[Bug 2073783] Re: [MIR] exfatprogs

2025-01-13 Thread Rodrigo Figueiredo Zaiden
I reviewed exfatprogs 1.2.6-1 as checked into plucky and 1.2.5-2 as checked into oracular. This shouldn't be considered a full audit but rather a quick gauge of maintainability. plucky version was mainly considered for the most part of this review but it is also valid for oracular as they are pret

[Bug 2088444] Re: CVE-2024-45006 Linux 6.8.0 / 6.8.12 Noble full system crash

2024-11-18 Thread Rodrigo Figueiredo Zaiden
Hi, thanks for getting in touch. for noble, CVE-2024-45006 is queued to be fixed in version 6.8.0-50.51. This version is planned be released in the week of 02-Dec. ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-45006 ** Changed in: linux (Ubuntu) Status: New => Fix Co

[Bug 2088444] Re: CVE-2024-45006 Linux 6.8.0 / 6.8.12 Noble full system crash

2024-11-18 Thread Rodrigo Figueiredo Zaiden
** Package changed: linux-signed (Ubuntu) => linux (Ubuntu) ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2088444 Title: CVE-202

[Bug 2084715] Re: recent date test causes new builds to fail

2024-10-16 Thread Rodrigo Figueiredo Zaiden
** No longer affects: python-urllib3 (Ubuntu Noble) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2084715 Title: recent date test causes new builds to fail To manage notifications about this bug go

[Bug 2084715] Re: recent date test causes new builds to fail

2024-10-16 Thread Rodrigo Figueiredo Zaiden
** Also affects: python-urllib3 (Ubuntu Noble) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2084715 Title: recent date test causes new builds to fail To

[Bug 1597017] Re: mount rules grant excessive permissions

2024-09-16 Thread Rodrigo Figueiredo Zaiden
Testing Documentation: This update was tested following the guidelines available at: https://wiki.ubuntu.com/Process/Merges/TestPlans/AppArmor In summary, they are: - AppArmor cache files verification; - Basic Ubuntu login tests: network, browser, apt; - LXC, LXD, Docker basic operations and appa

[Bug 2066262] Re: [MIR] libdex

2024-09-09 Thread Rodrigo Figueiredo Zaiden
I reviewed libdex 0.7.1-1 as checked into oracular. This shouldn't be considered a full audit but rather a quick gauge of maintainability. libdex is basically a GNOME library used for asynchronous operations. from upstream: Dex provides Future-based programming for GLib-based applications. Dex

[Bug 1597017] Re: mount rules grant excessive permissions

2024-09-06 Thread Rodrigo Figueiredo Zaiden
** Tags removed: verification-needed-focal verification-needed-jammy ** Tags added: verification-done-focal verification-done-jammy ** Tags removed: verification-needed ** Tags added: verification-done -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscr

[Bug 2076174] Re: noble/linux-oem-6.11: 6.11.0-1001.1 -proposed tracker

2024-08-14 Thread Rodrigo Figueiredo Zaiden
** Changed in: kernel-sru-workflow/security-signoff Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2076174 Title: noble/linux-oem-6.11: 6.11.0-1001.1 -propo

[Bug 948459] Re: oggenc fails when using '--advanced-encode-option disable_coupling' switch and CBR encoding

2022-05-12 Thread Rodrigo Figueiredo Zaiden
. - CVE-2017-14160, CVE-2018-10392, CVE-2018-10393 * Fix autopkgtest: - debian/patches/0003-vorbisenc-detect-if-new-template-is-null.patch: check if new_template is NULL at vorbis_encode_ctl() in lib/vorbisenc.c. -- Rodrigo Figueiredo Zaiden Wed, 11 May 2022 14:54:32 -0300

[Bug 948459] Re: oggenc fails when using '--advanced-encode-option disable_coupling' switch and CBR encoding

2022-05-12 Thread Rodrigo Figueiredo Zaiden
Upstream issue is: https://gitlab.xiph.org/xiph/vorbis/-/issues/1975 and the solution is the commit: https://gitlab.xiph.org/xiph/vorbis/-/commit/42f2bb2936ea06e3a9a2fc2260988120d6dfc97d the '--advanced-encode-option disable_coupling' in oggenc is used on autopkgtests for libvorbis. so, in xenia

[Bug 1971895] Re: Warning messages from stat printed on installation with no user crontabs

2022-05-10 Thread Rodrigo Figueiredo Zaiden
/cron/-/commit/23047851 -- Rodrigo Figueiredo Zaiden Tue, 10 May 2022 18:07:46 -0300 ** Changed in: cron (Ubuntu Xenial) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. ht

[Bug 1971895] Re: Warning messages from stat printed on installation with no user crontabs

2022-05-10 Thread Rodrigo Figueiredo Zaiden
** Changed in: cron (Ubuntu Xenial) Assignee: (unassigned) => Rodrigo Figueiredo Zaiden (rodrigo-zaiden) ** Changed in: cron (Ubuntu Bionic) Assignee: (unassigned) => Rodrigo Figueiredo Zaiden (rodrigo-zaiden) -- You received this bug notification because you are a member of

[Bug 1639372] Re: CVE-2016-9082: DOS attack in converting SVG to PNG

2022-05-10 Thread Rodrigo Figueiredo Zaiden
Fixed in xenial 1.14.6-1ubuntu0.1~esm1: https://ubuntu.com/security/notices/USN-5407-1 ** Changed in: cairo (Ubuntu Xenial) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpa

[Bug 1971550] Re: networkd-dispatcher missing state 'initialized'

2022-05-04 Thread Rodrigo Figueiredo Zaiden
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-29799 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1971550 Title: networkd-dispatcher missing state 'initialized' To manage notifi

[Bug 1971550] Re: networkd-dispatcher missing state 'initialized'

2022-05-04 Thread Rodrigo Figueiredo Zaiden
** Changed in: networkd-dispatcher (Ubuntu) Assignee: (unassigned) => Rodrigo Figueiredo Zaiden (rodrigo-zaiden) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1971550 Title: netwo

[Bug 1888309] Re: [MIR] octavia

2022-04-07 Thread Rodrigo Figueiredo Zaiden
VE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-17134 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-3895 ** Changed in: octavia (Ubuntu) Assignee: Rodrigo Figueiredo Zaiden (rodrigo-zaiden) => (unassigned) -- You received this bug notification because y

[Bug 1912091] Re: Memory Leak GNU Tar 1.33

2022-03-15 Thread Rodrigo Figueiredo Zaiden
** Changed in: tar (Ubuntu Bionic) Status: New => Fix Released ** Changed in: tar (Ubuntu Focal) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1912091 Title:

[Bug 1912091] Re: Memory Leak GNU Tar 1.33

2022-03-15 Thread Rodrigo Figueiredo Zaiden
This bug was fixed in the tagged releases https://ubuntu.com/security/notices/USN-5329-1 General changelog: * SECURITY UPDATE: Denial of service (LP: #1912091) - debian/patches/CVE-2021-20193.patch: in read_header method in src/list.c, change the return value to be the value of status

[Bug 1961820] Re: CVE-2021-21708: potential RCE with filter_var(..., FILTER_VALIDATE_FLOAT)

2022-02-28 Thread Rodrigo Figueiredo Zaiden
after a validation is succeeded, and add a test for this case in ext/filter/tests/bug81708.phpt - CVE-2021-21708 -- Rodrigo Figueiredo Zaiden Thu, 24 Feb 2022 12:03:09 -0300 ** Changed in: php8.0 (Ubuntu) Status: In Progress => Fix Released -- You received this

[Bug 1961820] Re: CVE-2021-21708: potential RCE with filter_var(..., FILTER_VALIDATE_FLOAT)

2022-02-28 Thread Rodrigo Figueiredo Zaiden
after a validation is succeeded, and add a test for this case in ext/filter/tests/bug81708.phpt - CVE-2021-21708 -- Rodrigo Figueiredo Zaiden Thu, 24 Feb 2022 11:55:48 -0300 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-21708 ** Changed in: php7.4 (Ubuntu

[Bug 1961820] Re: CVE-2021-21708: potential RCE with filter_var(..., FILTER_VALIDATE_FLOAT)

2022-02-24 Thread Rodrigo Figueiredo Zaiden
** Also affects: php8.0 (Ubuntu) Importance: Undecided Status: New ** Changed in: php8.0 (Ubuntu) Assignee: (unassigned) => Rodrigo Figueiredo Zaiden (rodrigo-zaiden) ** Changed in: php8.0 (Ubuntu) Status: New => In Progress -- You received this bug notification b

[Bug 1961820] Re: CVE-2021-21708: potential RCE with filter_var(..., FILTER_VALIDATE_FLOAT)

2022-02-24 Thread Rodrigo Figueiredo Zaiden
** Changed in: php7.4 (Ubuntu) Status: Confirmed => In Progress ** Changed in: php7.4 (Ubuntu) Assignee: (unassigned) => Rodrigo Figueiredo Zaiden (rodrigo-zaiden) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1888309] Re: [MIR] octavia

2022-02-24 Thread Rodrigo Figueiredo Zaiden
** Changed in: octavia (Ubuntu) Assignee: Ubuntu Security Team (ubuntu-security) => Rodrigo Figueiredo Zaiden (rodrigo-zaiden) ** Changed in: octavia (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, wh

[Bug 1953173] Re: [MIR] python-asgiref

2022-02-21 Thread Rodrigo Figueiredo Zaiden
giref (Ubuntu) Assignee: Rodrigo Figueiredo Zaiden (rodrigo-zaiden) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1953173 Title: [MIR] python-asgiref To manage notificatio

[Bug 1953173] Re: [MIR] python-asgiref

2022-02-21 Thread Rodrigo Figueiredo Zaiden
From: https://github.com/django/asgiref/issues/317 Upstream confirmed that it is in fact an issue, but, it's not exploitable. My understanding is that it will hit other guards before falling in that case. And, changing it would be a potential risk of breaking other things. I'm pretty satisfied w

[Bug 1953173] Re: [MIR] python-asgiref

2022-02-18 Thread Rodrigo Figueiredo Zaiden
Hi Lena, Thanks for checking and testing it. I raised an issue in the upstream to ask about it: https://github.com/django/asgiref/issues/317 Thanks! ** Bug watch added: github.com/django/asgiref/issues #317 https://github.com/django/asgiref/issues/317 -- You received this bug notification

[Bug 1953173] Re: [MIR] python-asgiref

2022-02-16 Thread Rodrigo Figueiredo Zaiden
Hi Server team, could you, please, take a look into the following lines in wgsi.py: def build_environ(self, scope, body): ... environ = { ... "SCRIPT_NAME": scope.get("root_path", "").encode("utf8").decode("latin1"), "PATH_INFO": scope["pat

[Bug 1953173] Re: [MIR] python-asgiref

2022-02-10 Thread Rodrigo Figueiredo Zaiden
** Changed in: python-asgiref (Ubuntu) Status: New => In Progress ** Changed in: python-asgiref (Ubuntu) Assignee: Ubuntu Security Team (ubuntu-security) => Rodrigo Figueiredo Zaiden (rodrigo-zaiden) -- You received this bug notification because you are a member of Ubunt

[Bug 1953516] [NEW] autopkgtest test-tls-passphrase is failing due to an expired certificate

2021-12-07 Thread Rodrigo Figueiredo Zaiden
Public bug reported: autopkgtest test-tls-passphrase is failing due to an expired certificate: not ok 1808 parallel/test-tls-passphrase --- duration_ms: 1.117 severity: fail exitcode: 1 stack: |- events.js:174 throw er; // Unhandled 'error' event ^ Error

[Bug 1951432] [NEW] fail to build from source

2021-11-18 Thread Rodrigo Figueiredo Zaiden
Assignee: Rodrigo Figueiredo Zaiden (rodrigo-zaiden) Status: In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1951432 Title: fail to build from source To manage notifications about this