[Bug 1748247] Re: [CVE] Arbitrary command execution in the removable device notifier

2018-03-21 Thread Launchpad Bug Tracker
This bug was fixed in the package plasma-workspace - 4:5.5.5.2-0ubuntu1.1 --- plasma-workspace (4:5.5.5.2-0ubuntu1.1) xenial-security; urgency=medium * SECURITY UPDATE: Arbitrary command execution in the removable device notifier (LP: #1748247): - fix-CVE-2018-6791.patch

[Bug 1748247] Re: [CVE] Arbitrary command execution in the removable device notifier

2018-03-21 Thread Launchpad Bug Tracker
This bug was fixed in the package plasma-workspace - 4:5.10.5-0ubuntu1.1 --- plasma-workspace (4:5.10.5-0ubuntu1.1) artful-security; urgency=high * SECURITY UPDATE: Arbitrary command execution in the removable device notifier (LP: #1748247): - fix-CVE-2018-6791.patch -

[Bug 1748247] Re: [CVE] Arbitrary command execution in the removable device notifier

2018-03-16 Thread Simon Quigley
I have uploaded these fixes (for Artful and Xenial) to a fresh, empty test PPA of mine with all architectures enabled and only the security repo enabled. I then tested both in VMs of each release, and they work as intended. It also fixes the security issue. Security Team, feel free to copy my

[Bug 1748247] Re: [CVE] Arbitrary command execution in the removable device notifier

2018-03-16 Thread Simon Quigley
So it looks like Backports already has the fixes. ** Changed in: kubuntu-ppa/artful Status: New => Fix Released ** Changed in: kubuntu-ppa/xenial Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 1748247] Re: [CVE] Arbitrary command execution in the removable device notifier

2018-03-16 Thread Simon Quigley
These fixes should be looked into for Backports too. ** Also affects: kubuntu-ppa Importance: Undecided Status: New ** Also affects: kubuntu-ppa/artful Importance: Undecided Status: New ** Also affects: kubuntu-ppa/xenial Importance: Undecided Status: New **

[Bug 1748247] Re: [CVE] Arbitrary command execution in the removable device notifier

2018-03-16 Thread Simon Quigley
There isn't even a plasma-workspace on Trusty... ** No longer affects: plasma-workspace (Ubuntu Trusty) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1748247 Title: [CVE] Arbitrary command

[Bug 1748247] Re: [CVE] Arbitrary command execution in the removable device notifier

2018-03-16 Thread Simon Quigley
I remember having a discussion with the security team and forgot to update this bug... CVE-2018-6790 isn't worth patching because it's a low priority CVE with an intrusive patch. So I consider that Won't Fix. ** Description changed: KDE Project Security Advisory

[Bug 1748247] Re: [CVE] Arbitrary command execution in the removable device notifier

2018-02-20 Thread Simon Quigley
Debian says kde-runtime isn't affected, and I can confirm. ** Changed in: kde-runtime (Ubuntu Trusty) Status: In Progress => Invalid ** Changed in: kde-runtime (Ubuntu Xenial) Status: In Progress => Invalid ** No longer affects: kde-runtime (Ubuntu) ** No longer affects:

[Bug 1748247] Re: [CVE] Arbitrary command execution in the removable device notifier

2018-02-08 Thread Rik Mills
No information in the referenced CVE to say how or if it affects kde- runtime. ** Changed in: kde-runtime (Ubuntu Bionic) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1748247] Re: [CVE] Arbitrary command execution in the removable device notifier

2018-02-08 Thread Rik Mills
** Changed in: plasma-workspace (Ubuntu Bionic) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1748247 Title: [CVE] Arbitrary command execution in the removable

[Bug 1748247] Re: [CVE] Arbitrary command execution in the removable device notifier

2018-02-08 Thread Simon Quigley
I'm assigning the Bionic fixes to Rik; I'm unsure if plasma-workspace is still affected, but it seems kde-runtime is in fact affected. ** Changed in: plasma-workspace (Ubuntu Bionic) Importance: Undecided => High ** Changed in: plasma-workspace (Ubuntu Bionic) Assignee: (unassigned) =>

[Bug 1748247] Re: [CVE] Arbitrary command execution in the removable device notifier

2018-02-08 Thread Simon Quigley
CVE-2018-6790 CVE-2018-6791 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1748247 Title: [CVE] Arbitrary command execution in the removable device notifier To manage notifications about this bug