*** This bug is a security vulnerability ***

Public security bug reported:
Impact
------
After updating to webkit2gtk 2.40, emails are unreadable in the Evolution app 
on Ubuntu 22.04 LTS "Jammy".

Test Case
--------
sudo apt install evolution
Open the Settings app (gnome-control-center).
Switch to the Online Accounts page and add an Online Account where you have 
email (hosted by Google or Microsoft)
Open the Evolution app.
Wait a few moments for email to be downloaded. Verify that you can read emails.


From Ubuntu 22.04 LTS:
sudo add-apt-repository ppa:jbicha/arch
sudo apt dist-upgrade

Open the Evolution app.
Verify that you can read emails.

What Could Go Wrong
-------------------

Other Info
----------
This issue also affects Ubuntu 20.04 LTS. However, I believe that webkit2gtk 
has reached End of Life for Ubuntu 20.04 LTS now and is unlikely to receive any 
more updates past 2.38.6. If you use an app that uses webkit2gtk, it is 
recommended to upgrade to Ubuntu 22.04 LTS now.

This issue was fixed in evolution 3.46.1 which is available in kinetic-
updates for Ubuntu 22.10. evolution 3.46.1 depends on evolution-data-
server 3.46.1. Before or at the same time that webkit2gtk 2.40 is pushed
to kinetic-security, evolution and evolution-data-server should be
rebuilt and copied to kinetic-security.

Similarly, this issue will be fixed in evolution 3.44.4-0ubuntu2.
evolution and evolution-data-server 3.44.4 will need to be copied to
jammy-security in order for webkit2gtk 2.40 to be pushed to jammy-
security.

The two patches for this fix were pushed to the stable evolution
gnome-42 branch (3.44.x series) in September 2022 and January 2023. The
Evolution developer discontinued official support for Evolution 3.44 in
early August 2022 and will not do any tarball releases after that date.

** Affects: evolution
     Importance: Unknown
         Status: Unknown

** Affects: evolution (Ubuntu)
     Importance: High
         Status: Fix Released

** Affects: evolution (Ubuntu Jammy)
     Importance: Undecided
         Status: Fix Committed

** Affects: evolution (Ubuntu Kinetic)
     Importance: Undecided
     Assignee: Jeremy Bícha (jbicha)
         Status: Triaged


** Tags: jammy

** Also affects: evolution (Ubuntu Kinetic)
   Importance: Undecided
       Status: New

** Also affects: evolution (Ubuntu Jammy)
   Importance: Undecided
       Status: New

** Changed in: evolution (Ubuntu Kinetic)
       Status: New => Triaged

** Changed in: evolution (Ubuntu Kinetic)
     Assignee: (unassigned) => Jeremy Bícha (jbicha)

** Changed in: evolution (Ubuntu Jammy)
       Status: New => Fix Committed

** Bug watch added: gitlab.gnome.org/GNOME/evolution/-/issues #2001
   https://gitlab.gnome.org/GNOME/evolution/-/issues/2001

** Also affects: evolution via
   https://gitlab.gnome.org/GNOME/evolution/-/issues/2001
   Importance: Unknown
       Status: Unknown

-- 
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to evolution in Ubuntu.
https://bugs.launchpad.net/bugs/2021533

Title:
  evolution 3.44: emails are unreadable with webkit2gtk  2.40

To manage notifications about this bug go to:
https://bugs.launchpad.net/evolution/+bug/2021533/+subscriptions


-- 
desktop-bugs mailing list
desktop-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs

Reply via email to