Your message dated Sun, 14 May 2017 21:06:55 +0000
with message-id <e1da0j9-0009jm...@fasolo.debian.org>
and subject line Bug#862571: fixed in pcmanfm 1.2.5-3
has caused the Debian Bug report #862571,
regarding pcmanfm: single instance socket may be blocked by another user.
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
862571: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862571
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: pcmanfm
Version: 1.2.5-2
Version: 1.2.3-1.1
Severity: serious
Tags: upstream security

The socket placed in /tmp is predictable and public-writable. Therefore
if one user placed a symlink to another socket instead of socket for
another user then said another user will either be unable to use pcmanfm,
or may send requests to the first user's pcmanfm. Upstream released a fix
for this issue:

https://git.lxde.org/gitweb/?p=lxde/pcmanfm.git;a=commitdiff;h=bc8c3d871e9ecc67c47ff002b68cf049793faf08

--- End Message ---
--- Begin Message ---
Source: pcmanfm
Source-Version: 1.2.5-3

We believe that the bug you reported is fixed in the latest version of
pcmanfm, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 862...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Andriy Grytsenko <and...@rep.kiev.ua> (supplier of updated pcmanfm package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 14 May 2017 23:29:20 +0300
Source: pcmanfm
Binary: pcmanfm pcmanfm-dbg
Architecture: source amd64
Version: 1.2.5-3
Distribution: unstable
Urgency: medium
Maintainer: Debian LXDE Maintainers 
<pkg-lxde-maintain...@lists.alioth.debian.org>
Changed-By: Andriy Grytsenko <and...@rep.kiev.ua>
Description:
 pcmanfm    - extremely fast and lightweight file manager
 pcmanfm-dbg - extremely fast and lightweight file manager (debug)
Closes: 862571
Changes:
 pcmanfm (1.2.5-3) unstable; urgency=medium
 .
   * Adding 01-Fix-potential-access-violation.patch from upstream
     (Closes: #862571).
Checksums-Sha1:
 ef8731b1e1225a5acbb3402b8c6da6a5024c1092 2062 pcmanfm_1.2.5-3.dsc
 14ede1441b2995dc1fa238a745c2b9e95f87248f 12364 pcmanfm_1.2.5-3.debian.tar.xz
 ca845098ebfb9319492cb687d8bbe9c5a518e98b 310138 pcmanfm-dbg_1.2.5-3_amd64.deb
 aa48935b8aedbf01b205ac47b45c17457ab280ca 10816 pcmanfm_1.2.5-3_amd64.buildinfo
 b360da60c262ed8f3fe433c9d24c9e3912e8235f 281084 pcmanfm_1.2.5-3_amd64.deb
Checksums-Sha256:
 74745aff8cec6abb2e31b26c2f746721be687c53363c5ed4cabab01c52d31857 2062 
pcmanfm_1.2.5-3.dsc
 00ccf74088e7a606ebe85ddf1bda304dd2847e8663ea614ac6aa6acb374b3ef0 12364 
pcmanfm_1.2.5-3.debian.tar.xz
 ee8146fa18db2c34c0fc0c3bac1230f1ec3ce2f5b635c2a26d93fc416ce6da52 310138 
pcmanfm-dbg_1.2.5-3_amd64.deb
 07f0652800bfecc336dcbeb4373e244800e92cbba2ba4608274facf83a4c0796 10816 
pcmanfm_1.2.5-3_amd64.buildinfo
 49996f897a1f47a5cdc2e35acaa5dba422dcbb789b1837a119df0dbb87592d84 281084 
pcmanfm_1.2.5-3_amd64.deb
Files:
 27c4e835b1fae84a8d148c5cf8e7bf13 2062 utils optional pcmanfm_1.2.5-3.dsc
 7213ff7d3e7510487ecb1c3c660ef657 12364 utils optional 
pcmanfm_1.2.5-3.debian.tar.xz
 a587178c777104bd55174ae32b851f05 310138 debug extra 
pcmanfm-dbg_1.2.5-3_amd64.deb
 47e1337053785c7707d0c2bdfe9b388e 10816 utils optional 
pcmanfm_1.2.5-3_amd64.buildinfo
 3dd74a0451c58c95eaafe1a5c77caab0 281084 utils optional 
pcmanfm_1.2.5-3_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAEBCgAGBQJZGL/TAAoJEAV2MC/hidTSApcP/33l4A+hIwroXsl5QZyqKMHN
PtigjZ+UZzUMPDEbjHDDo0XsYu5+6/ms8f+QG3XzCxzV7uFdb5CiCuAdtta+6z6N
LN5GkKyb/u+TfX5JtgA6F382Gnu/DdYLSppyYN5zhAfW5Lgsa8S5YfG7BREI0ePU
fEkvt07M64nWZ4r4d3hT9oNhhJg+lFw766aFXGsVsEQwDhFUB4tuAz38pXQ3SRNP
e4L9EQG6KPL+oDWDyDIFCY7RM+4NOxpaQdcUATsay/VIdRMt0/xTonIYcLAiOiSq
D9FG8dNlEPxqpup0n31X6A3/G4N/5Pbem2N2cWMB2SkrYNPrvy+yMLjumF+uVBmp
LPOa0xp0zXzT1ABPtKnbkXEgmL86qIXdMh0A3+VeOmxLqXK54Aht20MB4jfzCNcC
CIVCwLF0cREB8FIMc9lcR9li8O7tMNXHe65VbBLV/EPjwhDv/b8Av6xi9FC3SLm+
0aNKm5NDo5sKzZKjjCHsHHVrWqOpysxzDzYd0jJng8a1EfMdDgnC5PdQ/iGHuffj
4mFx0Xxz6+/lpBMPyCfmRmOZ0mEt+YPuac6xDEvHrLi444o1BFTRxeZVsPufEi85
lIAGzKTbDyA7b9IdPgdxYG92KIMDXrLcJUap5nU2bo4CnRo/VSKU13TvD5OD9OKw
qA/fQohld1TSeOXWrLCM
=nyXH
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to