[Bug 1898547] Re: neutron-linuxbridge-agent fails to start with iptables 1.8.5

2020-11-05 Thread Alex Murray
** Description changed: [Impact] With iptables 1.8.5 neutron-linuxbridge-agent fails to properly start. The log file shows many errors like: 2020-10-05 10:20:37.998 551 ERROR neutron.plugins.ml2.drivers.agent._common_agent ; Stdout: ; Stderr: iptables-restore: line 29 failed

[Bug 1898547] Re: neutron-linuxbridge-agent fails to start with iptables 1.8.5

2020-11-05 Thread Alex Murray
FYI the two autopkgtest failures for arm64 (sshuttle & firewalld) both appear to be transient failures so these are currently being retried... -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1898547 Tit

[Bug 1903883] Re: XPS 13 9310 Tiger Lake Unable to boot 20.10 after intel-microcode update 3.20201110.0ubuntu0.20.10.1

2020-11-11 Thread Alex Murray
** Changed in: intel-microcode (Ubuntu) Assignee: (unassigned) => Alex Murray (alexmurray) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1903883 Title: XPS 13 9310 Tiger Lake Unable to b

[Bug 1903883] Re: XPS 13 9310 Tiger Lake Unable to boot 20.10 after intel-microcode update 3.20201110.0ubuntu0.20.10.1

2020-11-11 Thread Alex Murray
Thanks for reporting this issue - thanks @superrm1 for forwarding it upstream - https://github.com/intel/Intel-Linux-Processor-Microcode- Data-Files/issues/44 - I'll push an update soon which reverts just this single microcode for the intel-microcode package in Ubuntu. ** Bug watch added: github.

[Bug 1903864] Re: qemu-system-x86_64: -device tpm-tis, tpmdev=tpm-tpm0, id=tpm0: Property 'tpm-tis.tpmdev' can't find value 'tpm-tpm0'

2020-11-11 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1903677] Re: Mozilla Firefox / Firefox ESR Arbitrary Code Execution Vulnerability

2020-11-11 Thread Alex Murray
firefox 82.0.3 was released for xenial, bionic, focal, groovy and hirsute yesterday. ** Changed in: firefox (Ubuntu) Status: New => Fix Released ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu B

[Bug 1903484] Re: package python-six 1.14.0-2 failed to install/upgrade: installed python-six package post-installation script subprocess returned error exit status 127

2020-11-11 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1885248] Re: Update intel-microcode to latest upstream release 20200616 to fix possible regression in 06-5e-03/0x000506e3

2020-11-11 Thread Alex Murray
This is now obsolete - we recently updated intel-microcode to the most recent 20201110 release. ** Changed in: intel-microcode (Ubuntu) Status: New => Fix Released ** Changed in: intel-microcode (Ubuntu Xenial) Status: New => Fix Released ** Changed in: intel-microcode (Ubuntu Bion

[Bug 1841281] Re: ClamAV needs updated to reflect security fixes

2020-11-11 Thread Alex Murray
This was fixed in clamav 0.101.4+dfsg-0ubuntu0.YY.MM.1 for each corresponding Ubuntu release. ** Changed in: clamav (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchp

[Bug 1904068] [NEW] apt(-get) source fails to use credentials from /etc/apt/auth.conf(.d)

2020-11-12 Thread Alex Murray
Public bug reported: I have configured apt-src access to the private ESM PPAs via entries in /etc/apt/sources.list.d/ubuntu-security.list as follows: deb-src https://private-ppa.launchpad.net/ubuntu-esm/esm-infra- security/ubuntu trusty main and then added credentials as follows to /etc/apt/auth

[Bug 1898547] Re: neutron-linuxbridge-agent fails to start with iptables 1.8.5

2020-11-12 Thread Alex Murray
** Tags removed: verification-needed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1898547 Title: neutron-linuxbridge-agent fails to start with iptables 1.8.5 To manage notifications about this bug

[Bug 1898547] Re: neutron-linuxbridge-agent fails to start with iptables 1.8.5

2020-11-12 Thread Alex Murray
jdstrand sponsored this to groovy-proposed and autopkgtests have all passed - ~ubuntu-sru - could you please review? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1898547 Title: neutron-linuxbridge-

[Bug 1904288] Re: package bluez 5.53-0ubuntu3 failed to install/upgrade: il sottoprocesso installato pacchetto bluez script post-installation ha restituito lo stato di errore 1

2020-11-15 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1903883] Re: XPS 13 9310 Tiger Lake Unable to boot 20.10 after intel-microcode update 3.20201110.0ubuntu0.20.10.1

2020-11-15 Thread Alex Murray
@Pierre - can you please open a new bug report via `ubuntu-bug intel- microcode` and we can follow up there - thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1903883 Title: XPS 13 9310 Tiger L

[Bug 1891953] Re: CVE-2019-8936

2020-11-17 Thread Alex Murray
@rokclimb15 - are you still looking at producing debdiff's for focal + groovy as well? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1891953 Title: CVE-2019-8936 To manage notifications about this

[Bug 1891953] Re: CVE-2019-8936

2020-11-17 Thread Alex Murray
Excellent - thank you :) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1891953 Title: CVE-2019-8936 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ntp/+bug/

[Bug 1904192] Re: ebtables can not rename just created chain

2020-11-17 Thread Alex Murray
Yep I'll take this @Christian ** Changed in: iptables (Ubuntu Groovy) Assignee: (unassigned) => Alex Murray (alexmurray) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1904192 Title:

[Bug 1904658] Re: intel-ucode sig=0x406e3 from release 3.20201110.0ubuntu0.20.04.2 hangs system in early boot

2020-11-19 Thread Alex Murray
Thanks for reporting this issue, I have tried to reproduce it locally on a couple machines with the same CPUID but they boot fine with this microcode revision - from their dmesg: microcode: microcode updated early to revision 0xe2, date = 2020-07-14 Linux version 5.4.0-54-generic (buildd@lcy01-amd

[Bug 1901572] Re: snapd vulnerable to Library Injection from CWD

2020-12-03 Thread Alex Murray
Deleted PoC etc before marking this public. ** Attachment removed: "snap-escape-POC.tar.gz" https://bugs.launchpad.net/snapcraft/+bug/1901572/+attachment/5427455/+files/snap-escape-POC.tar.gz ** Attachment removed: "make_libc.py" https://bugs.launchpad.net/snapcraft/+bug/1901572/+attachme

[Bug 1906474] Re: phpldapadmin 1.2.5 vulnerable to stored cross site scripting

2020-12-10 Thread Alex Murray
CVE-2020-35132 was assigned by MITRE for this issue. ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-35132 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1906474 Title: php

[Bug 1805316] Re: systemd 229-4ubuntu21.9 faulty - breaks the system!

2018-11-27 Thread Alex Murray
*** This bug is a duplicate of bug 1804847 *** https://bugs.launchpad.net/bugs/1804847 I've marked this as a duplicate of bug #1804847 - please add any further comments to that bug instead. ** This bug has been marked a duplicate of bug 1804847 systemd=229-4ubuntu21.8 use of fchownat faile

[Bug 1770877] Re: [MIR] tracker-miners

2018-11-27 Thread Alex Murray
** Changed in: tracker-miners (Ubuntu) Assignee: Ubuntu Security Team (ubuntu-security) => Alex Murray (alexmurray) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1770877 Title: [MIR] trac

[Bug 1805519] Re: G15 package website url invalid, leads to possible malware install

2018-11-27 Thread Alex Murray
*** This bug is a duplicate of bug 1468526 *** https://bugs.launchpad.net/bugs/1468526 ** Information type changed from Private Security to Public ** This bug has been marked a duplicate of bug 1468526 g15tools.com seems to be not anymore under control be g15tools -- You received this bu

[Bug 1770877] Re: [MIR] tracker-miners

2018-11-27 Thread Alex Murray
sensitive bits from HOME etc - ACK from security team to promote to main. ** Bug watch added: GNOME Bug Tracker #764786 https://bugzilla.gnome.org/show_bug.cgi?id=764786 ** Changed in: tracker-miners (Ubuntu) Assignee: Alex Murray (alexmurray) => (unassigned) -- You received this b

[Bug 1770877] Re: [MIR] tracker-miners

2018-11-27 Thread Alex Murray
Whoops - just noticed the comment re which version to review - will take a look at the suggested version in https://salsa.debian.org/gnome-team /tracker-miners -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/

[Bug 1770877] Re: [MIR] tracker-miners

2018-11-27 Thread Alex Murray
** Changed in: tracker-miners (Ubuntu) Assignee: (unassigned) => Alex Murray (alexmurray) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1770877 Title: [MIR] tracker-miners To man

[Bug 1770877] Re: [MIR] tracker-miners

2018-11-28 Thread Alex Murray
, libgif-dev, libgxps-dev, libosinfo-1.0-dev, libtagc0-dev, libcue-dev, libseccomp-dev, dbus, dbus-x11, procps, shared-mime-info, Security team ACK to promote to main. ** Changed in: tracker-miners (Ubuntu) Assignee: Alex Murray (alexmurray) => (unassigned) -- You received this

[Bug 1770871] Re: [MIR] libcue

2018-11-28 Thread Alex Murray
I reviewed libcue (2.2.1-2) from disco. This is not a full security audit but rather a quick gauge of maintainability. libcue is a library to parse CUE sheets / files (metadata which describes how tracks of a CD or DVD are layed out). Stored as plain text and commonly have the .cue extension. Pars

[Bug 1790855] Re: [MIR] gpsd

2018-12-02 Thread Alex Murray
@cyphermox - this is assigned to the security team for security review but is still marked Incomplete from your questions earlier - plus looks like you also NAK'd it above - is this now ACK'd from your side or is it still blocked - and hence should I un-assign it from the security team? -- You re

[Bug 1784401] Re: [SRU] ceph 10.2.11

2018-09-04 Thread Alex Murray
This would also happen to fix 3 outstanding CVEs for ceph in Xenial as well: CVE-2018-10861, CVE-2018-1128, CVE-2018-1129 I was looking at backporting fixes for these to 10.2.10 but the commits which fix the actual CVEs seem to depend on a fair few other commits in between 10.2.10 and 10.2.11 so i

[Bug 1790496] Re: apparmor profile for gpsd

2018-09-05 Thread Alex Murray
@paelzer - from my experience with gpsd that looks pretty good regarding the file rules etc - hopefully someone else who is more intimately familiar with AppArmor can comment on the list of capabilities. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subsc

[Bug 1776996] Re: secureboot-db out of date, missing revocations from Aug 2016

2018-09-10 Thread Alex Murray
@vorlon - seems this might be causing a failure - see #1791248 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1776996 Title: secureboot-db out of date, missing revocations from Aug 2016 To manage no

[Bug 1256185] Re: [MIR] libsdl2

2018-09-10 Thread Alex Murray
Since qemu is off the list it looks like the primary motivation for this MIR is now gone - as such, the security team proposes we close this MIR and then if another team still wants libsdl2 in main, they should file a new MIR. -- You received this bug notification because you are a member of Ubun

[Bug 1791248] Re: package secureboot-db 1.2 failed to install/upgrade: installed secureboot-db package post-installation script subprocess returned error exit status 1

2018-09-10 Thread Alex Murray
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1791248 Title: package secureboot-db 1.2 failed to install/upgrade: installed secureboot-d

[Bug 1791893] Re: Trailing garbage data when sending on an AF_PACKET socket

2018-09-11 Thread Alex Murray
This looks a lot like #1783110 ** Information type changed from Private Security to Public ** Information type changed from Public to Private Security ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu B

[Bug 1798725] [NEW] Content "n\xff=" can crash libpcre when an application is matching the pattern \s*=

2018-10-18 Thread Alex Murray
*** This bug is a security vulnerability *** Public security bug reported: Reported upstream at https://bugs.exim.org/show_bug.cgi?id=2330 - libpcre3 can be made to crash when matching the pattern \s*= when the context is n\xff= Able to reproduce on current Bionic using the PoC attached (which i

[Bug 1798725] Re: Content "n\xff=" can crash libpcre when an application is matching the pattern \s*=

2018-10-25 Thread Alex Murray
** Attachment added: "PoC using libpcre (ie without libglib)" https://bugs.launchpad.net/ubuntu/+source/pcre3/+bug/1798725/+attachment/5205348/+files/PoC.c -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/

[Bug 1798725] Re: Content "n\xff=" can crash libpcre when an application is matching the pattern \s*=

2018-10-25 Thread Alex Murray
I have reworked the PoC to one which allows to reproduce the crash directly just using libpcre, and have verified this works directly on the upstream libpcre releases 8.39, 8.40, 8.41 & 8.42 - waiting on response from upstream - https://bugs.exim.org/show_bug.cgi?id=2330#c2 ** Bug watch added: bug

[Bug 1798725] Re: Content "n\xff=" can crash libpcre when an application is matching the pattern \s*=

2018-10-26 Thread Alex Murray
Seems this is a bug in gvfs not properly validating as UTF8 before calling into glib: https://bugs.exim.org/show_bug.cgi?id=2330#c9 ** Package changed: pcre3 (Ubuntu) => gvfs (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. ht

[Bug 1798725] Re: Content "n\xff=" can crash libpcre when an application is matching the pattern \s*=

2018-10-29 Thread Alex Murray
This was fixed in upstream commit https://gitlab.gnome.org/GNOME/gvfs/commit/a23eb6f14eb3cffa1585d4e5e566f779337d1e04 Uncertain whether this qualifies as a security issue - there doesn't seem to be any real security impact from the bug - so unmarking this as a security issue now. ** Information t

[Bug 1800662] Re: CVE-2017-1000083 is still present on atril

2018-10-31 Thread Alex Murray
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1800662 Title: CVE-2017-183 is still present on atril To manage notifications

[Bug 1798725] Re: gvfs may crash when parsing non-valid UTF8 in autorun.inf

2018-11-13 Thread Alex Murray
@Seb - so there is an autorun.inf in the original tarball which can be used (I will attach it separately here as well) - and this reproduces the crash for me - I just copied it to a FAT formatted USB drive, plugged it in and then in dmesg: [ 40.361136] gvfs-udisks2-vo[1563]: segfault at 7f3c60a4

[Bug 1798725] Re: gvfs may crash when parsing non-valid UTF8 in autorun.inf

2018-11-13 Thread Alex Murray
@Seb - also I rebuilt gvfs locally for bionic with that upstream patch added and can confirm it does not segfault after that - would be happy to test your SRUd version and confirm it as well if needed. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscri

[Bug 1803132] Re: virtualbox 0day exploit

2018-11-14 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 1803595] Re: Dash to dock visable from GDM lock screen after locking

2018-11-18 Thread Alex Murray
*** This bug is a duplicate of bug 1769383 *** https://bugs.launchpad.net/bugs/1769383 Thank you for taking the time to report this bug and helping to make Ubuntu better. This particular bug has already been reported and is a duplicate of bug 1769383, so it is being marked as such. Please look

[Bug 1798725] Re: gvfs may crash when parsing non-valid UTF8 in autorun.inf

2018-11-20 Thread Alex Murray
Tested the version from cosmic-proposed in an up-to-date VM and it failed - looks like this is not actually applied during the build - see the build log https://launchpadlibrarian.net/398362236/buildlog_ubuntu- cosmic-amd64.gvfs_1.38.1-0ubuntu1_BUILDING.txt.gz and notice it is never listed during u

[Bug 1798725] Re: gvfs may crash when parsing non-valid UTF8 in autorun.inf

2018-11-20 Thread Alex Murray
Tested the version from bionic-proposed in an up-to-date VM and it passed Steps to test locally as follows: 1. Enabled bionic-proposed 2. sudo apt-get dist-upgrade 3. sudo reboot On next boot with the autorun.inf on a local USB drive: $ dmesg | grep gvfs $ apt-cache policy gvfs gvfs: Installe

[Bug 1798725] Re: gvfs may crash when parsing non-valid UTF8 in autorun.inf

2018-11-21 Thread Alex Murray
Tested the new version in cosmic-proposed on an up-to-date cosmic VM by inserting a USB drive with the attached autorun.inf and it passes. Steps to test locally as follows: 1. Enabled cosmic-proposed 2. sudo apt-get dist-upgrade 3. sudo reboot On next boot with the autorun.inf on a local USB dri

[Bug 1800715] Re: Prompt for credential when it shouldn't

2018-11-22 Thread Alex Murray
The security team consider the existing behaviour is fine - ie. automatically connect without authentication when an admin session is logged in and is an active seat (ie. the screen / session is not switched to some other users sessions / VT), and the screen is unlocked. If someone has direct phys

[Bug 1801410] Re: Icons.keep.flashing

2018-11-05 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1801383] Re: apport uploading WifiSyslog to public bug reports is a major privacy risk

2018-11-05 Thread Alex Murray
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1801383 Title: apport uploading WifiSyslog to public bug reports is a major privacy

[Bug 1795921] Re: Out-of-Bounds write in systemd-networkd dhcpv6 option handling

2018-11-05 Thread Alex Murray
@yassine-mrabet - In general, Ubuntu does not upgrade major versions of software and instead backports security fixes to the current version - also we track CVEs independently in our own CVE tracker - in this case please see https://people.canonical.com/~ubuntu- security/cve/2018/CVE-2018-15688.htm

[Bug 1802160] Re: liblivemedia62 and liblivemedia64 probably have CVE-2018-4013 security problem

2018-11-07 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 1802349] Re: video is not playing in the default player and ear phone sound is not working

2018-11-08 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1768984] Re: CVE-2018-10115 impacts p7zip-rar

2018-11-08 Thread Alex Murray
@amribrahim1987 if you could please attach a debdiff we can look at trying to sponsor it. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1768984 Title: CVE-2018-10115 impacts p7zip-rar To manage not

[Bug 1802464] Re: package openvswitch-testcontroller 2.5.5-0ubuntu0.16.04.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2018-11-11 Thread Alex Murray
*** This bug is a duplicate of bug 1802463 *** https://bugs.launchpad.net/bugs/1802463 Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a

[Bug 1802600] Re: ??????

2018-11-11 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1802981] Re: Lockscreen shown dash when screen was locked

2018-11-12 Thread Alex Murray
*** This bug is a duplicate of bug 1769383 *** https://bugs.launchpad.net/bugs/1769383 Thank you for taking the time to report this bug and helping to make Ubuntu better. This particular bug has already been reported and is a duplicate of bug 1769383, so it is being marked as such. Please look

[Bug 1709164] Re: [MIR] bubblewrap

2018-09-14 Thread Alex Murray
y etc. if it were somehow to be compromised). ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-5226 ** Changed in: bubblewrap (Ubuntu) Assignee: Alex Murray (alexmurray) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 1709164] Re: [MIR] bubblewrap

2018-09-15 Thread Alex Murray
Ah ok thanks - sorry I somehow missed those details in comment 4 - cheers. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1709164 Title: [MIR] bubblewrap To manage notifications about this bug go to

[Bug 1790377] Re: Ubuntu 18.04.1 and below: Information disclosure through world readable by default home directory permissions

2018-09-17 Thread Alex Murray
*** This bug is a duplicate of bug 48734 *** https://bugs.launchpad.net/bugs/48734 ** This bug has been marked a duplicate of bug 48734 Home permissions too open ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a m

[Bug 1240234] Re: phablet in android_input group which gives rw access to /dev/input/event* and /dev/rfkill

2018-09-17 Thread Alex Murray
** Changed in: android (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1240234 Title: phablet in android_input group which gives rw access to /dev/input/even

[Bug 1371170] Re: information disclosure: clipboard contents can be obtained without user knowledge

2018-09-17 Thread Alex Murray
** Changed in: content-hub (Ubuntu) Status: New => Won't Fix ** Changed in: mir (Ubuntu) Status: New => Confirmed ** Changed in: canonical-devices-system-image Status: Confirmed => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which

[Bug 1510317] Re: Shell Command Injection in "Mailcap" file handling

2018-09-17 Thread Alex Murray
** Changed in: python3.5 (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1510317 Title: Shell Command Injection in "Mailcap" file handling To manage notificat

[Bug 1483037] Re: Possible Shell Command Injection in daemon

2018-09-17 Thread Alex Murray
** Changed in: unity-scope-audacious (Ubuntu) Status: New => Confirmed ** Changed in: unity-scope-clementine (Ubuntu) Status: New => Confirmed ** Changed in: unity-scope-gmusicbrowser (Ubuntu) Status: New => Confirmed ** Changed in: unity-scope-gourmet (Ubuntu) Status

[Bug 1532314] Re: Buffer overflow in cgmanager

2018-09-17 Thread Alex Murray
Based on the most recent comments, changing the priority back to undecided since there is no clear path forward for now. ** Changed in: libnih (Ubuntu) Importance: High => Undecided ** Changed in: lxc (Ubuntu) Importance: High => Undecided ** Changed in: cgmanager (Ubuntu) Status: N

[Bug 1792148] Re: adopt PHP 7.2.8+ to fix vulnerability in php-fpm

2018-09-17 Thread Alex Murray
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1792148 Title: adopt PHP 7.2.8+ to fix vulnerability in php-fpm To manage notifica

[Bug 1792176] Re: package kismet 2013.03.R1b-3build1 failed to install/upgrade: underproces installerede post-installation-script returnerede afslutningsstatus 6

2018-09-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1792241] Re: package systemd-sysv 237-3ubuntu10.3 failed to install/upgrade: installed systemd-shim package post-removal script subprocess returned error exit status 2

2018-09-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1792312] Re: package libx11-data 2:1.6.3-1ubuntu2.1 failed to install/upgrade: package libx11-data is already installed and configured

2018-09-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1792500] Re: package docker.io 17.12.1-0ubuntu1 failed to install/upgrade: installed docker.io package post-installation script subprocess returned error exit status 1

2018-09-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1791643] Re: I install, and then a few days later the whole thing crashes

2018-09-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1791954] Re: gnome-tweaks crashed with AttributeError in /usr/lib/python3/dist-packages/gtweak/tweaks/tweak_group_general.py: 'NoneType' object has no attribute 'mode'

2018-09-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1791477] Re: Thunderbird Multiple Security Vulnerabilities

2018-09-17 Thread Alex Murray
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1791477 Title: Thunderbird Multiple Security Vulnerabilities To manage notificatio

[Bug 1792135] Re: jackd crashed with SIGABRT in std::terminate()

2018-09-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1791438] Re: package snort (not installed) failed to install/upgrade: installed snort package post-installation script subprocess returned error exit status 1

2018-09-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1791433] Re: Path traversal vulnerability

2018-09-17 Thread Alex Murray
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1791433 Title: Path traversal vulnerability To manage notifications about this bug

[Bug 1791415] Re: package firefox-locale-en 62.0+build2-0ubuntu0.16.04.3 failed to install/upgrade: package firefox-locale-en is already installed and configured

2018-09-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1791406] Re: cannot install grub-eif-amd64-signed to /target

2018-09-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1791414] Re: package firefox-locale-en 62.0+build2-0ubuntu0.16.04.3 failed to install/upgrade: package firefox-locale-en is already installed and configured

2018-09-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1791405] Re: bluetooth always in discoverable mode (security issue)

2018-09-17 Thread Alex Murray
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1791405 Title: bluetooth always in discoverable mode (security issue) To manage no

[Bug 1792938] Re: PHP 7.2.7 contains various security issues.

2018-09-17 Thread Alex Murray
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1792938 Title: PHP 7.2.7 contains various security issues. To manage notifications

[Bug 1792953] Re: Security issue with PHP < 7.0.32 on Xenial

2018-09-17 Thread Alex Murray
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1792953 Title: Security issue with PHP < 7.0.32 on Xenial To manage notifications

[Bug 1793019] Re: package postgresql-10 10.5-0ubuntu0.18.04 failed to install/upgrade: installed postgresql-10 package pre-removal script subprocess returned error exit status 2

2018-09-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1792996] Re: idk

2018-09-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1793144] Re: package samba 2:4.7.6+dfsg~ubuntu-0ubuntu2.2 failed to install/upgrade: installed samba package post-installation script subprocess returned error exit status 1

2018-09-18 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1793174] Re: ndiswrapper-dkms 1.59-2: ndiswrapper kernel module failed to build

2018-09-18 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1793287] Re: network-manager can not save changes with option "Ask for this password every time" option when using WPA 2 Personal

2018-09-19 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1792967] Re: CVE-2018-7738 - command execution via unmount's bash-completion

2018-09-20 Thread Alex Murray
** Changed in: util-linux (Ubuntu) Status: New => Confirmed ** Changed in: util-linux (Ubuntu) Importance: Undecided => Low -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1792967 Title: CV

[Bug 1793607] Re: GPU Overheats and laptop shuts off

2018-09-20 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1793899] Re: package samba 2:4.7.6+dfsg~ubuntu-0ubuntu2.2 failed to install/upgrade: installed samba package post-installation script subprocess returned error exit status 1

2018-09-22 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1793973] Re: package gnome-menus 3.13.3-6ubuntu3.1 failed to install/upgrade: triggers looping, abandoned

2018-09-23 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1820798] Re: hardening-check: add support for detecting stack clash protected binaries

2019-04-09 Thread Alex Murray
The attached should is more robust to optimisation in gcc and is updated against the latest devscripts in disco ** Patch added: "devscripts_2.19.4ubuntu0.1.debdiff" https://bugs.launchpad.net/ubuntu/+source/devscripts/+bug/1820798/+attachment/5254407/+files/devscripts_2.19.4ubuntu0.1.debdiff

[Bug 1820798] Re: hardening-check: add support for detecting stack clash protected binaries

2019-04-09 Thread Alex Murray
Relaxed some of the checks to find additional stack-clash-protected binaries due to more optimisation shenanigans ** Patch added: "devscripts_2.19.4ubuntu0.1.debdiff" https://bugs.launchpad.net/ubuntu/+source/devscripts/+bug/1820798/+attachment/5254597/+files/devscripts_2.19.4ubuntu0.1.debdiff

[Bug 1854362] Re: [MIR] ceph-iscsi, tcmu, python-configshell-fb, python-rtslib-fb, urwid

2020-02-17 Thread Alex Murray
targetcli-fb has not been mentioned previously and is not a task on this bug - does it need to be added? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1854362 Title: [MIR] ceph-iscsi, tcmu, python-c

[Bug 1843403] Re: [MIR] nfs-ganesha, ntirpc

2020-02-17 Thread Alex Murray
I reviewed ntirpc 3.0-0ubuntu2 as checked into focal. This shouldn't be considered a full audit but rather a quick gauge of maintainability. ntirpc is a fork of the existing libtirpc library providing RPC services for nfs-ganesha and others. - CVE History: - Only 1 past CVEs against ntirpc

[Bug 1843403] Re: [MIR] nfs-ganesha, ntirpc

2020-02-17 Thread Alex Murray
** Attachment added: "ntirpc coverity defect results" https://bugs.launchpad.net/ubuntu/+source/ntirpc/+bug/1843403/+attachment/5329131/+files/coverity.txt ** Changed in: ntirpc (Ubuntu) Assignee: Ubuntu Security Team (ubuntu-security) => (unassigned) -- You received this bug notificati

[Bug 1862600] Re: sensitive config files are world-readable

2020-02-17 Thread Alex Murray
** Information type changed from Public to Public Security ** Tags removed: community-security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862600 Title: sensitive config files are world-readable

[Bug 1854362] Re: [MIR] ceph-iscsi, tcmu, python-configshell-fb, python-rtslib-fb, urwid, targetcli-fb

2020-02-20 Thread Alex Murray
I reviewed python-configshell-fb 1.1.fb25-1.1 as checked into focal. This shouldn't be considered a full audit but rather a quick gauge of maintainability. python-configshell-fb provides a python library which is used for building CLI based user-interfaces. Upstream appears healthy and responsive

[Bug 1815991] Re: [MIR] masakari and masakari-monitors

2020-02-24 Thread Alex Murray
I reviewed masakari 9.0.0~b2~git2020020609.8b122a8-0ubuntu2 as checked into focal. This shouldn't be considered a full audit but rather a quick gauge of maintainability. masakari is a OpenStack component providing a high availability service for instances - this allows KVM-based virtual machine i

<    1   2   3   4   5   6   7   8   9   10   >