunt

[Touch-packages] [Bug 1881982] Re: DoS vulnerability: cause resource exhaustion

2020-07-09 Thread Marc Deslauriers
https://github.com/sungjungk/whoopsie_killer -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to whoopsie in Ubuntu. https://bugs.launchpad.net/bugs/1881982 Title: DoS vulnerability: cause resource exhaustion Status in whoopsi

[Touch-packages] [Bug 1872560] Re: integer overflow in whoopsie 0.2.69

2020-07-09 Thread Marc Deslauriers
https://github.com/sungjungk/apport-vuln -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to whoopsie in Ubuntu. https://bugs.launchpad.net/bugs/1872560 Title: integer overflow in whoopsie 0.2.69 Status in whoopsie package in

[Touch-packages] [Bug 1872560] Re: integer overflow in whoopsie 0.2.69

2020-07-09 Thread Marc Deslauriers
** Also affects: whoopsie (Ubuntu Focal) Importance: Undecided Status: New ** Also affects: whoopsie (Ubuntu Xenial) Importance: Undecided Status: New ** Also affects: whoopsie (Ubuntu Groovy) Importance: High Assignee: Marc Deslauriers (mdeslaur) Status

[Touch-packages] [Bug 1881982] Re: DoS vulnerability: cause resource exhaustion

2020-07-09 Thread Marc Deslauriers
** Also affects: whoopsie (Ubuntu Bionic) Importance: Undecided Status: New ** Also affects: whoopsie (Ubuntu Groovy) Importance: Medium Assignee: Marc Deslauriers (mdeslaur) Status: Confirmed ** Also affects: whoopsie (Ubuntu Xenial) Importance: Undecided

[Touch-packages] [Bug 1864982] Re: Ubuntu desktop computer doesn't seem to lock correctly

2020-07-14 Thread Marc Deslauriers
** Changed in: lightdm (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lightdm in Ubuntu. https://bugs.launchpad.net/bugs/1864982 Title: Ubuntu desktop computer doesn't seem to lock

[Touch-packages] [Bug 1617620] Re: Autorun files from Removable Media

2020-07-14 Thread Marc Deslauriers
** Changed in: gsettings-desktop-schemas (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to gsettings-desktop-schemas in Ubuntu. https://bugs.launchpad.net/bugs/1617620 Title: Autorun f

[Touch-packages] [Bug 1513964] Re: dsextras.py : Shell Command Injection with a pkg name

2020-07-14 Thread Marc Deslauriers
** Changed in: pygobject-2 (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to pygobject-2 in Ubuntu. https://bugs.launchpad.net/bugs/1513964 Title: dsextras.py : Shell Command Injectio

[Touch-packages] [Bug 1570788] Re: Makes mDNS ddos amplification attack possible

2020-07-14 Thread Marc Deslauriers
I think this was CVE-2017-6519, which was fixed a long time ago. I am closing this bug, please feel free to open a new bug if you can reproduce with a more recent version of Ubuntu. Thanks! ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-6519 ** Changed in: avahi (Ubuntu)

[Touch-packages] [Bug 1594695] Re: apparmor service not started on fresh install

2020-07-14 Thread Marc Deslauriers
Are you still able to reproduce this issue with later versions of Ubuntu? ** Changed in: apparmor (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.laun

[Touch-packages] [Bug 1404084] Re: Fix for CVE-2013-6045 breaks decoding of chroma-subsampled images

2020-07-14 Thread Marc Deslauriers
** Changed in: openjpeg (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openjpeg in Ubuntu. https://bugs.launchpad.net/bugs/1404084 Title: Fix for CVE-2013-6045 breaks decoding of ch

[Touch-packages] [Bug 896836] Re: Segmentation fault when asking help() for the list of modules

2020-07-14 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to python2.7 in Ubuntu. https://bugs.launchpad.net/bugs/896836 Title: Segmentation fault when asking help() for the lis

[Touch-packages] [Bug 1885496] Re: Intel Wireless 8260 [8086:24f3] Subsystem [8086:9010] Bluetooth is disabled in gui, but audio reciever's action button still controls Ubuntu

2020-07-14 Thread Marc Deslauriers
Hi, Could you please attach a screenshot of the slider you are referring to? I believe you are confusing the slider's purpose. The slider is to make your bluetooth computer visible to be able to pair new devices, it does not disconnect existing devices. ** Changed in: linux (Ubuntu) Stat

[Touch-packages] [Bug 1885496] Re: Intel Wireless 8260 [8086:24f3] Subsystem [8086:9010] Bluetooth is disabled in gui, but audio reciever's action button still controls Ubuntu

2020-07-14 Thread Marc Deslauriers
Ok, actually the slider is in fact to disable bluetooth completely, please ignore my previous comment. ** Changed in: bluez (Ubuntu) Status: Incomplete => Confirmed ** Changed in: linux (Ubuntu) Status: Incomplete => Confirmed -- You received this bug notification because you are

[Touch-packages] [Bug 1887898] Re: Bluetooth sound card not detected

2020-07-17 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1884265] Re: [fips] ntpq segfaults when attempting to use MD5 from FIPS-openssl library.

2020-07-17 Thread Marc Deslauriers
ACK on the debdiff in comment #11, uploaded with a slight LP tag fix for processing by the SRU team. Thanks! ** Changed in: openssl (Ubuntu Bionic) Status: Confirmed => In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is sub

[Touch-packages] [Bug 1889206] [NEW] Regression in USN-4436-1

2020-07-28 Thread Marc Deslauriers
me cards are missing graphics ** Affects: librsvg (Ubuntu) Importance: Undecided Status: New ** Affects: librsvg (Ubuntu Xenial) Importance: Undecided Assignee: Marc Deslauriers (mdeslaur) Status: Confirmed ** Affects: librsvg (Ubuntu Bionic) Importance: Undecided

[Touch-packages] [Bug 1889206] Re: Regression in USN-4436-1

2020-07-28 Thread Marc Deslauriers
Can also be tested by running "eog /usr/share/aisleriot/cards/anglo.svgz". See attached screenshot. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to librsvg in Ubuntu. https://bugs.launchpad.net/bugs/1889206 Title: Regressio

[Touch-packages] [Bug 1889206] Re: Regression in USN-4436-1

2020-07-28 Thread Marc Deslauriers
** Attachment added: "eog displaying issue rendering anglo cardset" https://bugs.launchpad.net/ubuntu/+source/librsvg/+bug/1889206/+attachment/5396555/+files/anglo-issue.png ** Bug watch added: gitlab.gnome.org/GNOME/librsvg/-/issues #612 https://gitlab.gnome.org/GNOME/librsvg/-/issues/612

[Touch-packages] [Bug 1889206] Re: Regression in USN-4436-1

2020-07-29 Thread Marc Deslauriers
** Changed in: librsvg (Ubuntu) Status: Confirmed => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to librsvg in Ubuntu. https://bugs.launchpad.net/bugs/1889206 Title: Regression in USN-4436-1 Status in librs

[Touch-packages] [Bug 1890170] Re: ImportError libstdc++.so.6 cannot allocate memory after importing PyQt5.Qt PyQt5.QtCore and cv2

2020-08-04 Thread Marc Deslauriers
I think this is related: $ readelf --dynamic libmysqlclient.so.21.1.19 | grep BIND 0x001e (FLAGS) BIND_NOW $ readelf --dynamic libmysqlclient.so.21.1.21 | grep BIND 0x001e (FLAGS) BIND_NOW STATIC_TLS ** Information type changed from Public to

[Touch-packages] [Bug 1890170] Re: ImportError libstdc++.so.6 cannot allocate memory after importing PyQt5.Qt PyQt5.QtCore and cv2

2020-08-04 Thread Marc Deslauriers
Possibly related: https://github.com/mysql/mysql-server/commit/735bd2a53834266c7256830c8d34672ea55fe17b -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to opencv in Ubuntu. https://bugs.launchpad.net/bugs/1890170 Title: Import

[Touch-packages] [Bug 1890170] Re: ImportError libstdc++.so.6 cannot allocate memory after importing PyQt5.Qt PyQt5.QtCore and cv2

2020-08-04 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1889851 *** https://bugs.launchpad.net/bugs/1889851 I'm pretty sure this is a dupe of #1889851. Marking as such. ** This bug has been marked a duplicate of bug 1889851 Driver QMysql can't be loaded -- You received this bug notification because you are a

[Touch-packages] [Bug 1881976] Re: apport-gtk and apport-kde install xiterm+thai as dependency (x-terminal-emulator)

2020-08-04 Thread Marc Deslauriers
Unfortunately, this SRU has been superseded by a security update. Please re-upload the SRU. Thanks! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apport in Ubuntu. https://bugs.launchpad.net/bugs/1881976 Title: apport-gtk

[Touch-packages] [Bug 1891123] Re: Openssh vulnerability on ubuntu 16.04

2020-08-11 Thread Marc Deslauriers
Hi, The only thing an attacker can do with this vulnerability is DoS their own connection. As such, it is not considered a security issue either by the upstream OpenSSH project, or by the Ubuntu security team. Like other distros, we have no plans to fix this issue in our stable releases. ** Chan

[Touch-packages] [Bug 1890286] Re: ansi escape sequence injection in add-apt-repository

2020-08-12 Thread Marc Deslauriers
Hi, Could you elaborate which codes in that manpage you feel are dangerous and are actually implemented by the common terminals? The old screendump and window title codes were disabled long ago, I'm not sure any of the others are anything other than a nuisance. -- You received this bug notificat

[Touch-packages] [Bug 1888085] Re: Fehler : Ubuntu 18.04.4 LTS

2020-08-18 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1895294] Re: Fix Raccoon vulnerability (CVE-2020-1968)

2020-09-16 Thread Marc Deslauriers
This has now been fixed: https://ubuntu.com/security/notices/USN-4504-1 ** Changed in: openssl (Ubuntu Xenial) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https

[Touch-packages] [Bug 1895294] Re: Fix Raccoon vulnerability (CVE-2020-1968)

2020-09-16 Thread Marc Deslauriers
It's not feasible to stop the affected ciphers from re-using secrets, it's in the specification. Removing the ciphers is what was done in later releases of openssl, including the 1.0.2w version that was released specifically to address this issue: https://www.openssl.org/news/secadv/20200909.txt

[Touch-packages] [Bug 1882098] Re: Packagekit lets user install untrusted local packages in Bionic and Focal

2020-09-23 Thread Marc Deslauriers
Hi Julian, Could you please backport the patch in comment #9 to xenial? The code in xenial is substantially different. Thanks! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to packagekit in Ubuntu. https://bugs.launchpad.net/

[Touch-packages] [Bug 1882098] Re: Packagekit lets user install untrusted local packages in Bionic and Focal

2020-09-23 Thread Marc Deslauriers
I am currently preparing updates for this issue, and I just tested the bionic update that includes this patch, and it works in my environment. Could you please make sure you created the policy file ok, and have rebooted after updating packagekit? -- You received this bug notification because you

[Touch-packages] [Bug 1888887] Re: Reading local files as root leads to sensitive information disclosure

2020-09-24 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to packagekit in Ubuntu. https://bugs.launchpad.net/bugs/187 Title: Reading local files as root leads to

[Touch-packages] [Bug 1888887] Re: Reading local files as root leads to sensitive information disclosure

2020-09-24 Thread Marc Deslauriers
The updates for this issue have been released: https://ubuntu.com/security/notices/USN-4538-1 Thanks! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to packagekit in Ubuntu. https://bugs.launchpad.net/bugs/187 Title: Re

[Touch-packages] [Bug 1882098] Re: Packagekit lets user install untrusted local packages in Bionic and Focal

2020-09-24 Thread Marc Deslauriers
The updates for this issue have been released: https://ubuntu.com/security/notices/USN-4538-1 Thanks! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to packagekit in Ubuntu. https://bugs.launchpad.net/bugs/1882098 Title: Pa

[Touch-packages] [Bug 1897666] Re: FTBFS: nss for groovy ftbfs due to erroneous nonnull check arising from glibc getcwd() annotation

2020-09-29 Thread Marc Deslauriers
** Changed in: nss (Ubuntu) Status: New => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to nss in Ubuntu. https://bugs.launchpad.net/bugs/1897666 Title: FTBFS: nss for groovy ftbfs due to erroneous nonn

[Touch-packages] [Bug 1899347] Re: whoopsie assert failure: double free or corruption (fasttop)

2020-10-27 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1899100 *** https://bugs.launchpad.net/bugs/1899100 ** Information type changed from Private to Public ** This bug has been marked a duplicate of bug 1899100 whoopsie assert failure: double free or corruption (fasttop) -- You received this bug notificat

[Touch-packages] [Bug 1899100] Re: whoopsie assert failure: double free or corruption (fasttop)

2020-10-27 Thread Marc Deslauriers
Here's a proposed fix, not sure if this is the exact cause of the double-free or if duplicate keys are acceptable or not. ** Patch added: "Proposed Fix" https://bugs.launchpad.net/ubuntu/+source/whoopsie/+bug/1899100/+attachment/5427819/+files/whoopsie_0.2.73~test1.debdiff ** Information type

[Touch-packages] [Bug 1900255] Re: accountsservice drop privileges denial of service (GHSL-2020-187, GHSL-2020-188)

2020-11-05 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to accountsservice in Ubuntu. https://bugs.launchpad.net/bugs/1900255 Title: accountsservice drop privileges

[Touch-packages] [Bug 1902931] Re: problem with nvidia on Ubuntu 18.04.5 LTS

2020-11-06 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1902758] Re: Xorg freeze

2020-11-06 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1902407] Re: package python3-pexpect 4.2.1-1 failed to install/upgrade: installed python3-pexpect package post-installation script subprocess returned error exit status 1

2020-11-06 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1903332] Re: Apport get_config incorrectly drops privileges

2020-11-12 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apport in Ubuntu. https://bugs.launchpad.net/bugs/1903332 Title: Apport get_config incorrectly drops privi

<    1   2   3   4   5   6   7   8   9   10   >