[Bug 2104279] Re: rhythmbox crashed with SIGSEGV in rb_ext_db_cancel_requests()

2025-05-08 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to rhythmbox in Ubuntu. https://bugs.launchpad.net/bugs/2104279 Title: rhythmbox crashed with SIGSEGV in rb_ext_db_cancel_reque

[Bug 2106404] Re: poppler April 2025 security fixes

2025-04-07 Thread Marc Deslauriers
Thanks Jeremy, I'll handle the stable releases. -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to poppler in Ubuntu. https://bugs.launchpad.net/bugs/2106404 Title: poppler April 2025 security fixes To manage notifications about this

[Bug 1976478] Re: Telegram Desktop steals input on Lock screen (Xorg session)

2025-02-14 Thread Marc Deslauriers
** Changed in: gnome-shell (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/1976478 Title: Telegram Desktop steals input on Lock screen (Xo

[Bug 2060613] Re: Gedit sometimes crashes by segmentation fault at closure

2025-01-14 Thread Marc Deslauriers
I believe this is caused by the snippets plugin. When I disable it, I no longer get a crash on exit. Unfortunately, it looks like the snippets plugin was removed in later versions. -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gedit

[Bug 2089680] Re: Insufficient fix for CVE-2024-10573

2024-11-26 Thread Marc Deslauriers
This only affected Focal, the later releases include the second commit already. ** Changed in: mpg123 (Ubuntu Jammy) Status: New => Fix Released ** Changed in: mpg123 (Ubuntu Noble) Status: New => Fix Released ** Changed in: mpg123 (Ubuntu Oracular) Status: New => Fix Releas

[Bug 2089680] [NEW] Insufficient fix for CVE-2024-10573

2024-11-26 Thread Marc Deslauriers
*** This bug is a security vulnerability *** Public security bug reported: The fix for CVE-2024-10573 is insufficient in certain releases, pending investigation. This is the tracking bug. ** Affects: mpg123 (Ubuntu) Importance: Undecided Assignee: Marc Deslauriers (mdeslaur

[Bug 2051574] Re: gnome-shell-portal-helper crashed with SIGTRAP in waitUntilSyncedOrDie() from WebKit::XDGDBusProxy::launch() ["bwrap: setting up uid map: Permission denied" ; "Failed to fully launch

2024-08-16 Thread Marc Deslauriers
I'll let someone else decide if this bug is still worth fixing even though we aren't using the helper anymore. -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/2051574 Title: gno

[Bug 2051574] Re: gnome-shell-portal-helper crashed with SIGTRAP in waitUntilSyncedOrDie() from WebKit::XDGDBusProxy::launch() ["bwrap: setting up uid map: Permission denied" ; "Failed to fully launch

2024-08-16 Thread Marc Deslauriers
Ah yes, this should be fixed now because of the security update. I meant to update this bug, but forgot. Thanks for noticing. -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/205157

[Bug 2077001] Re: Clipboard contents available at locked screen

2024-08-14 Thread Marc Deslauriers
Thanks! ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/2077001 Title: Clipboard contents available at lock

[Bug 2039354] Re: GDM does not prevent users with login shell /sbin/nologin from logging on

2024-05-24 Thread Marc Deslauriers
Adding gnome-session as this is where the logic exists. I don't see any changes in the latest gnome-session script. Could you please file a bug with the upstream gnome-session developers here?: https://gitlab.gnome.org/GNOME/gnome-session/-/issues Thanks! ** Also affects: gnome-session (Ubuntu)

[Bug 2062916] Re: evolution has undefined symbol in newest libwebkit2gtk

2024-04-22 Thread Marc Deslauriers
That is pretty odd, I can't reproduce this issue on jammy. what's the output of "ldd /lib/x86_64-linux- gnu/libwebkit2gtk-4.0.so.37"? -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to evolution in Ubuntu. https://bugs.launchpad.net/bugs

[Bug 2051543] Re: When I use a keyboard shortcut to lower a window, the window retains its keyboard focus.

2024-04-12 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/2051543 Title: When I use a keyboard shortcut to lower a window, the w

[Bug 2047595] Re: sound control panel security

2024-01-19 Thread Marc Deslauriers
** Package changed: ubuntu-meta (Ubuntu) => gnome-shell (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/2047595 Title: sound control panel security To manage notificat

[Bug 2042350] [NEW] When switching workspaces with mouse, no dot in indicator

2023-10-31 Thread Marc Deslauriers
Public bug reported: When switching between workspaces with ctrl-alt-arrow, there is an indicator that pops up with a bright dot highlighting which workspace is being switched to. When switching between workspaces by scrolling the mouse wheel over the "show applications" icon, the indicator pops u

[Bug 2036310] Re: gnome shell crash after sleep mode

2023-10-13 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 2036746] Re: CVE-2023-43090: avoid exposing window previews on lock screen via keyboard

2023-09-20 Thread Marc Deslauriers
** Changed in: gnome-shell (Ubuntu Lunar) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/2036746 Title: CVE-2

[Bug 2029361] Re: evolution does not start

2023-08-02 Thread Marc Deslauriers
I'm glad you figured it out, thanks for updating the bug! I'll close it now since this looks like a configuration issue. ** Changed in: evolution (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to

[Bug 2029361] Re: evolution does not start

2023-08-02 Thread Marc Deslauriers
Hi, Thanks for reporting this issue. I can't seem to reproduce this issue on Ubuntu 22.04. I do see the "WEBKIT_FORCE_SANDBOX no longer allows disabling the sandbox." message, which is normal since that workaround is no longer required, but evolution starts fine and works as expected. Could you

[Bug 2021533] Re: evolution 3.44: emails are unreadable with webkit2gtk 2.40

2023-07-31 Thread Marc Deslauriers
** Changed in: evolution (Ubuntu Kinetic) Status: Triaged => Won't Fix ** Changed in: evolution (Ubuntu Jammy) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to evolution in Ubuntu. ht

[Bug 1998060] Re: CVE-2022-37290: Pasted zip archive/invalid file causes NPD

2023-07-25 Thread Marc Deslauriers
Kinetic has now reached end-of-life. There is nothing else to sponsor in this bug for now. I am unsubscribing ubuntu-security-sponsors. If a new debdiff is attached for sponsoring, please re-subscribe the team. Thanks! ** Changed in: nemo (Ubuntu Kinetic) Status: In Progress => Won't Fix

[Bug 2022002] Re: browsers are not working suddenly...

2023-06-09 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 2022391] Re: security breach

2023-06-09 Thread Marc Deslauriers
** Package changed: ubuntu => gnome-control-center (Ubuntu) ** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-control-center in Ubuntu. https://bugs.launchpad.net/bugs/202

[Bug 1998060] Re: CVE-2022-37290: Pasted zip archive/invalid file causes NPD

2023-05-31 Thread Marc Deslauriers
Oh, that would be great, I could release them all at once. Thanks! -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to nautilus in Ubuntu. https://bugs.launchpad.net/bugs/1998060 Title: CVE-2022-37290: Pasted zip archive/invalid file ca

[Bug 2001503] Re: gnome-control-center crashed with SIGSEGV -- pipewire

2023-03-17 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 2008662] Re: How do I fix error : "Appear a prohibit icon

2023-03-17 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1998060] Re: CVE-2022-37290: Pasted zip archive/invalid file causes NPD

2023-02-17 Thread Marc Deslauriers
The update is for kinetic, did you test it on kinetic? -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to nautilus in Ubuntu. https://bugs.launchpad.net/bugs/1998060 Title: CVE-2022-37290: Pasted zip archive/invalid file causes NPD To

[Bug 1998060] Re: CVE-2022-37290: Pasted zip archive/invalid file causes NPD

2023-02-09 Thread Marc Deslauriers
ACK on the debdiff in comment #8. I have slightly adjusted it to add the bug number to the changelog and to fix the urls in the patch. I have uploaded it to the security team PPA here: https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa Please test it to make sure it works properl

[Bug 1982422] Re: Multiple vulnerabilities in Bionic, Focal and Jammy

2023-02-09 Thread Marc Deslauriers
There are no updated debdiffs to sponsor, unsubscribing ubuntu-security- sponsors for now. Please resubscribe the group once updated debdiffs have been attached to this bug. Thanks! -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gimp

[Bug 1993214] Re: [jammy] Update gjs to 1.74 using mozjs102 102.3

2023-02-07 Thread Marc Deslauriers
We are not going to release these yet, we are blocked on comment #8. -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gjs in Ubuntu. https://bugs.launchpad.net/bugs/1993214 Title: [jammy] Update gjs to 1.74 using mozjs102 102.3 To m

[Bug 1993214] Re: [jammy] Update gjs to 1.74 using mozjs102 102.3

2023-02-06 Thread Marc Deslauriers
The image builds are pulling in -proposed? -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gjs in Ubuntu. https://bugs.launchpad.net/bugs/1993214 Title: [jammy] Update gjs to 1.74 using mozjs102 102.3 To manage notifications about

[Bug 1993214] Re: [jammy] Update gjs to 1.74 using mozjs102 102.3

2022-12-15 Thread Marc Deslauriers
mozjs102 and gjs packages have been uploaded for jammy, and mozjs102 for kinetic, into the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Once they are finished building, they can be pocket-copied by an archive admin into the -proposed pocke

[Bug 1993214] Re: [jammy] Update gjs to 1.74 using mozjs102 102.3

2022-12-12 Thread Marc Deslauriers
Looks like a few more CVEs have been published between 102.3 in karmic and 102.5 in lunar: 102.4 CVE-2022-42928 bug 1791520 102.5 CVE-2022-45406 bug 1791975 102.5 CVE-2022-45409 bug 1796901 Perhaps we should move to 102.5? I have to admit, bumping to a new major release of mozjs sounds risky. Wh

[Bug 1983778] Re: Major security issue in Ubuntu Desktop default config - Removable Media

2022-09-23 Thread Marc Deslauriers
I personally don't think the reasons you've listed above are good enough to change the default setting, but please file a bug with the upstream project and you can convince them to change them: https://gitlab.gnome.org/GNOME/gnome-control-center/-/issues Once you've filed a bug with the GNOME pro

[Bug 1920643] Re: Notification popup before login -> app started w/o login

2022-08-24 Thread Marc Deslauriers
** Changed in: gdm3 (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gdm3 in Ubuntu. https://bugs.launchpad.net/bugs/1920643 Title: Notification popup before login -> app started w/o login To

[Bug 1930140] Re: GUI "Extract Here" bug - loop until disk is full

2022-08-24 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1987162] Re: 43: New Device Security feature is confusing and unhelpful currently

2022-08-22 Thread Marc Deslauriers
Another issue to consider here is that there is no secure way to display the information in the first place. If some of those settings are disabled, malware can simply modify the app to display a green checkbox next to Level 3, leading to a false sense of security. -- You received this bug notifi

[Bug 1987162] Re: 43: New Device Security feature is confusing and unhelpful currently

2022-08-20 Thread Marc Deslauriers
I don't understand not only why those advanced features would be exposed in a GUI, but why ordinary users would care at all about most of those settings. If we're going to expose "security information" to users, we should probably start by showing basic stuff, like if they are properly getting sec

[Bug 1982422] Re: Multiple vulnerabilities in Bionic, Focal and Jammy

2022-08-09 Thread Marc Deslauriers
I took a look at the debdiffs in #2, #3, and #8, and here are my comments: For Bionic: - The package doesn't build with the debdiff provided. Please fix and make sure it builds before submitting it again. - In CVE-2022-32990-2.patch, you dropped the section that patches xcf_load_buffer, but in

[Bug 1955362] Re: epiphany December 2021 XSS issues

2022-08-08 Thread Marc Deslauriers
ACK on the debdiff in comment #3. It is building in the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Once it has finished building, please test it and detail the testing performed in this bug, and we will release it as a security update. T

[Bug 1969851] Re: CVE-2022-29536 epiphany

2022-08-08 Thread Marc Deslauriers
ACK on the debdiff in comment #2. It is building in the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Once it has finished building, please test it and detail the testing performed in this bug, and we will release it as a security update. T

[Bug 1974250] Re: ~/.pam_environment gets created as owned by root

2022-05-24 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Also affects: accountsservice (Ubuntu Jammy) Importance: Undecided Status: New ** Also affects: accountsservice (Ubuntu Kinetic) Importance: High Status: Fix Released ** Changed in: accountsservice (Ubunt

[Bug 1971415] Re: Remote desktop is automatically enabled after login

2022-05-18 Thread Marc Deslauriers
This patch is still broken. The same thing happens with VNC: 1- Turn on remote desktop, turn on VNC. 2- Only turn off remote desktop while leaving VNC checked 3- Reboot 4- The VNC port is listening to connections even though remote desktop says off in the control center. -- You received this bu

[Bug 1964795] Re: gnome-keyring-daemon crashed with signal 7

2022-03-30 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1965686] Re: After the laptop comes out of sleep mode, the desktop environment for some reason breaks and appears crashes window

2022-03-30 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/1965686 Title: After the laptop comes out of sleep mode, the desktop

[Bug 1965869] Re: Screen only partially locked. Password promt was visible, but switching to window and typing eg in terminal was possible

2022-03-30 Thread Marc Deslauriers
** Package changed: ubuntu => gnome-shell (Ubuntu) ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/1965869 Title: Sc

[Bug 1959591] Re: Out-of-bounds read during processing of a password-protected PDF file

2022-02-18 Thread Marc Deslauriers
** Changed in: poppler (Ubuntu) Status: New => Confirmed ** Changed in: poppler (Ubuntu) Importance: Undecided => Low -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to poppler in Ubuntu. https://bugs.launchpad.net/bugs/1959591

[Bug 1946578] Re: Update for CVE-2021-41133

2021-12-14 Thread Marc Deslauriers
Thanks for testing! https://ubuntu.com/security/notices/USN-5191-1 ** Changed in: flatpak (Ubuntu) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to flatpak in Ubuntu. https://bugs.launchpad.n

[Bug 1945086] Re: nautilus crashed with SIGSEGV in delete_outdated_error_traps().

2021-11-23 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1945388] Re: opening application steals focus from authenticate window

2021-11-23 Thread Marc Deslauriers
** Package changed: ubuntu => gnome-shell (Ubuntu) ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/1945388 Title: op

[Bug 1949225] Re: screen lock is not working on suspend

2021-11-23 Thread Marc Deslauriers
** Package changed: ubuntu => gnome-shell (Ubuntu) ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/1949225 Title: sc

[Bug 1950035] Re: suspend does not lock in 20.04

2021-11-23 Thread Marc Deslauriers
** Package changed: linux (Ubuntu) => gnome-shell (Ubuntu) ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/1950035 Tit

[Bug 1951098] Re: security issue!

2021-11-23 Thread Marc Deslauriers
** Package changed: ubuntu => gnome-shell (Ubuntu) ** Summary changed: - security issue! + When screen is locked the top bar with apps shows ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which

[Bug 1942542] Re: gedit causes loss of extended attributes (xattrs)

2021-09-23 Thread Marc Deslauriers
** Also affects: gedit via https://gitlab.gnome.org/GNOME/gedit/-/issues/464 Importance: Unknown Status: Unknown ** Changed in: gedit (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed t

[Bug 1944464] Re: gnome-screensaver locked screen leaks text to underlying windows

2021-09-23 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Changed in: gnome-screensaver (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-screensaver in Ubuntu. https://bugs.lau

[Bug 1935690] Re: Lock Screen Failure - Desktop Contents Momentarily Visible

2021-08-10 Thread Marc Deslauriers
** Package changed: unity (Ubuntu) => gnome-shell (Ubuntu) ** Changed in: gnome-shell (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/193569

[Bug 1929304] Re: file-roller / gnome archive manager fails to extract

2021-06-04 Thread Marc Deslauriers
Status: New ** Also affects: gnome-autoar (Ubuntu Hirsute) Importance: Undecided Status: New ** Also affects: gnome-autoar (Ubuntu Groovy) Importance: Undecided Status: New ** Changed in: gnome-autoar (Ubuntu Bionic) Assignee: (unassigned) => Marc Deslauri

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-05-14 Thread Marc Deslauriers
Hi, have you had a chance to test the packages as requested in comment #31 yet? Thanks! -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to caribou in Ubuntu. https://bugs.launchpad.net/bugs/1912060 Title: [SRU] caribou: Segfault (as re

[Bug 1925834] Re: BRASERO DOESNT WORK WITH UBUNTU 20.04 NO CD WRITING BACK UP ? WHY

2021-05-07 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1926093] Re: package gconf-service 3.2.6-6ubuntu1 failed to install/upgrade: problemas de dependência - deixando desconfigurado

2021-05-07 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1910220] Re: Characters from dead keys shown in plan view in password field on login screen

2021-03-09 Thread Marc Deslauriers
I can reproduce this on Ubuntu 20.04 and Ubuntu 20.10 ** Changed in: gnome-shell (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/1910220

[Bug 1917801] Re: Multi monitor bug opening windows (not responsive to input in the location it is drawn)

2021-03-09 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1917812] Re: extracting archives from within nautilus omits subfolders

2021-03-08 Thread Marc Deslauriers
tus: New => In Progress ** Changed in: gnome-autoar (Ubuntu Xenial) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: gnome-autoar (Ubuntu Bionic) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: gnome-autoar (Ubuntu Focal) Statu

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-01-28 Thread Marc Deslauriers
The focal debdiff has an extra commit that the groovy debdiff does't have, and it doesn't look like that commit is in the upstream repo: >From 85ac8f9e210243d95163cf8b1013470a6d9c7eaa Mon Sep 17 00:00:00 2001 From: Clement Lefebvre Date: Tue, 12 Jan 2021 17:30:25 + Subject: [PATCH 2/4] Fix su

[Bug 1913584] Re: passwords openly readable from gnome-keyring-daemon

2021-01-28 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. This is not a bug, but rather expected behavior: https://wiki.ubuntu.com/SecurityTeam/FAQ#gnome-keyring Please feel free to report any other bugs you may find. ** Information type changed from Private Security to P

[Bug 1912060] Re: [SRU] caribou: Segfault (as regression of xorg CVE-2020-25712 fix) cause security issue for cinnamon

2021-01-26 Thread Marc Deslauriers
The minimal fix should be published as a security update. Once a groovy debdiff is available too, ping someone on the security team and we'll get it built and published. Thanks! -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to caribou i

[Bug 1905741] Re: poppler 0.62.0-2ubuntu2.11 and 0.41.0-0ubuntu1.15 security updates break Splash output

2020-11-26 Thread Marc Deslauriers
buntu) Status: New => Invalid ** Changed in: poppler (Ubuntu Xenial) Status: New => In Progress ** Changed in: poppler (Ubuntu Bionic) Status: New => In Progress ** Changed in: poppler (Ubuntu Xenial) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in

[Bug 1902761] Re: package gdm3 3.36.3-0ubuntu0.20.04.2 failed to install/upgrade: el subproceso instalado paquete gdm3 script post-installation devolvió el código de salida de error 10

2020-11-06 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1889206] Re: Regression in USN-4436-1

2020-07-29 Thread Marc Deslauriers
** Changed in: librsvg (Ubuntu) Status: Confirmed => Invalid -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to librsvg in Ubuntu. https://bugs.launchpad.net/bugs/1889206 Title: Regression in USN-4436-1 To manage notifications

[Bug 1889206] Re: Regression in USN-4436-1

2020-07-28 Thread Marc Deslauriers
** Attachment added: "eog displaying issue rendering anglo cardset" https://bugs.launchpad.net/ubuntu/+source/librsvg/+bug/1889206/+attachment/5396555/+files/anglo-issue.png ** Bug watch added: gitlab.gnome.org/GNOME/librsvg/-/issues #612 https://gitlab.gnome.org/GNOME/librsvg/-/issues/612

[Bug 1889206] Re: Regression in USN-4436-1

2020-07-28 Thread Marc Deslauriers
Can also be tested by running "eog /usr/share/aisleriot/cards/anglo.svgz". See attached screenshot. -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to librsvg in Ubuntu. https://bugs.launchpad.net/bugs/1889206 Title: Regression in USN-

[Bug 1889206] [NEW] Regression in USN-4436-1

2020-07-28 Thread Marc Deslauriers
me cards are missing graphics ** Affects: librsvg (Ubuntu) Importance: Undecided Status: New ** Affects: librsvg (Ubuntu Xenial) Importance: Undecided Assignee: Marc Deslauriers (mdeslaur) Status: Confirmed ** Affects: librsvg (Ubuntu Bionic) Importance: Undecided

[Bug 1887861] Re: Gnome Lock screen shows old screen before lock screen

2020-07-17 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/1887861 Title: Gnome Lock screen shows old screen before loc

[Bug 896836] Re: Segmentation fault when asking help() for the list of modules

2020-07-14 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to pygtk in Ubuntu. https://bugs.launchpad.net/bugs/896836 Title: Segmentation fault when asking help() for the list of modules

[Bug 1881780] Re: Nautilus requires SMBv1 to work from "Other Locations" without manually typing in the address.

2020-07-14 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to nautilus in Ubuntu. https://bugs.launchpad.net/bugs/1881780 Title: Nautilus requires SMBv1 to work from "Other Locations" wit

[Bug 1882353] Re: Ubuntu Dock and Top bar accessible from lockscreen

2020-07-14 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/1882353 Title: Ubuntu Dock and Top bar accessible from lockscreen To

[Bug 1844853] Re: IBus no longer works in Qt applications after upgrade

2020-03-23 Thread Marc Deslauriers
** Tags removed: verification-needed verification-needed-disco -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to glib2.0 in Ubuntu. https://bugs.launchpad.net/bugs/1844853 Title: IBus no longer works in Qt applications after upgrade

[Bug 1857122] Re: New Windows are opened below other windows and require extra clicks to acees

2020-03-11 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1864948] Re: circumflex accent in a password is not hidden properly

2020-03-11 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-terminal in Ubuntu. https://bugs.launchpad.net/bugs/1864948 Title: circumflex accent in a password is not hidden prope

[Bug 1866899] Re: Snap Store can't install or remove snaps on 20.04 (password prompt issue?)

2020-03-11 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1844853] Re: IBus no longer works in Qt applications after upgrade

2020-03-03 Thread Marc Deslauriers
Is anyone actively working on the glib2.0 SRUs? We are blocked on them for our ibus security update... -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to glib2.0 in Ubuntu. https://bugs.launchpad.net/bugs/1844853 Title: IBus no longer

[Bug 1855477] Re: gnome-control-center will not let me paste in a password from my password manger

2019-12-11 Thread Marc Deslauriers
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-control-center in Ubuntu. https://bugs.launchpad.net/bugs/1855477 Title: gnome-control-center will not let me paste in

[Bug 1855157] Re: these bugs are stop me to do some specifing task like my screenlock doesn't working

2019-12-11 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1716013] Re: Printers should not be auto-added without permission from user

2019-10-18 Thread Marc Deslauriers
** Changed in: gnome-settings-daemon (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-settings-daemon in Ubuntu. https://bugs.launchpad.net/bugs/1716013 Title: Printers should not be aut

[Bug 1791405] Re: bluetooth always in discoverable mode (security issue)

2019-10-18 Thread Marc Deslauriers
** Changed in: bluez (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-bluetooth in Ubuntu. https://bugs.launchpad.net/bugs/1791405 Title: bluetooth always in discoverable mode (security

[Bug 1771196] Re: daap plugin opens port by default

2019-09-17 Thread Marc Deslauriers
While Rhythmbox does indeed open a port when started, the user needs to start it before the port becomes available. This is no different than opening a Bittorrent client application, or some other application that opens ports. That being said, perhaps the plugin should be disabled by default. Tha

[Bug 1780365] Re: Credentials located in gnome-keyring can be compromised easily

2019-09-17 Thread Marc Deslauriers
** Changed in: gnome-keyring (Ubuntu) Status: New => Confirmed ** Changed in: gnome-keyring (Ubuntu) Importance: Undecided => Low -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-keyring in Ubuntu. https://bugs.launchpa

[Bug 1797161] Re: GNOME Image Viewer (EOG): invalid XPM file causes dynamic memory allocation

2019-09-17 Thread Marc Deslauriers
** Changed in: eog (Ubuntu) Status: New => Incomplete ** Changed in: eog (Ubuntu) Status: Incomplete => Invalid ** Changed in: gdk-pixbuf (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscr

[Bug 1797012] Re: Fingerprint login can be changed without authentication

2019-09-17 Thread Marc Deslauriers
*** This bug is a duplicate of bug 1532264 *** https://bugs.launchpad.net/bugs/1532264 I am going to mark this as a dupe of bug 1532264 since it looks to be the same root cause. Thanks! ** Information type changed from Private Security to Public Security ** This bug has been marked a duplica

[Bug 1841713] Re: It is unlocking the screen when I type my password when caps lock is on

2019-09-17 Thread Marc Deslauriers
Hi, Are you able to reproduce this with a freshly installed Ubuntu? Thanks! ** Package changed: gnome-screensaver (Ubuntu) => gnome-shell (Ubuntu) ** Information type changed from Private Security to Public Security ** Changed in: gnome-shell (Ubuntu) Status: New => Incomplete -- You

[Bug 1842668] Re: Workspace view is showing before unlocking 19.04

2019-09-17 Thread Marc Deslauriers
** Package changed: ubuntu => gnome-shell (Ubuntu) ** Information type changed from Private Security to Public Security ** Changed in: gnome-shell (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed

[Bug 1843718] Re: I can change password of one administrator from other

2019-09-17 Thread Marc Deslauriers
Closing this bug as per previous comment. Thanks! ** Changed in: gnome-control-center (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-control-center in Ubuntu. https://bugs.launchpad.net/bu

[Bug 1819406] Re: Found broken a feature for fingerprint image obfuscation

2019-06-28 Thread Marc Deslauriers
** Changed in: libfprint (Ubuntu) Status: New => Confirmed ** Changed in: libfprint (Ubuntu) Importance: High => Low ** Changed in: libfprint (Ubuntu) Importance: Low => High ** Also affects: libfprint via https://gitlab.freedesktop.org/libfprint/fprintd/issues/16 Importance:

[Bug 1828116] Re: Password works uppercase and lowercase

2019-06-28 Thread Marc Deslauriers
** Changed in: gdm3 (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.net/bugs/1828116 Title: Password works uppercase and lowercase To manage no

[Bug 1797161] Re: GNOME Image Viewer (EOG): invalid XPM file causes dynamic memory allocation

2019-03-07 Thread Marc Deslauriers
** Bug watch added: gitlab.gnome.org/GNOME/gdk-pixbuf/issues #95 https://gitlab.gnome.org/GNOME/gdk-pixbuf/issues/95 ** Also affects: choreographics via https://gitlab.gnome.org/GNOME/gdk-pixbuf/issues/95 Importance: Unknown Status: Unknown ** Project changed: choreographics => gd

[Bug 1815602] Re: [SRU] Update epiphany-browser to 3.28.5 in Bionic

2019-03-07 Thread Marc Deslauriers
** Changed in: epiphany-browser (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to epiphany-browser in Ubuntu. https://bugs.launchpad.net/bugs/1815602 Title: [SRU] Update epiphany-browser to 3.2

[Bug 1818357] Re: Screen not locked when coming out of suspend/hibernate

2019-03-07 Thread Marc Deslauriers
** Package changed: gnome-screensaver (Ubuntu) => gnome-shell (Ubuntu) ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gnome-shell in Ubuntu. https://bugs.launchpad.

[Bug 1773561] Re: Xenial/16.04: GIMP needs a security update - unfixed issues (CVE-2017: 17784-17789).

2019-02-14 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to gimp in Ubuntu. https://bugs.launchpad.net/bugs/1773561 Title: Xenial/16.04: GIMP needs a security update - unfixed

[Bug 1772919] Re: pam-gnome-keyring.so reveals user’s password credential as a plaintext form

2019-02-14 Thread Marc Deslauriers
** Also affects: gnome-keyring (Ubuntu Xenial) Importance: Undecided Status: New ** Also affects: gnome-keyring (Ubuntu Trusty) Importance: Undecided Status: New ** Changed in: gnome-keyring (Ubuntu) Status: New => Fix Released ** Changed in: gnome-keyring (Ubuntu Trus

[Bug 1808908] Re: Screen not locked when coming out of suspend/hibernate

2019-01-18 Thread Marc Deslauriers
Are you able to reproduce this issue at will? It sounds like there is something wrong with your authentication settings. Did you install fingerprint reader software, or are you connected to an LDAP directory? ** Package changed: gnome-screensaver (Ubuntu) => gnome-shell (Ubuntu) ** Changed in: g

[Bug 1803059] Re: Nullpointer dereference

2018-12-04 Thread Marc Deslauriers
The upstream commit was assigned CVE-2018-19149. ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-19149 -- You received this bug notification because you are a member of Ubuntu Desktop Bugs, which is subscribed to poppler in Ubuntu. https://bugs.launchpad.net/bugs/1803059 Title

  1   2   3   4   5   6   7   8   9   10   >