[Touch-packages] [Bug 1794629] Re: CVE-2018-15473 - User enumeration vulnerability

2018-11-04 Thread Marc Deslauriers
** Also affects: openssh (Ubuntu Bionic) Importance: Undecided Status: New ** Also affects: openssh (Ubuntu Trusty) Importance: Undecided Status: New ** Also affects: openssh (Ubuntu Cosmic) Importance: Undecided Status: New ** Also affects: openssh (Ubuntu Xenial)

[Touch-packages] [Bug 1794169] Re: AWS ubuntu became unreachable after ssh login

2018-11-01 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://bugs.launchpad.net/bugs/1794169 Title: AWS ubuntu became unreachable after ssh login

[Touch-packages] [Bug 1802090] Re: update overwrites sshd_config

2018-11-07 Thread Marc Deslauriers
That's not supposed to happen. Could you please attach your /var/log /dist-upgrade/apt-term.log file? Did you update manually, or was this done automatically? Thanks. ** Changed in: openssh (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a

[Touch-packages] [Bug 1802090] Re: update overwrites sshd_config

2018-11-07 Thread Marc Deslauriers
It looks like you upgraded from Ubuntu 16.04 to Ubuntu 18.04. >From the log file: Unpacking openssh-server (1:7.6p1-4) over (1:7.2p2-4ubuntu2.4) ... Then the upgrade asked you what to do with the modified conffile, again, from the log: Configuring openssh-server sshd_config: A new version

[Touch-packages] [Bug 1802090] Re: update overwrites sshd_config

2018-11-07 Thread Marc Deslauriers
Oh, sorry about that, I didn't notice the date...and also requested the wrong log file. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssh in Ubuntu. https://bugs.launchpad.net/bugs/1802090 Title: update overwrites

[Touch-packages] [Bug 1802090] Re: update overwrites sshd_config

2018-11-07 Thread Marc Deslauriers
>From the new log: Preparing to unpack .../openssh-sftp-server_1%3a7.6p1-4ubuntu0.1_amd64.deb ... Unpacking openssh-sftp-server (1:7.6p1-4ubuntu0.1) over (1:7.6p1-4) ... Preparing to unpack .../openssh-server_1%3a7.6p1-4ubuntu0.1_amd64.deb ... Unpacking openssh-server (1:7.6p1-4ubuntu0.1) over

[Touch-packages] [Bug 1794629] Re: CVE-2018-15473 - User enumeration vulnerability

2018-11-08 Thread Marc Deslauriers
** Changed in: openssh (Ubuntu Cosmic) Status: In Progress => Fix Released ** Changed in: openssh (Ubuntu) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssh in Ubuntu.

[Touch-packages] [Bug 1793092] Re: [FFe] openssl 1.1.1

2018-09-19 Thread Marc Deslauriers
Big ACK from the security team. We would like to see this backported into bionic at some point and having it in cosmic first would allow us to identify and fix any issues. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1753572] Re: cpio in Busybox 1.27 ingnores "unsafe links"

2019-01-17 Thread Marc Deslauriers
I just uploaded this for bionic to be processed by the SRU team. Bryan, do you have an example archive that can be used to test this? Thanks! ** Changed in: busybox (Ubuntu Bionic) Status: Confirmed => In Progress -- You received this bug notification because you are a member of Ubuntu

[Touch-packages] [Bug 1811930] Re: package unattended-upgrades 1.1ubuntu1.18.04.8 failed to install/upgrade: installed unattended-upgrades package post-installation script subprocess returned error ex

2019-01-18 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Touch-packages] [Bug 1811719] Re: sfd

2019-01-18 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Touch-packages] [Bug 1807514] Re: update error

2019-01-18 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Touch-packages] [Bug 1808095] Re: uniq is not checking and handling all file types

2019-01-18 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to coreutils in Ubuntu. https://bugs.launchpad.net/bugs/1808095 Title: uniq is not checking and handling all file

[Touch-packages] [Bug 1808092] Re: Checking and handling various filetypes in fmt

2019-01-18 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to coreutils in Ubuntu. https://bugs.launchpad.net/bugs/1808092 Title: Checking and handling various filetypes in fmt

[Touch-packages] [Bug 1803059] Re: Nullpointer dereference

2018-12-04 Thread Marc Deslauriers
The upstream commit was assigned CVE-2018-19149. ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-19149 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to poppler in Ubuntu.

[Touch-packages] [Bug 828756] Re: getting "connection is untrusted" warnings

2018-12-03 Thread Marc Deslauriers
This is an ancient bug and likely no longer applies to recent releases. As such, I am closing it. If anyone is still hitting this issue with current releases, please file a new bug. ** Changed in: ca-certificates-java (Ubuntu) Status: Confirmed => Invalid ** Changed in: empathy (Ubuntu)

[Touch-packages] [Bug 1811210] Re: intramfs-tools 0.130ubuntu3.3 in bionic-security breaks netplan.io in -security or in release

2019-01-10 Thread Marc Deslauriers
A rebuild of netplan.io into the security pocket was performed an hour ago and should fix this issue. I am marking this bug as fix released, feel free to re-open it if the issue isn't actually resolved. Thanks! ** Changed in: initramfs-tools (Ubuntu) Status: New => Confirmed ** Changed

[Touch-packages] [Bug 1812353] Re: content injection in http method (CVE-2019-3462)

2019-01-22 Thread Marc Deslauriers
** Changed in: apt (Ubuntu Precise) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apt in Ubuntu. https://bugs.launchpad.net/bugs/1812353 Title: content injection in http method

[Touch-packages] [Bug 1821752] [NEW] libc6 version 2.19 breaks NSS loading for static binaries

2019-03-26 Thread Marc Deslauriers
Public bug reported: Rebuilding busybox on trusty breaks wget name resolution. Introduced by: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=0d23a5c1b1908700d25b7e3c6cece148e19dded4 fixed by: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=93bad7c97c7047ecaf7664859e2b49c0fe995443 **

[Touch-packages] [Bug 1818090] Re: Cups can not print with "filter failed" error just after ghostcript update

2019-02-28 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1818089 *** https://bugs.launchpad.net/bugs/1818089 ** This bug has been marked a duplicate of bug 1818089 Cups can not print with "filter failed" error just after ghostcript update -- You received this bug notification because you are a member of

[Touch-packages] [Bug 1753572] Re: cpio in Busybox 1.27 ingnores "unsafe links"

2019-02-18 Thread Marc Deslauriers
Thanks! ** Tags removed: verification-needed verification-needed-bionic ** Tags added: verification-done verification-done-bionic -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to busybox in Ubuntu.

[Touch-packages] [Bug 1816361] Re: remote ssh-login impossible with openssh 7.2p2-4ubuntu2.7

2019-02-19 Thread Marc Deslauriers
Could you please provide a log file to the authentication failure? Which version of OpenSSH works? ** Changed in: openssh (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssh in

[Touch-packages] [Bug 1818949] Re: a lot of time consume to open ubuntu

2019-03-07 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Touch-packages] [Bug 1818309] Re: package libqt53drenderer5 (not installed) failed to install/upgrade: trying to overwrite '/usr/lib/i386-linux-gnu/libQt53DRenderer.so.5.5.1', which is also in packag

2019-03-07 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Touch-packages] [Bug 1810241] Re: NULL dereference when decompressing specially crafted archives

2019-03-07 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to tar in Ubuntu. https://bugs.launchpad.net/bugs/1810241 Title: NULL dereference when decompressing

[Touch-packages] [Bug 1813833] Re: User without read permission on cron.allow can execute crontab

2019-03-07 Thread Marc Deslauriers
** Changed in: cron (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cron in Ubuntu. https://bugs.launchpad.net/bugs/1813833 Title: User without read permission on cron.allow can

[Touch-packages] [Bug 1818386] Re: Deb Packages not installing web browsers

2019-03-07 Thread Marc Deslauriers
Thanks for your comments. This does not appear to be a bug report and we are closing it. We appreciate the difficulties you are facing, but it would make more sense to raise your question in the support tracker. Please visit https://answers.launchpad.net/ubuntu/+addquestion ** Information type

[Touch-packages] [Bug 1818387] Re: package linux-firmware 1.157.21 failed to install/upgrade: il sottoprocesso installato script di post-installation ha restituito lo stato di errore 1

2019-03-07 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Touch-packages] [Bug 1803441] Re: BASH_CMDS is writable in restricted bash shells (fixed upstream, need to backport patch)

2019-03-07 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to bash in Ubuntu. https://bugs.launchpad.net/bugs/1803441 Title: BASH_CMDS is writable in restricted bash

[Touch-packages] [Bug 1803192] Re: Internal MIC stopped to work on 18.10

2019-03-07 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Touch-packages] [Bug 1797161] Re: GNOME Image Viewer (EOG): invalid XPM file causes dynamic memory allocation

2019-03-07 Thread Marc Deslauriers
** Bug watch added: gitlab.gnome.org/GNOME/gdk-pixbuf/issues #95 https://gitlab.gnome.org/GNOME/gdk-pixbuf/issues/95 ** Also affects: choreographics via https://gitlab.gnome.org/GNOME/gdk-pixbuf/issues/95 Importance: Unknown Status: Unknown ** Project changed: choreographics =>

[Touch-packages] [Bug 1753572] Re: cpio in Busybox 1.27 ingnores "unsafe links"

2019-02-18 Thread Marc Deslauriers
Hi Bryan, Could you please test the package that is now in bionic-proposed, and post your results here? Thanks! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to busybox in Ubuntu. https://bugs.launchpad.net/bugs/1753572

[Touch-packages] [Bug 1782263] Re: NetworkManager authentication problems caused by polkit

2019-01-24 Thread Marc Deslauriers
This is likely a bug in network-manager, not policykit...adding network- manager to this. Also, I don't see any activity on the upstream bug that would suggest it's been addressed in any way. ** Also affects: network-manager (Ubuntu) Importance: Undecided Status: New -- You received

[Touch-packages] [Bug 1824498] Re: Unable to connect to wifi since wpasupplicant_2.4-0ubuntu6.4_amd64.deb update

2019-04-12 Thread Marc Deslauriers
What happens when you try to connect? What kind of wireless connection are you using? Do you have anything relevant in your log files? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to wpa in Ubuntu.

[Touch-packages] [Bug 1824961] Re: AppArmor blocks apport python hook from working

2019-04-16 Thread Marc Deslauriers
Reassigning to the kopanocore package as that is what contains the problematic profile. ** Package changed: apparmor (Ubuntu) => kopanocore (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu.

[Touch-packages] [Bug 1828215] Re: openssl ca -spkac output regressed

2019-06-13 Thread Marc Deslauriers
ACK from the security team on the low CVE being included in this SRU. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bugs/1828215 Title: openssl ca -spkac output regressed

[Touch-packages] [Bug 1832522] Re: openssl maintainer scripts do not trigger services restart

2019-06-13 Thread Marc Deslauriers
ACK from the security team on the low CVE being included in this SRU. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bugs/1832522 Title: openssl maintainer scripts do not

[Touch-packages] [Bug 1832397] Re: dbus errors and running older version

2019-06-12 Thread Marc Deslauriers
Hi, > Linux bitfenix-server 5.1.6-050106-generic #201905311031 SMP Fri May 31 That's not an Ubuntu kernel. Did you install a custom kernel? > dbus[19216]: Failed to start message bus: Failed to open "/etc/selinux/default/contexts/dbus_contexts": No such file or directory It looks like dbus

[Touch-packages] [Bug 1832257] Re: regression: sudo returns exit code 0 if child is killed with SIGTERM

2019-06-10 Thread Marc Deslauriers
Oh wow, I'm not sure how that happened. I'll release an update for this. ** Changed in: sudo (Ubuntu) Status: New => Confirmed ** Changed in: sudo (Ubuntu) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Also affects: sudo (Ubuntu Xenial) Importance: Und

[Touch-packages] [Bug 1832257] Re: regression: sudo returns exit code 0 if child is killed with SIGTERM

2019-06-10 Thread Marc Deslauriers
I've uploaded it to build in the following PPA: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages You can get it from there if you need it before tomorrow. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is

[Touch-packages] [Bug 1832257] Re: regression: sudo returns exit code 0 if child is killed with SIGTERM

2019-06-10 Thread Marc Deslauriers
I'll release it tomorrow. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to sudo in Ubuntu. https://bugs.launchpad.net/bugs/1832257 Title: regression: sudo returns exit code 0 if child is killed with SIGTERM Status in sudo

[Touch-packages] [Bug 1832337] Re: Require password when starting usb-creator

2019-06-18 Thread Marc Deslauriers
This will also require usb-creator to be modified to have a single policykit prompt. ** Also affects: usb-creator (Ubuntu) Importance: Undecided Status: New ** Changed in: usb-creator (Ubuntu) Assignee: (unassigned) => Ubuntu Security Team (ubuntu-security) ** Changed in:

[Touch-packages] [Bug 1828215] Re: openssl ca -spkac output regressed

2019-06-13 Thread Marc Deslauriers
I have run bionic-proposed cosmic-proposed and disco-proposed through the usual security team test procedure. They can be released with the fix for CVE-2019-1543. ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-1543 -- You received this bug notification because you are a

[Touch-packages] [Bug 1832397] Re: dbus errors and running older version

2019-06-12 Thread Marc Deslauriers
> If you go to It Linux kernel web page you see kernel is at 5.1.x Your issues are caused by the fact that you're running an unsupported kernel that isn't configured to work properly with Ubuntu. Please switch back to running a proper Ubuntu kernel. -- You received this bug notification because

[Touch-packages] [Bug 1832397] Re: dbus errors and running older version

2019-06-11 Thread Marc Deslauriers
Where exactly are you seeing that message? Does it work after rebooting? ** Changed in: dbus (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to dbus in Ubuntu.

[Touch-packages] [Bug 1828439] Re: false error message displaying printer out of paper

2019-05-09 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1828401 *** https://bugs.launchpad.net/bugs/1828401 ** This bug has been marked a duplicate of bug 1828401 9.26~dfsg+0-0ubuntu0.18.04.9 breaks cups printing of pdf -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 1823872] Re: Fixing fsfreeze-hook can break unattended upgrades

2019-05-24 Thread Marc Deslauriers
There are qemu packages for testing in the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to unattended-upgrades in Ubuntu.

[Touch-packages] [Bug 1781699] Re: DHCPv6 server crashes regularly (bionic)

2019-05-10 Thread Marc Deslauriers
Great, thanks for testing, I'll release these early next week! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to isc-dhcp in Ubuntu. https://bugs.launchpad.net/bugs/1781699 Title: DHCPv6 server crashes regularly (bionic)

[Touch-packages] [Bug 1797386] Re: [SRU] OpenSSL 1.1.1 to 18.04 LTS

2019-05-14 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bugs/1797386 Title: [SRU] OpenSSL 1.1.1 to 18.04 LTS Status in

[Touch-packages] [Bug 1781699] Re: DHCPv6 server crashes regularly (bionic)

2019-05-06 Thread Marc Deslauriers
) Importance: Undecided Status: New ** Changed in: isc-dhcp (Ubuntu Bionic) Status: New => In Progress ** Changed in: isc-dhcp (Ubuntu Bionic) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: isc-dhcp (Ubuntu Cosmic) Status: New => In

[Touch-packages] [Bug 1781699] Re: DHCPv6 server crashes regularly (bionic)

2019-05-06 Thread Marc Deslauriers
Packages for this issue are now available in the security team test ppa here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Could someone please try them out and make sure they resolve the issue? Thanks! -- You received this bug notification because you are a

[Touch-packages] [Bug 1834494] Re: latest bzip2 reports crc errors incorrectly

2019-06-28 Thread Marc Deslauriers
** Bug watch added: gitlab.com/federicomenaquintero/bzip2/issues #24 https://gitlab.com/federicomenaquintero/bzip2/issues/24 ** Also affects: bzip2 via https://gitlab.com/federicomenaquintero/bzip2/issues/24 Importance: Unknown Status: Unknown -- You received this bug

[Touch-packages] [Bug 1835135] Re: FIPS OpenSSL crashes Python2 hashlib

2019-07-10 Thread Marc Deslauriers
ium ** Changed in: python3.5 (Ubuntu Xenial) Status: New => In Progress ** Changed in: python3.5 (Ubuntu Xenial) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: python2.7 (Ubuntu Xenial) Importance: Undecided => Medium ** Changed in: python2.7 (Ubuntu Xe

[Touch-packages] [Bug 1834129] Re: Presence of sshd_config mandatory

2019-07-03 Thread Marc Deslauriers
Thanks for updating the bug! I'll close it now. ** Changed in: openssh (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssh in Ubuntu. https://bugs.launchpad.net/bugs/1834129

[Touch-packages] [Bug 1832919] Re: installed libssl1.1:amd64 package post-installation script subprocess returned error exit status 10

2019-07-08 Thread Marc Deslauriers
** Tags removed: verification-needed-bionic ** Tags added: verification-done-bionic -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bugs/1832919 Title: installed

[Touch-packages] [Bug 1840529] Re: System drop to emergency shell if encrypted home password was not provided

2019-08-23 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Touch-packages] [Bug 1840786] Re: Xorg freeze

2019-08-23 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Touch-packages] [Bug 1840615] Re: Slow booting, slow start-up & once a week fsck issues in Ubuntu 19.04

2019-08-23 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Touch-packages] [Bug 1843717] Re: Resolution

2019-09-17 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Touch-packages] [Bug 1838489] Re: adduser & deluser shell command injection

2019-09-17 Thread Marc Deslauriers
Hi! Have you had a chance to report this issue to Debian? ** Changed in: adduser (Ubuntu) Status: New => Incomplete ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which

[Touch-packages] [Bug 1842131] Re: ibus-ui-gtk3 crashed with SIGSEGV in ibus_bus_get_engines_by_names()

2019-09-17 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1842022 *** https://bugs.launchpad.net/bugs/1842022 ** This bug has been marked a duplicate of private bug 1842022 ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Touch

[Touch-packages] [Bug 1843829] Re: Incorrect Sudo configuration

2019-09-17 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Changed in: sudo (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to sudo in Ubuntu.

[Touch-packages] [Bug 1812316] Re: systemd: lack of seat verification in PAM module permits spoofing active session to polkit

2019-09-17 Thread Marc Deslauriers
This was fixed a while ago: https://usn.ubuntu.com/3938-1/ Marking this bug as fix released. Thanks! ** Changed in: systemd (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1822218] Re: clear crashed with SIGSEGV in __libc_start_main()

2019-09-17 Thread Marc Deslauriers
** Attachment removed: "CoreDump.gz" https://bugs.launchpad.net/ubuntu/+source/ncurses/+bug/1822218/+attachment/5250342/+files/CoreDump.gz ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 1791691] Re: PATH broken in systemd units

2019-09-17 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to initramfs-tools in Ubuntu. https://bugs.launchpad.net/bugs/1791691 Title: PATH broken in systemd units Status in

[Touch-packages] [Bug 1780506] Re: Password visible in systemd password prompt if user types too slow

2019-09-17 Thread Marc Deslauriers
Hi! Have you reported this issue to the upstream systemd developers? If not, could you please report it to them so that it can get fixed? Thanks! ** Changed in: systemd (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch

[Touch-packages] [Bug 1782225] Re: Cache poisoning vulnerability on the OS level DNS cache in Ubuntu

2019-09-17 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Changed in: dnsmasq (Ubuntu) Status: New => Confirmed ** Changed in: systemd (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages,

[Touch-packages] [Bug 1801383] Re: the WifiSyslog apport hook (used in firefox/tb) includes SSID informations

2019-09-17 Thread Marc Deslauriers
Hi Brian, Is this bug on your radar? Thanks! ** Changed in: apport (Ubuntu) Status: New => Confirmed ** Changed in: linux (Ubuntu) Status: Confirmed => Invalid ** Changed in: apport (Ubuntu) Assignee: (unassigned) => Brian Murray (brian-murray) -- You received this bug

[Touch-packages] [Bug 1801383] Re: the WifiSyslog apport hook (used in firefox/tb) includes SSID informations

2019-09-17 Thread Marc Deslauriers
Olivier, Did this fix make it to Thunderbird? Thanks! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apport in Ubuntu. https://bugs.launchpad.net/bugs/1801383 Title: the WifiSyslog apport hook (used in firefox/tb)

[Touch-packages] [Bug 1797161] Re: GNOME Image Viewer (EOG): invalid XPM file causes dynamic memory allocation

2019-09-17 Thread Marc Deslauriers
** Changed in: eog (Ubuntu) Status: New => Incomplete ** Changed in: eog (Ubuntu) Status: Incomplete => Invalid ** Changed in: gdk-pixbuf (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which

[Touch-packages] [Bug 1752417] Re: [ffe] including network-manager-openvpn-gnome, network-manager-l2tp-gnome, and network-manager-strongswan in the default installation

2019-09-17 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to network-manager in Ubuntu. https://bugs.launchpad.net/bugs/1752417 Title: [ffe] including

[Touch-packages] [Bug 1797012] Re: Fingerprint login can be changed without authentication

2019-09-17 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1532264 *** https://bugs.launchpad.net/bugs/1532264 I am going to mark this as a dupe of bug 1532264 since it looks to be the same root cause. Thanks! ** Information type changed from Private Security to Public Security ** This bug has been marked a

[Touch-packages] [Bug 1792004] Re: built-in PATH seems to have sbin and bin out of order; and inconsistent

2019-09-17 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://bugs.launchpad.net/bugs/1792004 Title: built-in PATH seems to have sbin and bin out of

[Touch-packages] [Bug 1823419] Re: jbig-kit calls abort() on invalid data, crashing many programs

2019-09-17 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to jbigkit in Ubuntu. https://bugs.launchpad.net/bugs/1823419 Title: jbig-kit calls abort() on invalid data,

[Touch-packages] [Bug 1838489] Re: adduser & deluser shell command injection

2019-09-17 Thread Marc Deslauriers
Thanks! ** Also affects: adduser (Debian) via https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=940577 Importance: Unknown Status: Unknown ** Changed in: adduser (Ubuntu) Status: Incomplete => Confirmed -- You received this bug notification because you are a member of

[Touch-packages] [Bug 1837734] Re: Firefox crash on a FIPS enabled machine due to libnss3

2019-07-24 Thread Marc Deslauriers
** Also affects: nss (Ubuntu Eoan) Importance: High Assignee: Vineetha Kamath (vineetha) Status: New ** Also affects: nss (Ubuntu Xenial) Importance: Undecided Status: New ** Also affects: nss (Ubuntu Disco) Importance: Undecided Status: New ** Also affects:

[Touch-packages] [Bug 1837734] Re: Firefox crash on a FIPS enabled machine due to libnss3

2019-07-24 Thread Marc Deslauriers
ACK on the debdiffs. Uploaded to eoan and to previous releases for processing by the SRU team, with slight versioning adjustment and the bug tag added to the changelog. Thanks! ** Changed in: nss (Ubuntu Xenial) Status: Confirmed => In Progress ** Changed in: nss (Ubuntu Bionic)

[Touch-packages] [Bug 1801383] Re: the WifiSyslog apport hook (used in firefox/tb) includes SSID informations

2019-09-19 Thread Marc Deslauriers
WifiSyslog does contain SSID information. While this will be removed from the thunderbird and firefox packages, I don't think it would be appropriate to remove it from the linux kernel apport reports. For linux packages, this information is helpful in debugging wireless driver issues. While a

[Touch-packages] [Bug 1452115] Re: Python interpreter binary is not compiled as PIE

2019-09-23 Thread Marc Deslauriers
** Changed in: python3.6 (Ubuntu) Assignee: (unassigned) => Ubuntu Security Team (ubuntu-security) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to python2.7 in Ubuntu. https://bugs.launchpad.net/bugs/1452115 Title:

[Touch-packages] [Bug 1834494] Re: latest bzip2 reports crc errors incorrectly

2019-06-28 Thread Marc Deslauriers
** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to bzip2 in Ubuntu. https://bugs.launchpad.net/bugs/1834494 Title: latest bzip2 reports crc errors incorrectly Status

[Touch-packages] [Bug 1856006] Re: The repository 'http://ppa.launchpad.net/blaimi/phpmyadmin-omnibus/ubuntu eoan Release' does not have a Release file. N: Updating from such a repository can't be don

2019-12-11 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Touch-packages] [Bug 1850032] Re: scanbd prevents HP printers to work correctly with HPLIP

2019-12-11 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1850032 Title: scanbd prevents HP printers to work correctly with

[Touch-packages] [Bug 1791405] Re: bluetooth always in discoverable mode (security issue)

2019-10-18 Thread Marc Deslauriers
** Changed in: bluez (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to bluez in Ubuntu. https://bugs.launchpad.net/bugs/1791405 Title: bluetooth always in discoverable mode (security

[Touch-packages] [Bug 1823419] Re: jbig-kit calls abort() on invalid data, crashing many programs

2019-10-18 Thread Marc Deslauriers
** Changed in: jbigkit (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to jbigkit in Ubuntu. https://bugs.launchpad.net/bugs/1823419 Title: jbig-kit calls abort() on invalid data,

[Touch-packages] [Bug 1717490] Re: LightDM keeps plain text login password in memory

2019-10-18 Thread Marc Deslauriers
** Changed in: lightdm (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lightdm in Ubuntu. https://bugs.launchpad.net/bugs/1717490 Title: LightDM keeps plain text login password in

[Touch-packages] [Bug 1717476] Re: DHCP Transaction ID (xid) is logged with INFO loglevel

2019-10-18 Thread Marc Deslauriers
** Changed in: isc-dhcp (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to isc-dhcp in Ubuntu. https://bugs.launchpad.net/bugs/1717476 Title: DHCP Transaction ID (xid) is logged with

[Touch-packages] [Bug 1832356] Re: Upgrade OpenSSH to 7.9p1-10 or better in stable series

2019-09-20 Thread Marc Deslauriers
** Changed in: openssh (Ubuntu Cosmic) Status: Confirmed => Won't Fix -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssh in Ubuntu. https://bugs.launchpad.net/bugs/1832356 Title: Upgrade OpenSSH to 7.9p1-10 or

[Touch-packages] [Bug 1844790] [NEW] Update OpenSSH in bionic to (1:7.9p1-10) for FIPS

2019-09-20 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1832356 *** https://bugs.launchpad.net/bugs/1832356 *** This bug is a security vulnerability *** Public security bug reported: Now that OpenSSL 1.1.1 has been added to Bionic, we would like to update OpenSSH to a version that can be linked to OpenSSL

[Touch-packages] [Bug 1822736] Re: Passwords longer than 255 characters break authentication

2019-10-05 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Touch-packages] [Bug 1844853] Re: IBus no longer works in Qt applications after upgrade

2020-03-03 Thread Marc Deslauriers
Is anyone actively working on the glib2.0 SRUs? We are blocked on them for our ibus security update... -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ibus in Ubuntu. https://bugs.launchpad.net/bugs/1844853 Title: IBus no

[Touch-packages] [Bug 1865504] Re: hwclock reports incorrect status in audit message

2020-03-05 Thread Marc Deslauriers
ACK on the debdiff in comment #3. Uploaded to focal. Thanks! ** Changed in: util-linux (Ubuntu) Status: New => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to util-linux in Ubuntu.

[Touch-packages] [Bug 1861472] Re: upgrade from fresh bionic to focal needlessly prompts user

2020-01-31 Thread Marc Deslauriers
Perhaps the hash is missing in debian/openssh-server.ucf-md5sum? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssh in Ubuntu. https://bugs.launchpad.net/bugs/1861472 Title: upgrade from fresh bionic to focal

[Touch-packages] [Bug 1860606] Re: TypeError: _fetch_archives() missing 1 required positional argument: 'allow_unauthenticated'

2020-01-22 Thread Marc Deslauriers
signee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: python-apt (Ubuntu Bionic) Importance: Undecided => High ** Changed in: python-apt (Ubuntu Bionic) Status: New => Confirmed ** Changed in: python-apt (Ubuntu Bionic) Assignee: (unassigned) => Marc Deslauriers (mde

[Touch-packages] [Bug 1860606] Re: TypeError: _fetch_archives() missing 1 required positional argument: 'allow_unauthenticated'

2020-01-22 Thread Marc Deslauriers
** Changed in: ubuntu-release-upgrader (Ubuntu Xenial) Status: Confirmed => Invalid ** Changed in: ubuntu-release-upgrader (Ubuntu Bionic) Status: Confirmed => Invalid ** Changed in: ubuntu-release-upgrader (Ubuntu Disco) Status: Confirmed => Invalid ** Changed in:

[Touch-packages] [Bug 1856494] Re: system program problem detected

2020-03-11 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apport in Ubuntu. https://bugs.launchpad.net/bugs/1856494 Title: system program problem detected Status in apport

[Touch-packages] [Bug 1854120] Re: Screen contents visible briefly on lock screen on resolution change

2020-03-11 Thread Marc Deslauriers
** Changed in: lightdm (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lightdm in Ubuntu. https://bugs.launchpad.net/bugs/1854120 Title: Screen contents visible briefly on lock screen

[Touch-packages] [Bug 1865831] Re: bug

2020-03-11 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Touch-packages] [Bug 1864982] Re: Ubuntu desktop computer doesn't seem to lock correctly

2020-03-11 Thread Marc Deslauriers
What desktop environment are you using? ** Changed in: lightdm (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lightdm in Ubuntu. https://bugs.launchpad.net/bugs/1864982 Title:

[Touch-packages] [Bug 1850820] Re: idhclient

2020-03-11 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Changed in: isc-dhcp (Ubuntu Focal) Status: New => In Progress ** Changed in: isc-dhcp (Ubuntu Focal) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) -- You received this bug notification becau

[Touch-packages] [Bug 1865474] Re: sysytemd-resolved automatically use an ipv6 dns server on lan

2020-03-11 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://bugs.launchpad.net/bugs/1865474 Title: sysytemd-resolved automatically use an ipv6 dns

<    3   4   5   6   7   8   9   10   11   12   >