[Bug 403113] Re: Fsniper doesn't safely check file names.

2009-07-24 Thread Jamie Strandboge
For Jaunty it is preferred that you do not add a patch system since it introduces more changes to the package than are necessary. If you insist on adding the patch system, please follow https://wiki.ubuntu.com/UbuntuDevelopment/PatchTaggingGuidelines. As it is now, there is no attribution, originat

[Bug 258172] Re: mktemp-generated filenames insufficiently random when too short

2009-01-23 Thread Jamie Strandboge
This is in Jaunty now: mktemp (1.5-9) unstable; urgency=high * Upstream patch to remove pid from name generation. closes: #495193. ** Changed in: mktemp (Ubuntu) Status: Confirmed => Fix Released -- mktemp-generated filenames insufficiently random when too short https://bugs.launchp

[Bug 320819] Re: package system-tools-backends 2.6.0-1ubuntu1.1 failed to install/upgrade: subprocess post-installation script returned error exit status 1

2009-01-24 Thread Jamie Strandboge
** Visibility changed to: Public ** This bug is no longer flagged as a security issue -- package system-tools-backends 2.6.0-1ubuntu1.1 failed to install/upgrade: subprocess post-installation script returned error exit status 1 https://bugs.launchpad.net/bugs/320819 You received this bug notifi

[Bug 288823] Re: Possible buffer underflow caused by integer overflow in the image conversion routines

2009-01-24 Thread Jamie Strandboge
Thanks Paul. Marking Invalid per upstream bug report. ** Changed in: ffmpeg (Ubuntu) Status: Incomplete => Invalid -- Possible buffer underflow caused by integer overflow in the image conversion routines https://bugs.launchpad.net/bugs/288823 You received this bug notification because y

[Bug 276350] Re: crafted reiserfs filesystem image local DoS (reboot)

2009-01-24 Thread Jamie Strandboge
** Visibility changed to: Public ** Also affects: linux via http://bugzilla.kernel.org/show_bug.cgi?id=12335 Importance: Unknown Status: Unknown -- crafted reiserfs filesystem image local DoS (reboot) https://bugs.launchpad.net/bugs/276350 You received this bug notification because

[Bug 317109] Re: Apparmour doesnt support use of /etc/ssl/

2009-01-24 Thread Jamie Strandboge
abstractions/ssl_keys on Jaunty). What do people think? ** Changed in: openldap2.3 (Ubuntu) Assignee: Jamie Strandboge (jdstrand) => (unassigned) Status: Confirmed => Invalid ** Changed in: apparmor (Ubuntu) Sourcepackagename: openldap => apparmor -- Apparmour doesnt suppo

[Bug 317109] Re: Apparmour doesnt support use of /etc/ssl/

2009-01-24 Thread Jamie Strandboge
I meant to have: /etc/ssl/ r, /etc/ssl/** r, -- Apparmour doesnt support use of /etc/ssl/ https://bugs.launchpad.net/bugs/317109 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.co

[Bug 190587] Re: Local root exploit in kernel 2.6.17 - 2.6.24 (vmsplice)

2009-01-24 Thread Jamie Strandboge
Per Gentoo, it's now fixed in all releases. ** Changed in: gentoo Importance: Unknown => Undecided Bugwatch: Gentoo Bugzilla #209460 => None Status: Confirmed => New ** Changed in: gentoo Status: New => Fix Released -- Local root exploit in kernel 2.6.17 - 2.6.24 (vmsplic

[Bug 284693] Re: zim crashed with SIGSEGV in Perl_av_clear()

2009-01-24 Thread Jamie Strandboge
This is working fine for me on Jaunty now. Marking as Fix Released. If you feel this in in error, please reset the status to New. ** Visibility changed to: Public ** Changed in: zim (Ubuntu) Status: Confirmed => Fix Released -- zim crashed with SIGSEGV in Perl_av_clear() https://bugs.lau

[Bug 292152] Re: nautilus-cd-burner silently fails when directory depth is too large

2009-01-24 Thread Jamie Strandboge
I didn't try, but the message made it clear that it would. The point was that nautilus-cd-burner should have a similar warning. -- nautilus-cd-burner silently fails when directory depth is too large https://bugs.launchpad.net/bugs/292152 You received this bug notification because you are a membe

[Bug 221059] Re: occasional boot hangs after installs with kvm smp

2009-01-24 Thread Jamie Strandboge
Marking as Fix Released since I haven't seen this happen during the Jaunty cycle. ** Changed in: kvm (Ubuntu) Status: New => Fix Released -- occasional boot hangs after installs with kvm smp https://bugs.launchpad.net/bugs/221059 You received this bug notification because you are a member

[Bug 268931] Re: Please backport ufw 0.22 from intrepid

2009-01-24 Thread Jamie Strandboge
Marking the iptables task as "Won't Fix" as it is too intrusive and ufw in Jaunty can run without the newer iptables. ** Changed in: iptables (Ubuntu) Status: Confirmed => Won't Fix ** Summary changed: - Please backport ufw 0.22 from intrepid + Please backport ufw from Jaunty ** Descript

[Bug 268931] Re: Please backport ufw from Jaunty

2009-01-24 Thread Jamie Strandboge
Marking the ufw portion of the bug as Fix Released, and assigning to me, as the changes required for later versions of ufw to run on Hardy have been incorporated in Jaunty. Leaving the Hardy Backports task to Didier. ** Changed in: ufw (Ubuntu) Assignee: Didier Roche (didrocks) => Ja

[Bug 213570] Re: kvm vulnerable to several CVEs

2009-01-24 Thread Jamie Strandboge
** This bug has been flagged as a security issue -- kvm vulnerable to several CVEs https://bugs.launchpad.net/bugs/213570 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://l

Re: [Bug 268502] Re: Bluetooth association no longer works

2009-01-24 Thread Jamie Lokier
e reports similar, they can't connect to ther S-E phone starting from Interpid. -- Jamie -- Bluetooth association no longer works https://bugs.launchpad.net/bugs/268502 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. --

[Bug 321000] Re: dpkg too many errors

2009-01-26 Thread Jamie Strandboge
** This bug is no longer flagged as a security issue ** Visibility changed to: Public -- dpkg too many errors https://bugs.launchpad.net/bugs/321000 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bug

[Bug 321102] Re: Security fixes in tor 0.2.0.32 and .33

2009-01-26 Thread Jamie Strandboge
Jaunty now has 0.2.0.33-1 ** Changed in: tor (Ubuntu) Status: New => Fix Released ** Changed in: tor (Ubuntu Dapper) Status: New => Confirmed ** Changed in: tor (Ubuntu Dapper) Importance: Undecided => High ** Changed in: tor (Ubuntu Gutsy) Status: New => Confirmed ** C

[Bug 321102] Re: Security fixes in tor 0.2.0.32 and .33

2009-01-26 Thread Jamie Strandboge
Thank you for using Ubuntu and taking the time to report a bug. This package is in universe and is community supported. If you are able, perhaps you could prepare debdiffs to fix this by following https://wiki.ubuntu.com/SecurityUpdateProcedures. -- Security fixes in tor 0.2.0.32 and .33 https:/

[Bug 320648] Re: package cpuburn 1.4-34 failed to install/upgrade: il sottoprocesso post-installation script ? stato terminato dal segnale (Segmentation fault)

2009-01-26 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 299048] Re: Pidgin nickname html insertion

2009-01-26 Thread Jamie Strandboge
** Bug watch added: Pidgin Trac #8252 http://developer.pidgin.im/ticket/8252 ** Also affects: pidgin via http://developer.pidgin.im/ticket/8252 Importance: Unknown Status: Unknown -- Pidgin nickname html insertion https://bugs.launchpad.net/bugs/299048 You received this bug notif

[Bug 321314] Re: upgrade to linux-image-2.6.27-7-generic in terminal fails

2009-01-26 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 315111] Re: netdiscover segfaults when looking up vendors

2009-01-26 Thread Jamie Strandboge
ignee: (unassigned) => Jamie Strandboge (jdstrand) Status: New => Incomplete -- netdiscover segfaults when looking up vendors https://bugs.launchpad.net/bugs/315111 You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. -- ubuntu-bugs m

[Bug 315111] Re: netdiscover segfaults when looking up vendors

2009-01-26 Thread Jamie Strandboge
Oh, I didn't look far enough. While sprintf doesn't write too much, and the for loop doesn't access beyond the end, tmac isn't null-terminated, which could cause strcmp to fail (it expects null terminated strings). -- netdiscover segfaults when looking up vendors https://bugs.launchpad.net/bugs/3

[Bug 317923] Re: Clamav modules still disabled even though security issues are fixed

2009-01-26 Thread Jamie Strandboge
clamav (0.92.1~dfsg2-1.1~dapper3.3) dapper-security; urgency=low [ Leonel Nunez ] * SECURITY UPDATE: * [CVE-2008-5314]: remote attack by sending a specially crafted JPEG file libclamav/special.c, libclamav/special.h, libclamav/scanners.c * [CVE-2008-3912]: libclamav/mbox.c, libclam

[Bug 317923] Re: Clamav modules still disabled even though security issues are fixed

2009-01-26 Thread Jamie Strandboge
All of these issues are fixed in Intrepid and higher. ** Changed in: clamav (Ubuntu) Status: Triaged => Fix Released -- Clamav modules still disabled even though security issues are fixed https://bugs.launchpad.net/bugs/317923 You received this bug notification because you are a member of

[Bug 319314] Re: Local privilege escalation when the user uses gksudo

2009-01-26 Thread Jamie Strandboge
*** This bug is a duplicate of bug 18905 *** https://bugs.launchpad.net/bugs/18905 ** Visibility changed to: Public ** This bug has been marked a duplicate of bug 18905 gksudo should notify users that the password is being remembered and used -- Local privilege escalation when the user u

[Bug 319367] Re: security vulnerability in sun java packages

2009-01-26 Thread Jamie Strandboge
** Visibility changed to: Public -- security vulnerability in sun java packages https://bugs.launchpad.net/bugs/319367 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://list

[Bug 319367] Re: security vulnerability in sun java packages

2009-01-26 Thread Jamie Strandboge
Jaunty already has sun-java5 1.5.0-17-0ubuntu1 and sun-java6 6-11-0ubuntu1. ** Changed in: sun-java5 (Ubuntu Dapper) Status: New => Confirmed ** Changed in: sun-java5 (Ubuntu Gutsy) Status: New => Confirmed ** Changed in: sun-java5 (Ubuntu Hardy) Status: New => Confirmed **

[Bug 319468] Re: crash from an assertion failure

2009-01-26 Thread Jamie Strandboge
Jaunty has 2.8.1.dfsg-0ubuntu2 ** Visibility changed to: Public ** Changed in: dkim-milter (Ubuntu) Status: Confirmed => In Progress ** Changed in: dkim-milter (Ubuntu Jaunty) Status: In Progress => Invalid ** Changed in: dkim-milter (Ubuntu Intrepid) Status: New => In Prog

[Bug 317892] Re: Quassel main inclusion report

2009-01-26 Thread Jamie Strandboge
** Changed in: quassel (Ubuntu) Assignee: Ubuntu Security Team (ubuntu-security) => Kees Cook (kees) Status: Incomplete => In Progress -- Quassel main inclusion report https://bugs.launchpad.net/bugs/317892 You received this bug notification because you are a member of Ubuntu Bugs, wh

[Bug 319875] Re: package sun-java5-doc 1.5.0-16-3 failed to install/upgrade: subprocess post-installation script returned error exit status 1

2009-01-26 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 321549] Re: secrecy

2009-01-26 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 200897] Re: [moin] [DSA-1514-1] multiple vulnerabilities

2009-01-27 Thread Jamie Strandboge
2007-2423 was fixed in 1.5.7-3 (Dapper and Gutsy also have the fix) 2007-2637 was fixed in 1.5.7-2 and 1.5.8 upstream. While not clear from the changelog, Dapper and Gutsy also have this commit http://hg.moinmo.in/moin/1.5/rev/0e41a0429ee1 (this CVE may have been split after publication) 2008-0

[Bug 200897] Re: [moin] [DSA-1514-1] multiple vulnerabilities

2009-01-27 Thread Jamie Strandboge
** Changed in: moin (Ubuntu Dapper) Status: Confirmed => Fix Committed ** Changed in: moin (Ubuntu Dapper) Assignee: (unassigned) => Jamie Strandboge (jdstrand) ** Changed in: moin (Ubuntu Gutsy) Status: Confirmed => Fix Committed ** Changed in: moin (Ubu

[Bug 322532] Re: ecryptfs does not handle symlinks within bzr

2009-01-28 Thread Jamie Strandboge
** Attachment added: "bzr_links.tar.gz" http://launchpadlibrarian.net/21748467/bzr_links.tar.gz -- ecryptfs does not handle symlinks within bzr https://bugs.launchpad.net/bugs/322532 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. --

[Bug 322532] [NEW] ecryptfs does not handle symlinks within bzr

2009-01-28 Thread Jamie Strandboge
/ bzr_links/.bzr/ bzr_links/.bzr/repository/ ... bzr_links/bar bzr_links/foo $ cd bzr_links/ $ bzr status modified: bar@ $ bzr diff bzr: ERROR: The dirstate file (DirState(u'/home/jamie/Private/tmp/bzr_links/.bzr/checkout/dirstate')) appears to be corrupt: Bad parse, we expected to end on \

[Bug 319367] Re: security vulnerability in sun java packages

2009-01-29 Thread Jamie Strandboge
Thank you for using Ubuntu and taking the time to report a bug. This package is in multiverse and is community supported. If you are able, perhaps you could prepare new source packages to fix this by following https://wiki.ubuntu.com/SecurityUpdateProcedures. -- security vulnerability in sun jav

[Bug 200897] Re: [moin] [DSA-1514-1] multiple vulnerabilities

2009-01-29 Thread Jamie Strandboge
http://www.ubuntu.com/usn/usn-716-1 ** Changed in: moin (Ubuntu Dapper) Status: Fix Committed => Fix Released -- [moin] [DSA-1514-1] multiple vulnerabilities https://bugs.launchpad.net/bugs/200897 You received this bug notification because you are a member of Ubuntu Bugs, which is subscri

[Bug 314915] Re: gnutls fails to use Verisign CA cert without a Basic Constraint

2009-01-30 Thread Jamie Strandboge
*** This bug is a duplicate of bug 305264 *** https://bugs.launchpad.net/bugs/305264 Thank you for taking the time to report this bug and helping to make Ubuntu better. This particular bug has already been reported and appears to be a duplicate of bug 305264, so it is being marked as such. Ple

[Bug 305264] Re: gnutls regression: failure in certificate chain validation

2009-01-30 Thread Jamie Strandboge
Commenting per request in #ubuntu-meeting. It is a really unfortunate situation that these certificates unintentionally passed verification before the updates. IMO, the security fix (that is also in other distributions now) is needed and should not be backed out. Without it, man-in-the middle atta

[Bug 267555] Re: Main Inclusion Report for dirmngr

2009-01-30 Thread Jamie Strandboge
Sorry this slipped. We have updated our request for audit procedures (https://wiki.ubuntu.com/SecurityTeam/Auditing and https://wiki.ubuntu.com/MainInclusionProcess) so this shouldn't happen in the future. ** Changed in: dirmngr (Ubuntu) Assignee: (unassigned) => Ubuntu Security Team (ubuntu-

[Bug 322834] Re: [regression] xine will not play certain mpeg video files

2009-01-30 Thread Jamie Strandboge
This does not appear to work on Jaunty (1.1.16.1-2ubuntu1) either, but plays in totem. -- [regression] xine will not play certain mpeg video files https://bugs.launchpad.net/bugs/322834 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. --

[Bug 322108] Re: package screenlets 0.1.2-3ubuntu1 failed to install/upgrade: subprocess post-installation script returned error exit status 1

2009-01-30 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2009-01-30 Thread Jamie Strandboge
** Changed in: csound (Ubuntu) Status: New => Confirmed ** Changed in: csound (Ubuntu) Importance: Undecided => Low ** Changed in: dia (Ubuntu) Status: New => Confirmed ** Changed in: dia (Ubuntu) Importance: Undecided => Low ** Changed in: eog (Ubuntu) Status: New =>

[Bug 322196] Re: Untrusted search path vulnerability in Python and multiple other programs

2009-01-30 Thread Jamie Strandboge
** Changed in: epiphany (Ubuntu) Status: New => Invalid ** Also affects: epiphany-browser (Ubuntu) Importance: Undecided Status: New ** Also affects: python2.3 (Ubuntu) Importance: Undecided Status: New ** Changed in: epiphany-browser (Ubuntu) Status: New => Con

[Bug 322999] Re: package linux-image-2.6.27-11-generic 2.6.27-11.25 failed to install/upgrade: fallito in buffer_write(fd) (10, ret=-1): dpkg-deb backend su `./lib/modules/2.6.27-11-generic/kernel/ubu

2009-01-30 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 323006] Re: cant play mp3's, or videos in ubuntu 8.10 64 bit!

2009-01-30 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 322875] Re: Kernel crashes after plugging in a USB stick

2009-01-30 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 323314] Re: package bnetd 0.4.25-7 failed to install/upgrade:

2009-01-30 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 323185] Re: I can not hear any voice from speakers in UBUNTU's media player i.e. Rhythmbox music player. Also in movie player.(movie runs but no sound)

2009-01-30 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 213570] Re: kvm vulnerable to several CVEs

2009-01-30 Thread Jamie Strandboge
** Changed in: kvm (Ubuntu Gutsy) Status: New => Confirmed ** Changed in: qemu (Ubuntu Dapper) Status: New => Confirmed ** Changed in: qemu (Ubuntu Gutsy) Status: New => Confirmed -- kvm vulnerable to several CVEs https://bugs.launchpad.net/bugs/213570 You received this bug

[Bug 59647] Re: Firewall not persistent

2009-01-30 Thread Jamie Strandboge
** Changed in: firestarter (Ubuntu) Status: New => Confirmed -- Firewall not persistent https://bugs.launchpad.net/bugs/59647 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.co

[Bug 252579] Re: Hardening Wordpress

2009-01-30 Thread Jamie Strandboge
** Changed in: wordpress (Ubuntu) Status: New => Confirmed ** Changed in: wordpress (Ubuntu) Importance: Undecided => Wishlist -- Hardening Wordpress https://bugs.launchpad.net/bugs/252579 You received this bug notification because you are a member of Ubuntu Bugs, which is a direct sub

[Bug 213570] Re: kvm vulnerable to several CVEs

2009-01-30 Thread Jamie Strandboge
** Changed in: qemu (Ubuntu) Status: New => Fix Released -- kvm vulnerable to several CVEs https://bugs.launchpad.net/bugs/213570 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubunt

[Bug 257949] Re: [CVE-2008-2420] stunnel incorrect OCSP validation vulnerability

2009-01-30 Thread Jamie Strandboge
** Changed in: stunnel4 (Ubuntu) Status: New => Fix Released ** Changed in: stunnel4 (Ubuntu Hardy) Status: New => Confirmed -- [CVE-2008-2420] stunnel incorrect OCSP validation vulnerability https://bugs.launchpad.net/bugs/257949 You received this bug notification because you are

[Bug 256771] Re: OpenSC initializes CardOS cards with improper access rights

2009-01-30 Thread Jamie Strandboge
** Changed in: opensc (Ubuntu Jaunty) Status: New => Fix Released ** Changed in: opensc (Ubuntu Intrepid) Status: New => Fix Released ** Changed in: opensc (Ubuntu Dapper) Status: New => Confirmed ** Changed in: opensc (Ubuntu Gutsy) Status: New => Confirmed ** Chang

[Bug 256621] Re: [CVE-2008-3459] OpenVPN vulnerability allows arbitrary command execution via crafted configuration

2009-01-30 Thread Jamie Strandboge
** Changed in: openvpn (Ubuntu) Status: New => Fix Released ** Changed in: openvpn (Ubuntu Hardy) Status: New => Confirmed ** Changed in: openvpn (Ubuntu Hardy) Importance: Undecided => Low -- [CVE-2008-3459] OpenVPN vulnerability allows arbitrary command execution via crafted

[Bug 259674] Re: OpenSC initializes CardOS cards with improper access rights (CVE-2008-2235)

2009-01-30 Thread Jamie Strandboge
** Changed in: opensc (Ubuntu Jaunty) Status: New => Fix Released ** Changed in: opensc (Ubuntu Dapper) Status: New => Confirmed ** Changed in: opensc (Ubuntu Gutsy) Status: New => Confirmed ** Changed in: opensc (Ubuntu Hardy) Status: New => Confirmed ** Changed in:

[Bug 263614] Re: makejail must use ldconfig.real by default

2009-01-30 Thread Jamie Strandboge
** Changed in: makejail (Ubuntu) Status: New => Confirmed -- makejail must use ldconfig.real by default https://bugs.launchpad.net/bugs/263614 You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. -- ubuntu-bugs mailing list ubuntu-bugs

[Bug 261395] Re: [gutsy] Last security Update does render system unusable

2009-01-30 Thread Jamie Strandboge
** This bug is no longer flagged as a security issue -- [gutsy] Last security Update does render system unusable https://bugs.launchpad.net/bugs/261395 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-b

[Bug 272889] Re: consider syncing movabletype-opensource from Debian

2009-01-30 Thread Jamie Strandboge
** Changed in: movabletype-opensource (Ubuntu Intrepid) Status: New => Confirmed ** Changed in: movabletype-opensource (Ubuntu Intrepid) Importance: Undecided => Low ** Changed in: movabletype-opensource (Ubuntu Jaunty) Status: New => Fix Released ** Changed in: movabletype-open

[Bug 274514] Re: CVE-2008-3949: python execution from current directory

2009-01-30 Thread Jamie Strandboge
** Changed in: emacs22 (Ubuntu) Status: New => Confirmed ** Changed in: emacs22 (Ubuntu) Importance: Undecided => Low -- CVE-2008-3949: python execution from current directory https://bugs.launchpad.net/bugs/274514 You received this bug notification because you are a member of Ubuntu B

[Bug 272242] Re: Format string vulnerability in kerneloops 0.12

2009-01-30 Thread Jamie Strandboge
Marking as Fix Released. It is fixed upstream and Ubuntu and Debian still have 0.10 (so when we do get 0.12 or higher, we won't be affected). ** Changed in: kerneloops (Ubuntu) Status: New => Fix Released -- Format string vulnerability in kerneloops 0.12 https://bugs.launchpad.net/bugs/27

[Bug 271820] Re: gksu does not warn about programs not in root's $PATH

2009-01-30 Thread Jamie Strandboge
** Changed in: gksu (Ubuntu) Status: New => Confirmed ** Changed in: gksu (Ubuntu) Importance: Undecided => Wishlist -- gksu does not warn about programs not in root's $PATH https://bugs.launchpad.net/bugs/271820 You received this bug notification because you are a member of Ubuntu Bug

[Bug 269081] Re: nat routes internal ip's over extrenal networks lan ips over wan networks

2009-01-30 Thread Jamie Strandboge
** This bug is no longer flagged as a security issue -- nat routes internal ip's over extrenal networks lan ips over wan networks https://bugs.launchpad.net/bugs/269081 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mail

[Bug 278674] Re: Ubuntu changes WPA2-password by itself

2009-01-30 Thread Jamie Strandboge
** This bug is no longer flagged as a security issue -- Ubuntu changes WPA2-password by itself https://bugs.launchpad.net/bugs/278674 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.c

[Bug 276951] Re: jokosher crashed asked if I would like to restart, and restarted as root

2009-01-30 Thread Jamie Strandboge
Thank you for taking the time to report this bug and helping to make Ubuntu better. Are you able to reproduce this on up to date Ubuntu 8.10? ** Changed in: jokosher (Ubuntu) Assignee: (unassigned) => Jamie Strandboge (jdstrand) Status: New => Incomplete -- jokosher crashed as

[Bug 275121] Re: shorewall generating garbled syslog entries

2009-01-30 Thread Jamie Strandboge
** This bug is no longer flagged as a security issue -- shorewall generating garbled syslog entries https://bugs.launchpad.net/bugs/275121 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.u

[Bug 282590] Re: defective log entries from pads in /var/log/messages

2009-01-30 Thread Jamie Strandboge
Unflagging as a security vulnerability. It seems more like a missing newline and the referenced bugs don't seem related. Please re-mark as security if there is evidence of attacker controlled memory corruption. ** This bug is no longer flagged as a security issue -- defective log entries from pa

[Bug 287939] Re: Ubuntu crash just after boot

2009-01-30 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 286851] Re: CVE-2008-3658,2008-3659,2008-3660

2009-01-30 Thread Jamie Strandboge
** Changed in: php5 (Ubuntu) Status: New => Confirmed ** Changed in: php5 (Ubuntu Hardy) Status: New => Confirmed -- CVE-2008-3658,2008-3659,2008-3660 https://bugs.launchpad.net/bugs/286851 You received this bug notification because you are a member of Ubuntu Bugs, which is a direc

[Bug 280893] Re: ‘Clickjacking’ issue

2009-01-30 Thread Jamie Strandboge
** Changed in: flashplugin-nonfree (Ubuntu Dapper) Status: New => Confirmed ** Changed in: flashplugin-nonfree (Ubuntu) Status: New => Fix Released -- ‘Clickjacking’ issue https://bugs.launchpad.net/bugs/280893 You received this bug notification because you are a member of Ubuntu B

[Bug 285922] Re: vlc: buffer overflow in TY demux

2009-01-30 Thread Jamie Strandboge
** Changed in: vlc (Ubuntu) Status: New => Confirmed -- vlc: buffer overflow in TY demux https://bugs.launchpad.net/bugs/285922 You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.c

[Bug 279490] Re: new lighttpd security fixes

2009-01-30 Thread Jamie Strandboge
*** This bug is a duplicate of bug 209627 *** https://bugs.launchpad.net/bugs/209627 ** This bug has been marked a duplicate of bug 209627 lighttpd (security) ssl fix -- new lighttpd security fixes https://bugs.launchpad.net/bugs/279490 You received this bug notification because you are a

[Bug 283327] Re: Intrepid Beta missing CUPS service in Gnome Services Administration Tool

2009-01-30 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 277907] Re: New upstream release 1.4.20 fixes security issues

2009-01-30 Thread Jamie Strandboge
*** This bug is a duplicate of bug 209627 *** https://bugs.launchpad.net/bugs/209627 ** This bug is no longer a duplicate of bug 279490 new lighttpd security fixes ** This bug has been marked a duplicate of bug 209627 lighttpd (security) ssl fix -- New upstream release 1.4.20 fixes se

[Bug 280053] Re: xinetd enabled is not overruled by disable in service declaration

2009-01-30 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 290507] Re: Firefox Should Not Prompt for Password Save in Guest Session

2009-01-30 Thread Jamie Strandboge
** Changed in: gdm-guest-session (Ubuntu) Status: New => Confirmed -- Firefox Should Not Prompt for Password Save in Guest Session https://bugs.launchpad.net/bugs/290507 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-b

[Bug 289983] Re: tcptrace is vulnerable against some of the fragrouter attacks

2009-01-30 Thread Jamie Strandboge
** This bug is no longer flagged as a security issue -- tcptrace is vulnerable against some of the fragrouter attacks https://bugs.launchpad.net/bugs/289983 You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. -- ubuntu-bugs mailing list ubu

[Bug 288011] Re: dns resolver does not support dnssec

2009-01-30 Thread Jamie Strandboge
** Changed in: glibc (Ubuntu) Status: New => Confirmed ** Changed in: glibc (Ubuntu) Importance: Undecided => Wishlist -- dns resolver does not support dnssec https://bugs.launchpad.net/bugs/288011 You received this bug notification because you are a member of Ubuntu Bugs, which is sub

[Bug 287992]

2009-01-30 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 287992]

2009-01-30 Thread Jamie Strandboge
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 293003] Re: CVE-2007-3215: remote shell command execution in class.phpmailer.php

2009-01-30 Thread Jamie Strandboge
Francois, can you submit a debdiff and mark the bug In Progress? Thanks! ** Changed in: mahara (Ubuntu) Status: New => Confirmed ** Changed in: mahara (Ubuntu) Status: Confirmed => Triaged -- CVE-2007-3215: remote shell command execution in class.phpmailer.php https://bugs.launchp

[Bug 292923] Re: CVE-2008-4796: missing input sanitising

2009-01-30 Thread Jamie Strandboge
** Changed in: libphp-snoopy (Ubuntu) Status: New => Confirmed -- CVE-2008-4796: missing input sanitising https://bugs.launchpad.net/bugs/292923 You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. -- ubuntu-bugs mailing list ubuntu-bu

[Bug 291008] Re: The init-script for NetworkManager can be run by non-root

2009-01-30 Thread Jamie Strandboge
** This bug is no longer flagged as a security issue -- The init-script for NetworkManager can be run by non-root https://bugs.launchpad.net/bugs/291008 You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. -- ubuntu-bugs mailing list ubuntu-b

[Bug 293004] Re: CVE-2008-4796: missing input sanitising in Snoopy.class.php

2009-01-30 Thread Jamie Strandboge
Francois, can you submit a debdiff and mark the bug In Progress (combined with the fix for bug #293003)? Thanks! ** Changed in: mahara (Ubuntu) Status: New => Triaged -- CVE-2008-4796: missing input sanitising in Snoopy.class.php https://bugs.launchpad.net/bugs/293004 You received this bu

Re: [Bug 268502] Re: Bluetooth association no longer works

2009-02-03 Thread Jamie Lokier
hyperair wrote: > You kidding? Bluetooth works perfectly for me on Intrepid, so please > don't talk as though the entire Ubuntu community is affected. Either > way, can someone who is affected open up a Jaunty installation (or > LiveCD) and see if the issue is fixed over there? It does not work fo

Re: [Bug 268502] Re: Bluetooth doesn't work (hci_cmd_task: hci0 command tx timeout)

2009-02-21 Thread Jamie Lokier
04 Device 004: ID 0a12:0001 Cambridge Silicon Radio, Ltd Bluetooth Dongle (HCI mode) But then I've said my bug may be a different one. -- Jamie -- Bluetooth doesn't work (hci_cmd_task: hci0 command tx timeout) https://bugs.launchpad.net/bugs/268502 You received this bug notific

[Bug 332560] Re: [9.04] Alt+F2 not working anymore

2009-02-23 Thread Jamie Strandboge
*** This bug is a duplicate of bug 331556 *** https://bugs.launchpad.net/bugs/331556 Turns out this was bug #331556 for me. I enabled 'Gnome Compatibility' in compiz config settings manager and it started working again. -- [9.04] Alt+F2 not working anymore https://bugs.launchpad.net/bugs/332

[Bug 332069] Re: code execution when following links

2009-02-23 Thread Jamie Strandboge
** Changed in: kdepim (Ubuntu Dapper) Status: New => In Progress ** Changed in: kdepim (Ubuntu Dapper) Assignee: (unassigned) => Jamie Strandboge (jdstrand) ** Changed in: kdepim (Ubuntu Gutsy) Status: New => In Progress ** Changed in: kdepim (Ubuntu Gutsy)

[Bug 332521] Re: [jaunty] no internet connection: dhclient-script cannot be execve'd

2009-02-23 Thread Jamie Strandboge
unassigned) => Jamie Strandboge (jdstrand) Status: New => Incomplete -- [jaunty] no internet connection: dhclient-script cannot be execve'd https://bugs.launchpad.net/bugs/332521 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubu

[Bug 332069] Re: code execution when following links

2009-02-23 Thread Jamie Strandboge
** Changed in: kdepim (Ubuntu Dapper) Status: In Progress => Fix Committed ** Changed in: kdepim (Ubuntu Gutsy) Status: In Progress => Fix Committed ** Changed in: kdepim (Ubuntu Hardy) Status: In Progress => Fix Committed ** Changed in: kdepim (Ubuntu Intrepid) Statu

[Bug 316550] Re: [CVE-2008-5619] [CVE-2008-5620] - Roundcube vulnerable and actively exploited

2009-02-23 Thread Jamie Strandboge
Andrew, thanks for yours patches. I just reviewed them and the patch for CVE-2008-5619 is extremely invasive and does not seem to go along with Debian's changes as you mentioned in the changelog. Can you look at Debian's 0.1.1-10, redo the patch and resubmit? Also, please reference this bug number

[Bug 292923] Re: CVE-2008-4796: missing input sanitising

2009-02-23 Thread Jamie Strandboge
** Changed in: libphp-snoopy (Ubuntu Hardy) Status: New => Confirmed -- CVE-2008-4796: missing input sanitising https://bugs.launchpad.net/bugs/292923 You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. -- ubuntu-bugs mailing list ubu

[Bug 292923] Re: CVE-2008-4796: missing input sanitising

2009-02-23 Thread Jamie Strandboge
Vincenzo, thank you for your work on this, however I cannot process your patch for Intrepid, because we do not do full version upgrades for security patches in Ubuntu. Instead, we backport fixes to the version in the release version of Ubuntu. Perhaps you could prepare debdiffs to fix this by follo

[Bug 268502] Re: Bluetooth doesn't work (hci_cmd_task: hci0 command tx timeout)

2009-02-23 Thread Jamie Lokier
Thanks for trying, NagPer. Yes, there's a small hunk missing from my "diff" - in include/net/bluetooth/rfcomm.h. Here's a new one, called make_2.6.24_bluetooth_work_in_2.6.28.diff. You still apply it after copying over the bluetooth tree from 2.6.24 over 2.6.28, as per the instructions. **

[Bug 268502] Re: Bluetooth doesn't work (hci_cmd_task: hci0 command tx timeout)

2009-02-23 Thread Jamie Lokier
Here's an alternative patch which might be easier for some people to try. Just apply this one to a linux-source-2.6.28-7 tree. It's exactly the same as the previous small patch, but you don't have fetch a 2.6.24 tree yourself and copy bits over. There's no point trying both patches, they're the s

[Bug 333711] Re: AppArmor profile for sbin.dhclient3 should handle connman

2009-02-24 Thread Jamie Strandboge
) Assignee: (unassigned) => Jamie Strandboge (jdstrand) Status: New => In Progress -- AppArmor profile for sbin.dhclient3 should handle connman https://bugs.launchpad.net/bugs/333711 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed t

[Bug 333711] Re: AppArmor profile for sbin.dhclient3 should handle connman

2009-02-24 Thread Jamie Strandboge
Marking connman task as "Won't Fix" for the above stated reasons. ** Changed in: connman (Ubuntu) Status: New => Won't Fix -- AppArmor profile for sbin.dhclient3 should handle connman https://bugs.launchpad.net/bugs/333711 You received this bug notification because you are a member of Ubu

[Bug 39602] Re: amd76xrom amd76xrom_init_one(): Unable to register resource 0xffc00000-0xffffffff - kernel bug?

2009-02-24 Thread Jamie Strandboge
** Attachment added: "lspci-vvnn.txt" http://launchpadlibrarian.net/23055606/lspci-vvnn.txt -- amd76xrom amd76xrom_init_one(): Unable to register resource 0xffc0-0x - kernel bug? https://bugs.launchpad.net/bugs/39602 You received this bug notification because you are a member of

<    3   4   5   6   7   8   9   10   11   12   >