[Bug 1970779] Re: Upgrade to 2.36.7 for Focal and Jammy

2022-08-28 Thread Luís Cunha dos Reis Infante da Câmara
** Summary changed: - Upgrade to 2.36.6 for Focal and Jammy + Upgrade to 2.36.7 for Focal and Jammy ** Description changed: - I want to upgrade the versions in Focal and Jammy to 2.36.6 to fix + I want to upgrade the versions in Focal and Jammy to 2.36.7 to fix security issues and other bugs,

[Bug 1970779] Re: Upgrade to 2.36.6 for Focal and Jammy

2022-08-17 Thread Luís Cunha dos Reis Infante da Câmara
Test plan: 1. Add my PPA (https://launchpad.net/~luis220413/+archive/ubuntu/security-updates/) to a test system running Ubuntu 20.04 or 22.04 (both releases must be tested). 2. Install cog with "sudo apt install cog" 3. Run cog -P x11 https://ubuntu.com/ 4. Run cog -P headless https://ubuntu.com

[Bug 1970779] Re: Upgrade to 2.36.6 for Focal and Jammy

2022-08-14 Thread Luís Cunha dos Reis Infante da Câmara
There are 3 snaps that contain WPE WebKit: * https://snapcraft.io/wpe-webkit-mir-kiosk-with-delay * https://snapcraft.io/wpe-webkit-mir-kiosk * https://snapcraft.io/wpe-webkit-libs ** Changed in: wpewebkit (Ubuntu Focal) Status: New => Confirmed ** Changed in: wpewebkit (Ubuntu Jammy)

[Bug 1970779] Re: Upgrade to 2.36.6 for Focal and Jammy

2022-08-14 Thread Luís Cunha dos Reis Infante da Câmara
: wpewebkit (Ubuntu) Status: Fix Committed => In Progress ** Changed in: wpewebkit (Ubuntu) Assignee: (unassigned) => Luís Cunha dos Reis Infante da Câmara (luis220413) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to t

[Bug 1970779] Re: Upgrade to 2.36.4 for Focal and Jammy

2022-08-07 Thread Luís Cunha dos Reis Infante da Câmara
WPE WebKit 2.36.6 was released today and I will package it next week (August 8-14). ** Summary changed: - Upgrade to 2.36.4 for Focal and Jammy + Upgrade to 2.36.6 for Focal and Jammy ** Description changed: - I want to upgrade the versions in Focal and Jammy to 2.36.4 to fix + [To be updated o

[Bug 1970779] Re: Upgrade to 2.36.4 for Focal and Jammy

2022-07-14 Thread Luís Cunha dos Reis Infante da Câmara
As I mentioned in the #ubuntu-security channel, to guarantee that we are not introducing issues, in addition to testing the package, only consider the changes in the Debian packaging tarball (ignoring the upstream changes). -- You received this bug notification because you are a member of Ubuntu

[Bug 1970779] Re: Upgrade to 2.36.4 for Focal and Jammy

2022-07-14 Thread Luís Cunha dos Reis Infante da Câmara
The patched source packages build successfully on all architectures. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1970779 Title: Upgrade to 2.36.4 for Focal and Jammy To manage notificatio

[Bug 1970779] Re: Upgrade to 2.36.4 for Focal and Jammy

2022-07-13 Thread Luís Cunha dos Reis Infante da Câmara
Impish will reach end-of-life tomorrow. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1970779 Title: Upgrade to 2.36.4 for Focal and Jammy To manage notifications about this bug go to: http

[Bug 1970779] Re: Upgrade to 2.36.4 for Focal, Impish and Jammy

2022-07-13 Thread Luís Cunha dos Reis Infante da Câmara
** Description changed: - I want to upgrade the versions in Focal, Impish and Jammy to 2.36.4 to - fix security issues and other bugs, as well as adding features that - increase compatibility with current websites. + I want to upgrade the versions in Focal and Jammy to 2.36.4 to fix + security iss

[Bug 1970779] Re: Upgrade to 2.36.4 for Focal, Impish and Jammy

2022-07-13 Thread Luís Cunha dos Reis Infante da Câmara
Given the first paragraph of comment #18, I just converted this bug back into a security update. ** Description changed: I want to upgrade the versions in Focal, Impish and Jammy to 2.36.4 to fix security issues and other bugs, as well as adding features that increase compatibility with cur

[Bug 1968922] Re: libnss3 is affected by CVE-2022-22747

2022-07-11 Thread Luís Cunha dos Reis Infante da Câmara
Fixed in versions 2:3.35-2ubuntu2.15 (18.04), 2:3.49.1-1ubuntu1.8 (20.04) and 2:3.68-1ubuntu1.2 (21.10). The version in Ubuntu 22.04 is not vulnerable. ** Changed in: nss (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bu

[Bug 1970779] Re: Upgrade to 2.36.4 for Focal, Impish and Jammy

2022-07-05 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-22662 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-22677 ** Description changed: I want to upgrade the versions in Focal, Impish and Jammy to 2.36.4 to fix security issues and other bugs, as well as adding

[Bug 1970779] Re: Upgrade to 2.36.3 for Focal, Impish and Jammy

2022-07-05 Thread Luís Cunha dos Reis Infante da Câmara
Patched packages are building in my PPA: https://launchpad.net/~luis220413/+archive/ubuntu/security-updates. ** Summary changed: - Upgrade to 2.36.3 for Focal, Impish and Jammy + Upgrade to 2.36.4 for Focal, Impish and Jammy ** Description changed: - I want to upgrade the versions in Focal, Imp

[Bug 1970779] Re: Upgrade to 2.36.3 for Focal, Impish and Jammy

2022-07-05 Thread Luís Cunha dos Reis Infante da Câmara
Version 2.36.4 was released today. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1970779 Title: Upgrade to 2.36.3 for Focal, Impish and Jammy To manage notifications about this bug go to: h

[Bug 1970779] Re: Upgrade to 2.36.3 for Focal, Impish and Jammy

2022-06-29 Thread Luís Cunha dos Reis Infante da Câmara
The upstream project recommends updating the versions of WPE WebKit, especially when they include fixes for known security issues: https://lists.webkit.org/pipermail/webkit-wpe/2022-June/000522.html -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed

[Bug 1970779] Re: Upgrade to 2.36.3 for Focal, Impish and Jammy

2022-06-28 Thread Luís Cunha dos Reis Infante da Câmara
I have sent an email to the upstream mailing list (webkit-wpe) asking if anyone is using the WPE WebKit packages in Ubuntu in production: https://lists.webkit.org/pipermail/webkit-wpe/2022-June/000520.html -- You received this bug notification because you are a member of Ubuntu Bugs, which is sub

[Bug 1968922] Re: libnss3 is affected by CVE-2022-22747

2022-06-22 Thread Luís Cunha dos Reis Infante da Câmara
I requested to the security team that this CVE be fixed in Ubuntu and Marc Deslauriers (from the security team) replied: We rated this CVE priority to be "low", which means we will not fix it until more important security issues come up in NSS. -- You received this bug notification because you a

[Bug 1968922] Re: libnss3 is affected by CVE-2022-22747

2022-06-20 Thread Luís Cunha dos Reis Infante da Câmara
Version 2:3.49.1-1ubuntu1.7 was released after this bug was reported and does not contain a fix for this CVE. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1968922 Title: libnss3 is affected

[Bug 1970779] Re: Upgrade to 2.36.3 for Focal, Impish and Jammy

2022-06-17 Thread Luís Cunha dos Reis Infante da Câmara
We can use cog for testing that the CVEs are fixed, if necessary. Due to the exception in comment #18, I believe that this bug can go through the security sponsoring process. The snap https://snapcraft.io/wpe-webkit-mir-kiosk has been installed/used recently by a substantial number of users (accor

[Bug 1970779] Re: Upgrade to 2.36.3 for Focal, Impish and Jammy

2022-06-16 Thread Luís Cunha dos Reis Infante da Câmara
** Changed in: wpewebkit (Ubuntu) Assignee: Luís Cunha dos Reis Infante da Câmara (luis220413) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1970779 Title: Upgrade

[Bug 1970779] Re: Upgrade to 2.36.3 for Focal, Impish and Jammy

2022-06-15 Thread Luís Cunha dos Reis Infante da Câmara
I have just transformed this bug into an Stable Release Update bug. ** Description changed: I want to upgrade the versions in Focal, Impish and Jammy to 2.36.3 to fix security issues and other bugs, as well as adding features that increase compatibility with current websites. The versi

[Bug 1970779] Re: Upgrade to 2.36.3 for Focal, Impish and Jammy

2022-06-15 Thread Luís Cunha dos Reis Infante da Câmara
** Description changed: + I want to upgrade the versions in Focal, Impish and Jammy to 2.36.3 to + fix security issues and other bugs, as well as adding features that + increase compatibility with current websites. + The version in Focal is affected by all vulnerabilities listed below. The

[Bug 1970779] Re: Multiple vulnerabilities in Focal, Impish and Jammy

2022-06-15 Thread Luís Cunha dos Reis Infante da Câmara
** Changed in: wpewebkit (Ubuntu) Status: Fix Committed => New ** Summary changed: - Multiple vulnerabilities in Focal, Impish and Jammy + Upgrade to 2.36.3 for Focal, Impish and Jammy -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to t

[Bug 1939281] Re: Please provide update for CVE-2021-36740 (VSV00007 Varnish HTTP/2 Request Smuggling Attack)

2022-06-08 Thread Luís Cunha dos Reis Infante da Câmara
** CVE removed: https://cve.mitre.org/cgi- bin/cvename.cgi?name=2019-20637 ** CVE removed: https://cve.mitre.org/cgi- bin/cvename.cgi?name=2020-11653 ** CVE removed: https://cve.mitre.org/cgi- bin/cvename.cgi?name=2022-23959 -- You received this bug notification because you are a member of Ubun

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-06-05 Thread Luís Cunha dos Reis Infante da Câmara
I am going through the last XSA (XSA-400) and will, if a local build is successful, add a patch for Focal tomorrow. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates s

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-06-05 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-3639 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To manag

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-05 Thread Luís Cunha dos Reis Infante da Câmara
Complete log for all tests in 18.04. All .err files are either attached or in lena_test_errors.tar.xz. ** Attachment added: "ffmpeg_test_log" https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/1970674/+attachment/5594952/+files/ffmpeg_test_log -- You received this bug notification because

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-05 Thread Luís Cunha dos Reis Infante da Câmara
** Attachment added: "sub2video.err" https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/1970674/+attachment/5594951/+files/sub2video.err -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970674 Ti

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-05 Thread Luís Cunha dos Reis Infante da Câmara
Test force_key_frames is also failing on 18.04. TESTforce_key_frames --- /home/user/ffmpeg-3.4.11/tests/ref/fate/force_key_frames2022-05-14 00:07:14.0 +0100 +++ tests/data/fate/force_key_frames2022-06-04 22:55:25.002760714 +0100 @@ -1,4 +1,3 @@ -07567b9528b8de523faaf49e4e1e0fc

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-05 Thread Luís Cunha dos Reis Infante da Câmara
Test sub2video is taking 9 hours. Stack trace: (gdb) i s #0 0x7fff62bf5974 in clock_gettime () #1 0x7f88bdf30d06 in __GI___clock_gettime (clock_id=clock_id@entry=1, tp=tp@entry=0x7fff62bdeea0) at ../sysdeps/unix/clock_gettime.c:115 #2 0x7f88be7fa8d1 in av_gettime_relative () at src

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-04 Thread Luís Cunha dos Reis Infante da Câmara
The tests did not finish in 24 minutes and one test (sub2video) is taking 15 minutes. I will retest on 18.04 now and publish results tomorrow. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970674 Tit

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-04 Thread Luís Cunha dos Reis Infante da Câmara
The test failed on 18.04 due to an integrity issue when receiving the input file for the failed test. I will re-run the test suite now, but with the following commands (I only added the -k option to the last command): $ debuild -us -uc $ export LD_LIBRARY_PATH="libavcodec:libavdevice:libavfilter

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-04 Thread Luís Cunha dos Reis Infante da Câmara
Patch for typo in architecture name for Ubuntu 21.10 ** Patch added: "architecture_typo_impish.debdiff" https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/1970674/+attachment/5594797/+files/architecture_typo_impish.debdiff -- You received this bug notification because you are a member of

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-03 Thread Luís Cunha dos Reis Infante da Câmara
Running Lintian on the changes file for Ubuntu 22.04 (amd64) reports the following warnings: W: ffmpeg-dbgsym: elf-error In program headers: Unable to find program interpreter name [usr/lib/debug/.build-id/01/31a3a53a5037d9cfce0b08e65bdf645b5fc6a6.debug] W: ffmpeg-dbgsym: elf-error In program he

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-03 Thread Luís Cunha dos Reis Infante da Câmara
Patch for typo in architecture name for Ubuntu 22.04 ** Patch added: "architecture_typo_jammy.debdiff" https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/1970674/+attachment/5594759/+files/architecture_typo_jammy.debdiff -- You received this bug notification because you are a member of Ub

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-03 Thread Luís Cunha dos Reis Infante da Câmara
All tests from the upstream testsuite (FATE) pass on 22.04. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970674 Title: New bug fix releases 3.4.11, 4.2.7 and 4.4.2 To manage notifications about t

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-03 Thread Luís Cunha dos Reis Infante da Câmara
All tests from the upstream testsuite (FATE) pass on 21.10. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970674 Title: New bug fix releases 3.4.11, 4.2.7 and 4.4.2 To manage notifications about t

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-03 Thread Luís Cunha dos Reis Infante da Câmara
For the version in Ubuntu 21.10, Lintian reported a typo in an architecture name and that the upstream tarball is missing a signature. Please add the attached signature when uploading to the Ubuntu 21.10 and 22.04 archives. ** Attachment added: "ffmpeg-4.4.2.tar.xz.asc" https://bugs.launchpad

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-03 Thread Luís Cunha dos Reis Infante da Câmara
For 20.04, I have run the tests as follows (based on the same files as in 18.04, but of course in the source of 20.04): $ debuild -us -uc $ export LD_LIBRARY_PATH="libavcodec:libavdevice:libavfilter:libavformat:libavresample:libavutil:libpostproc:libswresample:libswscale" $ cd debian/standard $ m

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-03 Thread Luís Cunha dos Reis Infante da Câmara
For the version in Ubuntu 20.04, Lintian only reported that the upstream tarball is missing a signature. Please add the attached signature when uploading to the Ubuntu 20.04 archive. ** Attachment added: "ffmpeg-4.2.7.tar.xz.asc" https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/1970674/+

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-03 Thread Luís Cunha dos Reis Infante da Câmara
All tests from the upstream testsuite (FATE) pass on 20.04. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970674 Title: New bug fix releases 3.4.11, 4.2.7 and 4.4.2 To manage notifications about t

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-03 Thread Luís Cunha dos Reis Infante da Câmara
I have run the tests as follows (based on the instructions in doc/fate.texi): $ export LD_LIBRARY_PATH="libavcodec:libavdevice:libavfilter:libavformat:libavresample:libavutil:libpostproc:libswresample:libswscale" $ cd debian/standard $ make -j1 fate-rsync SAMPLES=fate-suite/ $ make -j1 fate SAMPLE

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-03 Thread Luís Cunha dos Reis Infante da Câmara
Test vsynth_lena-amv is failing in 18.04: the expected and actual input file hashes are different. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970674 Title: New bug fix releases 3.4.11, 4.2.7 and

[Bug 1970674] Re: New bug fix releases 3.4.11, 4.2.7 and 4.4.2

2022-06-03 Thread Luís Cunha dos Reis Infante da Câmara
Lintian only reported that the upstream tarball is missing a signature. Please add the attached signature when uploading to the Ubuntu 18.04 archive. ** Attachment added: "ffmpeg-3.4.11.tar.xz.asc" https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/1970674/+attachment/5594576/+files/ffmpeg

[Bug 1971056] Re: CVE-2021-3850

2022-06-02 Thread Luís Cunha dos Reis Infante da Câmara
** Changed in: libphp-adodb (Ubuntu) Status: New => In Progress ** Changed in: libphp-adodb (Ubuntu) Assignee: (unassigned) => Luís Cunha dos Reis Infante da Câmara (luis220413) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscri

[Bug 1971004] Re: CVE-2022-23614

2022-06-02 Thread Luís Cunha dos Reis Infante da Câmara
** Changed in: php-twig (Ubuntu) Status: New => In Progress ** Changed in: twig (Ubuntu) Status: New => In Progress ** Changed in: php-twig (Ubuntu) Assignee: (unassigned) => Luís Cunha dos Reis Infante da Câmara (luis220413) ** Changed in: twig (Ubuntu)

[Bug 1971107] Re: Versions in Focal, Impish and Jammy are vulnerable to CVE-2022-26661 and CVE-2022-26662

2022-06-01 Thread Luís Cunha dos Reis Infante da Câmara
** Changed in: tryton-proteus (Ubuntu) Status: Confirmed => In Progress ** Changed in: tryton-server (Ubuntu) Status: Confirmed => In Progress ** Changed in: tryton-proteus (Ubuntu) Assignee: (unassigned) => Luís Cunha dos Reis Infante da Câmara (luis220413) ** C

[Bug 1970961] Re: Version in Bionic has multiple vulnerabilities

2022-06-01 Thread Luís Cunha dos Reis Infante da Câmara
** Changed in: faad2 (Ubuntu) Status: New => In Progress ** Changed in: faad2 (Ubuntu) Assignee: (unassigned) => Luís Cunha dos Reis Infante da Câmara (luis220413) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-06-01 Thread Luís Cunha dos Reis Infante da Câmara
** CVE removed: https://cve.mitre.org/cgi- bin/cvename.cgi?name=2021-26934 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To m

[Bug 1970783] Re: Multiple vulnerabilities in Bionic

2022-06-01 Thread Luís Cunha dos Reis Infante da Câmara
ged in: webkit2gtk (Ubuntu) Assignee: (unassigned) => Luís Cunha dos Reis Infante da Câmara (luis220413) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970783 Title: Multiple vulnerabilit

[Bug 1971185] Re: Multiple vulnerabilities in Bionic, Focal, Impish and Jammy

2022-05-31 Thread Luís Cunha dos Reis Infante da Câmara
** Patch added: "spip_jammy.debdiff" https://bugs.launchpad.net/ubuntu/+source/spip/+bug/1971185/+attachment/5594136/+files/spip_jammy.debdiff ** Changed in: spip (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bug

[Bug 1971185] Re: Multiple vulnerabilities in Bionic, Focal, Impish and Jammy

2022-05-31 Thread Luís Cunha dos Reis Infante da Câmara
** Patch added: "spip_impish.debdiff" https://bugs.launchpad.net/ubuntu/+source/spip/+bug/1971185/+attachment/5594134/+files/spip_impish.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/197118

[Bug 1971185] Re: Multiple vulnerabilities in Bionic, Focal, Impish and Jammy

2022-05-31 Thread Luís Cunha dos Reis Infante da Câmara
** Patch added: "spip_focal.debdiff" https://bugs.launchpad.net/ubuntu/+source/spip/+bug/1971185/+attachment/5594133/+files/spip_focal.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1971185

[Bug 1971185] Re: Multiple vulnerabilities in Bionic, Focal, Impish and Jammy

2022-05-31 Thread Luís Cunha dos Reis Infante da Câmara
ntu) Assignee: (unassigned) => Luís Cunha dos Reis Infante da Câmara (luis220413) ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-28959 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-28960 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-28961 -

[Bug 1971185] Re: Multiple vulnerabilities in Bionic, Focal, Impish and Jammy

2022-05-31 Thread Luís Cunha dos Reis Infante da Câmara
** Patch added: "spip_bionic.debdiff" https://bugs.launchpad.net/ubuntu/+source/spip/+bug/1971185/+attachment/5594128/+files/spip_bionic.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/197118

[Bug 1970779] Re: Multiple vulnerabilities in Focal, Impish and Jammy

2022-05-31 Thread Luís Cunha dos Reis Infante da Câmara
The upstream project issued a security advisory today: https://wpewebkit.org/security/WSA-2022-0005.html. The changelog in the patched packages was updated just now. These patched packages are currently building in my PPA (https://launchpad.net/~luis220413/+archive/ubuntu/security-updates), as of

[Bug 1970779] Re: Multiple vulnerabilities in Focal and Impish

2022-05-30 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-26700 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-26709 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-26717 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-26716 ** CVE

[Bug 1970779] Re: Multiple vulnerabilities in Focal and Impish

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
Due to a out-of-memory issue when building the package in Jammy, I needed to increase swap and retry the build. I uploaded the Jammy source package just now. Patched source packages are available in my PPA (https://launchpad.net/~luis220413/+archive/ubuntu/security-updates). ** Patch removed: "wp

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-26358 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-26359 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-26360 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-26361 -- You

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-26357 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-26356 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1976184] Re: Linux PV device frontends vulnerable to attacks by backends

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-23042 ** Description changed: The packages listed above are vulnerable to the CVEs below in at least - one Ubuntu release, as stated in the Ubuntu CVE Tracker. + one Ubuntu release, as stated in the Ubuntu CVE Tracker, except for

[Bug 1976184] Re: Linux PV device frontends vulnerable to attacks by backends

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-23041 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1976184 Title: Linux PV device frontends vulnerable to attacks by backends To m

[Bug 1976184] Re: Linux PV device frontends vulnerable to attacks by backends

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** Also affects: linux-azure-4.15 (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-dell300x (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-gcp-4.15 (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-snapdragon (Ubun

[Bug 1976184] Re: Linux PV device frontends vulnerable to attacks by backends

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** Summary changed: - CVE-2022-23036, CVE-2022-23037 and CVE-2022-23038 + Linux PV device frontends vulnerable to attacks by backends ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-23039 ** Description changed: - The following packages are vulnerable to CVE-2022-23036, CVE-20

[Bug 1976184] Re: CVE-2022-23036 and CVE-2022-23037

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** Summary changed: - CVE-2022-23036 + CVE-2022-23036 and CVE-2022-23037 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-23036 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-23037 ** Summary changed: - CVE-2022-23036 and CVE-2022-23037 + CVE-2022-23036, CVE

[Bug 1976184] Re: CVE-2022-23036

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** Also affects: linux-ibm-5.4 (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-kvm (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-oem-5.14 (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-oracle (Ubuntu) Impor

[Bug 1976184] Re: CVE-2022-23036

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** Also affects: linux-aws (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-aws-5.13 (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-aws-5.4 (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-azure (Ubuntu) Import

[Bug 1976184] [NEW] CVE-2022-23036

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
*** This bug is a security vulnerability *** Public security bug reported: The following packages are vulnerable in at least one Ubuntu release, as stated in the Ubuntu CVE Tracker. Please release fixed packages. Xen released a security advisory on March 10. (I was informed by the security tea

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-23035 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-23034 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1976181] [NEW] CVE-2021-28711 and CVE-2021-28712

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
*** This bug is a security vulnerability *** Public security bug reported: The version in Focal is vulnerable to CVE-2021-28711 and CVE-2021-28712. Please release patched versions. Xen released a security advisory on December 20: https://xenbits.xen.org/xsa/advisory-391.html ** Affects: linux-

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28705 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28709 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 T

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-29 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28704 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28707 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28708 -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-28 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-27674 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970779] Re: Multiple vulnerabilities in Focal and Impish

2022-05-28 Thread Luís Cunha dos Reis Infante da Câmara
I am now building version 2.36.3 (released today), with several bug fixes compared to 2.36.1. Source packages will be available in my PPA (https://launchpad.net/~luis220413/+archive/ubuntu/security-updates) tomorrow. ** Changed in: wpewebkit (Ubuntu) Status: Fix Committed => In Progress --

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-28 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-29480 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-28 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28706 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-28 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28701 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-27 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28699 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-27 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28698 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-27 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28697 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-26 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28694 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28695 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28696 -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-26 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28690 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-26 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-0089 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-26313 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Ti

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-24 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28692 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-24 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-28689 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-23 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-27379 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-23 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-26934 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-26933 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 T

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-23 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-29570 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-29571 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 T

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-23 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-29040 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-23 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-29479 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-23 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-28368 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-29486 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 T

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-23 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-29566 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-23 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-27670 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-23 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-27671 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-23 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-27672 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-23 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-25599 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-25601 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 T

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-23 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-25600 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

[Bug 1970507] Re: No security updates since release in all Ubuntu releases

2022-05-23 Thread Luís Cunha dos Reis Infante da Câmara
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-25603 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970507 Title: No security updates since release in all Ubuntu releases To mana

  1   2   3   >