[Bug 2072648] Re: Regression in Apache 2.4.52-1ubuntu4.10 causes intermittent errors in mod_proxy_http2 backend

2024-07-11 Thread Marc Deslauriers
Regression fix USN has now been published: https://ubuntu.com/security/notices/USN-6885-2 Thanks! ** Changed in: apache2 (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[USN-6885-2] Apache HTTP Server regression

2024-07-11 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6885-2 July 11, 2024 apache2 regression == A security issue affects these releases of Ubuntu and its derivatives: -

[Bug 2072648] Re: Regression in Apache 2.4.52-1ubuntu4.10 causes intermittent errors in mod_proxy_http2 backend

2024-07-11 Thread Marc Deslauriers
(Ubuntu Jammy) Importance: Undecided Status: New ** Also affects: apache2 (Ubuntu Focal) Importance: Undecided Status: New ** Changed in: apache2 (Ubuntu Focal) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: apache2 (Ubuntu Jammy) Assig

[Bug 2072648] Re: Regression in Apache 2.4.52-1ubuntu4.10 causes intermittent errors in mod_proxy_http2 backend

2024-07-11 Thread Marc Deslauriers
I have uploaded a test package to the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages If you could give it a spin and see if it fixes the issue, that would be great. If it does, I'll release it as a regression update. Thanks! -- You

[Bug 2072648] Re: Regression in Apache 2.4.52-1ubuntu4.10 causes intermittent errors in mod_proxy_http2 backend

2024-07-11 Thread Marc Deslauriers
This is a stab in the dark but perhaps this is part of the problem: https://github.com/apache/httpd/commit/4d3a308014be26e5407113b4c827a1ea2882bf38 Would you be willing to try a test package if I build one? -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 2072648] Re: Regression in Apache 2.4.52-1ubuntu4.10 causes intermittent errors in mod_proxy_http2 backend

2024-07-11 Thread Marc Deslauriers
** Changed in: apache2 (Ubuntu) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2072648 Title: Regression in Apache 2.4.52-1ubuntu4

[Bug 2072648] Re: Regression in Apache 2.4.52-1ubuntu4.10 causes intermittent errors in mod_proxy_http2 backend

2024-07-11 Thread Marc Deslauriers
Is this all your are getting? "Reason: URI has no hostname: /…" Or did you edit that to remove sensitive info? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2072648 Title: Regression in Apache

[USN-6888-1] Django vulnerabilities

2024-07-09 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6888-1 July 09, 2024 python-django vulnerabilities == A security issue affects these releases of Ubuntu and its

[USN-6887-1] OpenSSH vulnerability

2024-07-09 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6887-1 July 09, 2024 openssh vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6885-1] Apache HTTP Server vulnerabilities

2024-07-08 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6885-1 July 08, 2024 apache2 vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6883-1] OpenStack Glance vulnerability

2024-07-08 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6883-1 July 08, 2024 glance vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6882-1] Cinder vulnerability

2024-07-08 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6882-1 July 08, 2024 cinder vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6884-1] Nova vulnerability

2024-07-08 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6884-1 July 08, 2024 nova vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[Bug 2069596] Re: blocks wrong IPv4 and IPv6 addresses on LE systems (reversed byte order)

2024-07-05 Thread Marc Deslauriers
** Changed in: crowdsec-firewall-bouncer (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2069596 Title: blocks wrong IPv4 and IPv6 addresses on LE systems

[Bug 2068823] Re: gofmt in golang-1.22-go flagged by multiple EDR software

2024-07-05 Thread Marc Deslauriers
We have no way of knowing why virustotal is flagging this as being malicious, so there is no actionable item we can take with this bug report. Could you get more details on the issue? ** Changed in: golang-1.22 (Ubuntu) Status: New => Incomplete -- You received this bug notification

[Bug 2069301] Re: Xorg crash

2024-07-05 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2070259]

2024-07-05 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 2069382] Re: The Gnome graphics session disappears with SSH errors

2024-07-05 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2069490] Re: Possible fingerjacking vulnerability: CVE-2024-37408

2024-07-05 Thread Marc Deslauriers
** Changed in: pam (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2069490 Title: Possible fingerjacking vulnerability: CVE-2024-37408 To manage notifications

[Bug 2069596]

2024-07-05 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 2070418]

2024-07-05 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 2071634] Re: [81DE, Realtek ALC236, Mic, Internal] No sound at all

2024-07-05 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2071614] Re: package libc-bin 2.35-0ubuntu3.8 failed to install/upgrade: installed libc-bin package post-installation script subprocess returned error exit status 126

2024-07-05 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2071924] Re: package libavahi-ui-gtk3-0 0.7-4ubuntu7 failed to install/upgrade: dpkg-deb --fsys-tarfile subprocess returned error exit status 2

2024-07-05 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2072168] Re: package click 0.5.2-2ubuntu4 failed to install/upgrade: installed click package post-installation script subprocess returned error exit status 1

2024-07-05 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[USN-6877-1] LibreOffice vulnerability

2024-07-04 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6877-1 July 04, 2024 libreoffice vulnerability == A security issue affects these releases of Ubuntu and its derivatives:

[Bug 2071777] Re: Unable to ssh to servers in other subnet

2024-07-03 Thread Marc Deslauriers
Thanks for reporting this issue. It's a pretty odd issue, because all the OpenSSH update did was disable a line that logged something, so I'm not sure how it could be related to connecting from a different subnet. Can you confirm that downgrading to the previous release fixes the issue? -- You

[Bug 2071815] Re: Investigate ASLR re-randomization being disabled for children

2024-07-03 Thread Marc Deslauriers
** Summary changed: - Investigate ASLR being disabled for children + Investigate ASLR re-randomization being disabled for children -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2071815 Title:

[Bug 2071815] Re: Investigate ASLR being disabled for children

2024-07-03 Thread Marc Deslauriers
Subscribing Nick, who appears to be the original delta author. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2071815 Title: Investigate ASLR being disabled for children To manage notifications

[Bug 2071815] [NEW] Investigate ASLR being disabled for children

2024-07-03 Thread Marc Deslauriers
*** This bug is a security vulnerability *** Public security bug reported: The systemd-socket-activation.patch patch has an Ubuntu delta to fix bug 2011458, but this results in ASLR not being re-randomized for children because the patch delta does "rexec_flag = 0;". This was discovered as part

[USN-6860-1] OpenVPN vulnerabilities

2024-07-02 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6860-1 July 02, 2024 openvpn vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives: -

[Bug 2070497] Re: June 2024 security issue

2024-07-02 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Changed in: openssh (Ubuntu Oracular) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2070315] Re: error in /etc/cups/cupsd.conf from today's patch

2024-06-26 Thread Marc Deslauriers
It looks like upstream released a follow-up commit to fix this issue, or one similar to it: https://github.com/OpenPrinting/cups/commit/145b946a86062aafab76c656ee9c1112bfd4f804 We will build test packages to see if this solves the regression, and if so, we will publish updates. ** Also affects:

[USN-6852-1] Wget vulnerability

2024-06-26 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6852-1 June 26, 2024 wget vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6843-1] Plasma Workspace vulnerability

2024-06-26 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6843-1 June 26, 2024 plasma-workspace vulnerability == A security issue affects these releases of Ubuntu and its

[USN-6853-1] Ruby vulnerability

2024-06-26 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6853-1 June 26, 2024 ruby2.7, ruby3.0, ruby3.1 vulnerability == A security issue affects these releases of Ubuntu and its

[Bug 2067742] Re: [SRU] CVE-2024-36041 Fix ksmserver: Unauthorized users can access session manager

2024-06-19 Thread Marc Deslauriers
I have built packages in the security team proposed PPA for testing. Additional packages required no-change rebuilds in the -security pocket also. For Jammy, the additional packages are breeze, libksysguard, layer-shell-qt, kwin, kwayland-server. For Focal, the additional packages are kwin and

[Bug 2067742] Re: [SRU] CVE-2024-36041 Fix ksmserver: Unauthorized users can access session manager

2024-06-18 Thread Marc Deslauriers
ACK on the debdiffs, packages are building now! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2067742 Title: [SRU] CVE-2024-36041 Fix ksmserver: Unauthorized users can access session manager To

[USN-6836-1] SSSD vulnerability

2024-06-17 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6836-1 June 17, 2024 sssd vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6838-1] Ruby vulnerabilities

2024-06-17 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6838-1 June 17, 2024 ruby2.7, ruby3.0, ruby3.1, ruby3.2 vulnerabilities == A security issue affects these releases of

[USN-6837-1] Rack vulnerabilities

2024-06-17 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6837-1 June 17, 2024 ruby-rack vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives:

[USN-6833-1] VTE vulnerability

2024-06-13 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6833-1 June 13, 2024 vte2.91 vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6830-1] libndp vulnerability

2024-06-12 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6830-1 June 12, 2024 libndp vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6823-1] MySQL vulnerabilities

2024-06-11 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6823-1 June 11, 2024 mysql-8.0 vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives:

[USN-6815-1] AOM vulnerability

2024-06-06 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6815-1 June 06, 2024 aom vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6814-1] libvpx vulnerability

2024-06-06 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6814-1 June 06, 2024 libvpx vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6567-2] QEMU regression

2024-06-06 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6567-2 June 06, 2024 qemu regression == A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu

[Bug 2065579] Re: [UBUNTU 22.04] OS guest boot issues on 9p filesystem

2024-06-03 Thread Marc Deslauriers
In response to comment #7, I have no issue releasing a security update regression fix for focal and jammy that relaxes the CVE fix for sockets since that is a change in behaviour. Let me know once the proposed patch has been successfully tested to resolve the issue. -- You received this bug

[Bug 2065579] Re: [UBUNTU 22.04] OS guest boot issues on 9p filesystem

2024-05-30 Thread Marc Deslauriers
This is the upstream commit which introduced the change in behaviour: https://gitlab.com/qemu- project/qemu/-/commit/f6b0de53fb87ddefed348a39284c8e2f28dc4eda There is no subsequent fix to the new restrictions, and the only more recent commit is one to deprecate the whole proxy backend:

[USN-6801-1] PyMySQL vulnerability

2024-05-30 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6801-1 May 30, 2024 python-pymysql vulnerability == A security issue affects these releases of Ubuntu and its

[USN-6802-1] PostgreSQL vulnerability

2024-05-30 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6802-1 May 30, 2024 postgresql-14, postgresql-15, postgresql-16 vulnerability == A security issue affects these releases

[USN-6794-1] FRR vulnerabilities

2024-05-28 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6794-1 May 28, 2024 frr vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives: -

[Bug 2065728] Re: CVE-2024-3044

2024-05-28 Thread Marc Deslauriers
These were all released: https://ubuntu.com/security/notices/USN-6789-1 ** Changed in: libreoffice (Ubuntu Focal) Status: In Progress => Fix Released ** Changed in: libreoffice (Ubuntu Jammy) Status: In Progress => Fix Released ** Changed in: libreoffice (Ubuntu Mantic)

[USN-6790-1] amavisd-new vulnerability

2024-05-28 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6790-1 May 28, 2024 amavisd-new vulnerability == A security issue affects these releases of Ubuntu and its derivatives:

[USN-6789-1] LibreOffice vulnerability

2024-05-28 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6789-1 May 28, 2024 libreoffice vulnerability == A security issue affects these releases of Ubuntu and its derivatives:

[USN-6788-1] WebKitGTK vulnerabilities

2024-05-28 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6788-1 May 28, 2024 webkit2gtk vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives:

[USN-6791-1] Unbound vulnerability

2024-05-28 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6791-1 May 28, 2024 unbound vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[Bug 2059852] Re: Invalid free called during libfreetype FT_Done_Glyph

2024-05-25 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2059852 Title: Invalid free called during libfreetype FT_Done_Glyph To manage

[Bug 2039354] Re: GDM does not prevent users with login shell /sbin/nologin from logging on

2024-05-24 Thread Marc Deslauriers
Adding gnome-session as this is where the logic exists. I don't see any changes in the latest gnome-session script. Could you please file a bug with the upstream gnome-session developers here?: https://gitlab.gnome.org/GNOME/gnome-session/-/issues Thanks! ** Also affects: gnome-session

[Bug 2041751] Re: RM: Remove dangerously insecure MPPE PPTP from Ubuntu

2024-05-24 Thread Marc Deslauriers
** Changed in: linux (Ubuntu) Status: New => Invalid ** Changed in: network-manager-pptp (Ubuntu) Status: New => Won't Fix ** Changed in: ubuntu-release-notes Status: New => Fix Released ** Changed in: pptp-linux (Ubuntu) Status: New => Confirmed -- You received

[Bug 2045330] Re: Please remove these packages before 24.04 LTS release

2024-05-24 Thread Marc Deslauriers
** Changed in: openjdk-22 (Ubuntu) Status: Triaged => Fix Committed ** Changed in: openjdk-22 (Ubuntu) Status: Fix Committed => Fix Released ** Changed in: openjdk-23 (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of

[Bug 2058434] Re: leakage of private information through window list preview

2024-05-24 Thread Marc Deslauriers
** Changed in: mate-desktop (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2058434 Title: leakage of private information through window list preview To

[Bug 2063034]

2024-05-24 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 2063035] Re: CVE-2023-28100: TIOCLINUX can send commands outside sandbox if running on a virtual console

2024-05-24 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 2063055]

2024-05-24 Thread Marc Deslauriers
** Tags added: community-security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2063055 Title: Boot failure 24.04 To manage notifications about this bug go to:

[Bug 2067044] Re: package man-db 2.12.0-4build2 failed to install/upgrade: error writing to '': Input/output error

2024-05-24 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2066368] Re: package linux-image-5.4.0-150-generic 5.4.0-150.167 failed to install/upgrade: installed linux-image-5.4.0-150-generic package post-installation script subprocess returned error exit

2024-05-24 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2065678] Re: nvidia-graphics-drivers-545 package fails to launch graphical session with latest linux 5.15.0-107 update

2024-05-24 Thread Marc Deslauriers
** Also affects: linux (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2065678 Title: nvidia-graphics-drivers-545 package fails to launch

[Bug 2066372]

2024-05-24 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[USN-6785-1] GNOME Remote Desktop vulnerability

2024-05-23 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6785-1 May 23, 2024 gnome-remote-desktop vulnerability == A security issue affects these releases of Ubuntu and its

[Bug 2065728] Re: CVE-2024-3044

2024-05-15 Thread Marc Deslauriers
Since they are new upstream versions, and are already going through the SRU process, I'll wait until they are verified-done, and I will do a no- change rebuild of them into the -security pocket. Does that sound reasonable? Thanks! -- You received this bug notification because you are a member

[Bug 2065728] Re: CVE-2024-3044

2024-05-15 Thread Marc Deslauriers
Thanks for the debdiffs, I will prepare packages in the security PPA and will comment back -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2065728 Title: CVE-2024-3044 To manage notifications about

[USN-6772-1] strongSwan vulnerability

2024-05-14 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6772-1 May 14, 2024 strongswan vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6768-1] GLib vulnerability

2024-05-09 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6768-1 May 09, 2024 glib2.0 vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6763-1] libvirt vulnerability

2024-05-07 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6763-1 May 07, 2024 libvirt vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6759-1] FreeRDP vulnerabilities

2024-04-29 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6759-1 April 29, 2024 freerdp3 vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives:

[USN-6729-3] Apache HTTP Server vulnerabilities

2024-04-29 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6729-3 April 29, 2024 apache2 vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives:

[USN-6718-3] curl vulnerabilities

2024-04-29 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6718-3 April 29, 2024 curl vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6737-2] GNU C Library vulnerability

2024-04-29 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6737-2 April 29, 2024 glibc vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[USN-6734-2] libvirt vulnerabilities

2024-04-29 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6734-2 April 29, 2024 libvirt vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives:

[USN-6733-2] GnuTLS vulnerabilities

2024-04-29 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6733-2 April 29, 2024 gnutls28 vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives:

[Bug 2062389] Re: [SRU] Fix segfault in systemdunitdependency probe

2024-04-26 Thread Marc Deslauriers
ACK on the debdiffs. Uploaded for processing by the SRU team. Thanks! ** Changed in: openscap (Ubuntu Focal) Status: New => In Progress ** Changed in: openscap (Ubuntu Jammy) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs,

[USN-6752-1] FreeRDP vulnerabilities

2024-04-25 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6752-1 April 25, 2024 freerdp2 vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives:

[USN-6749-1] FreeRDP vulnerabilities

2024-04-24 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6749-1 April 24, 2024 freerdp2 vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives:

[Bug 2060880] Re: squid crashes after update to 4.10-1ubuntu1.10

2024-04-23 Thread Marc Deslauriers
The regression fix has now been published: https://ubuntu.com/security/notices/USN-6728-3 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2060880 Title: squid crashes after update to

[USN-6728-3] Squid vulnerability

2024-04-23 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6728-3 April 23, 2024 squid vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[Bug 2062916] Re: evolution has undefined symbol in newest libwebkit2gtk

2024-04-22 Thread Marc Deslauriers
That is pretty odd, I can't reproduce this issue on jammy. what's the output of "ldd /lib/x86_64-linux- gnu/libwebkit2gtk-4.0.so.37"? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2062916 Title:

[Bug 2060880] Re: squid crashes after update to 4.10-1ubuntu1.10

2024-04-22 Thread Marc Deslauriers
Thanks for testing it, it's much appreciated! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2060880 Title: squid crashes after update to 4.10-1ubuntu1.10 To manage notifications about this bug go

[Bug 2060880] Re: squid crashes after update to 4.10-1ubuntu1.10

2024-04-19 Thread Marc Deslauriers
I have located the issue and have prepared an updated package that will reintroduce the fixes for CVE-2023-5824. I have uploaded the updated package to the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Once it has finished building, could

[USN-6737-1] GNU C Library vulnerability

2024-04-18 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6737-1 April 18, 2024 glibc vulnerability == A security issue affects these releases of Ubuntu and its derivatives: -

[Bug 2061816] Re: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired

2024-04-16 Thread Marc Deslauriers
That's good to see! Since this is a deliberate side-effect of the security change, I am marking this bug as "invalid". Thanks ** Changed in: apache2 (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 2061816] Re: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired

2024-04-16 Thread Marc Deslauriers
I think this is actually the correct new behaviour for the security update...could you please try using ap_trust_cgilike_cl as instructed here: https://bz.apache.org/bugzilla/show_bug.cgi?id=68872 ** Bug watch added: bz.apache.org/bugzilla/ #68872

[Bug 2061816] Re: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired

2024-04-16 Thread Marc Deslauriers
Thanks for testing, I'll keep digging... -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2061816 Title: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired To

[Bug 2061816] Re: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired

2024-04-16 Thread Marc Deslauriers
I have uploaded a package with a possible fix to the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Once it's finished building, could you please give it a try and see if it solves the issue for you? If so, I will publish it as a security

[Bug 2061816] Re: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired

2024-04-16 Thread Marc Deslauriers
I believe I've spotted the regression and will have a package to test soon. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2061816 Title: apache2 2.4.41-4ubuntu3.17 defaults to

[Bug 2061816] Re: apache2 2.4.41-4ubuntu3.17 defaults to transfer-encoding=chunked where this is undesired

2024-04-16 Thread Marc Deslauriers
Thanks for filing this bug, I'll investigate the changes and will report back. Have you seen this behaviour on anything other than focal? ** Changed in: apache2 (Ubuntu) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Information type changed from Public to Public Secur

[USN-6733-1] GnuTLS vulnerabilities

2024-04-15 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6733-1 April 15, 2024 gnutls28 vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives:

[USN-6732-1] WebKitGTK vulnerabilities

2024-04-15 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6732-1 April 15, 2024 webkit2gtk vulnerabilities == A security issue affects these releases of Ubuntu and its

[USN-6734-1] libvirt vulnerabilities

2024-04-15 Thread Marc Deslauriers
== Ubuntu Security Notice USN-6734-1 April 15, 2024 libvirt vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives:

[Bug 2058023] Re: New versions of amavis with security fixes

2024-04-15 Thread Marc Deslauriers
There are packages for focal, jammy, and mantic available for testing in the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages If they work in your environment, please mention it in this bug. Thanks! -- You received this bug notification

  1   2   3   4   5   6   7   8   9   10   >