[Bug 2102129] Re: Fix for CVE-2025-27516 regressed jinja in Python2 on focal and bionic ESM

2025-03-12 Thread John Breton
** Summary changed: - Fix for CVE-2025-27516 regressed jinja in Python2 on focal and previous releases (ESM) + Fix for CVE-2025-27516 regressed jinja in Python2 on focal and bionic ESM -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2102129] Re: Fix for CVE-2025-27516 regressed jinja in Python2 on focal

2025-03-12 Thread John Breton
Thank you for the feedback thus far on this. For trusty and xenial I accounted for Python 2 compatibility and wrote a backport of getattr_static: ``` def getattr_static_py2(obj, attr, default=None): """ Mimic getattr_static from Python 3 in Python 2.7. """ for cls in inspect.getmro(type(obj)

[Bug 2102129] Re: Fix for CVE-2025-27516 regressed jinja in Python2 on focal and bionic ESM

2025-03-12 Thread John Breton
This update has now been pushed as of the publication of USN 7343-2: https://ubuntu.com/security/notices/USN-7343-2 The relevant fixes can be grabbed on bionic (available with Ubuntu Pro) and focal via a standard system update. Thank you all for your help in investigating this issue and for confi

[Bug 2103420] Re: Security issue with libsaml12

2025-03-20 Thread John Breton
Hi, thank you for the initial report and an additional thanks for providing a debdiff for Noble. A fix for affected releases is in progress. Once we have further updates we will share them here. ** Changed in: opensaml (Ubuntu) Assignee: (unassigned) => John Breton (john-breton) ** Chan

[Bug 2103420] Re: Security issue with libsaml12

2025-03-20 Thread John Breton
** Also affects: opensaml2 (Ubuntu) Importance: Undecided Status: New ** Changed in: opensaml2 (Ubuntu) Status: New => In Progress ** Changed in: opensaml2 (Ubuntu) Assignee: (unassigned) => John Breton (john-breton) -- You received this bug notification because you

[Bug 2103420] Re: Security issue with libsaml12

2025-03-21 Thread John Breton
** Changed in: opensaml2 (Ubuntu Trusty) Status: In Progress => Invalid ** Changed in: opensaml2 (Ubuntu) Status: In Progress => Fix Committed ** Changed in: opensaml2 (Ubuntu Trusty) Assignee: John Breton (john-breton) => (unassigned) -- You received this bug not

[Bug 2103420] Re: Security issue with libsaml12

2025-03-25 Thread John Breton
** Changed in: opensaml2 (Ubuntu Xenial) Status: Fix Committed => Fix Released ** Changed in: opensaml2 (Ubuntu Xenial) Assignee: John Breton (john-breton) => (unassigned) ** Changed in: opensaml2 (Ubuntu Bionic) Status: Fix Committed => Fix Released ** Changed in:

[Bug 2103420] Re: Security issue with libsaml12

2025-03-20 Thread John Breton
** Changed in: opensaml2 (Ubuntu Bionic) Status: Confirmed => In Progress ** Changed in: opensaml2 (Ubuntu Bionic) Assignee: (unassigned) => John Breton (john-breton) ** Changed in: opensaml2 (Ubuntu Xenial) Status: Confirmed => In Progress ** Changed in: opensaml

[Bug 2103420] Re: Security issue with libsaml12

2025-03-20 Thread John Breton
Fixes for Xenial, Bionic, Focal, Jammy, Noble, Oracular, and Plucky have been committed and are currently being built. They are pending publication. ** Changed in: opensaml2 (Ubuntu Xenial) Status: In Progress => Fix Committed ** Changed in: opensaml2 (Ubuntu Bionic) Status: In Prog

[Bug 2103420] Re: Security issue with libsaml12

2025-03-25 Thread John Breton
** Changed in: opensaml (Ubuntu Oracular) Assignee: John Breton (john-breton) => (unassigned) ** Changed in: opensaml (Ubuntu Noble) Assignee: John Breton (john-breton) => (unassigned) ** Changed in: opensaml (Ubuntu Jammy) Assignee: John Breton (john-breton) => (u

[Bug 2103420] Re: Security issue with libsaml12

2025-03-25 Thread John Breton
We appreciate your patience on this issue thus far. Fixes have been released for OpenSAML2 on Xenial and Bionic and for OpenSAML on Focal, Jammy, Noble, and Oracular. We will provide another update once a fix has been released for Plucky. -- You received this bug notification because you are a me

[Bug 2103420] Re: Security issue with libsaml12

2025-03-27 Thread John Breton
We have published a USN for this issue: https://ubuntu.com/security/notices/USN-7364-1 We recommend upgrading to the latest available version. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/210

[Bug 2103420] Re: Security issue with libsaml12

2025-03-26 Thread John Breton
** Changed in: opensaml (Ubuntu Plucky) Status: Fix Committed => Fix Released ** Changed in: opensaml (Ubuntu Plucky) Assignee: John Breton (john-breton) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to t

[Bug 2068805] Re: [SRU] "Install Now" button disappears for good if all packages unselected and Ubuntu Pro packages are shown but unavailable

2025-03-27 Thread John Breton
Xenial and Bionic have been uploaded to our esm-infra-updates-staging PPA. We are just waiting for this SRU to be published in the archive first for the other releases. ** Changed in: update-manager (Ubuntu Xenial) Status: Confirmed => Fix Committed ** Changed in: update-manager (Ubuntu Bi

[Bug 2104925] Re: Version 2.0.0.2-2ubuntu1.3+esm5 fails to install on Xenial

2025-03-28 Thread John Breton
resolves the issue or if any other issues arise. ** Changed in: ansible (Ubuntu) Status: Confirmed => Fix Released ** Changed in: ansible (Ubuntu) Assignee: John Breton (john-breton) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 2104925] Re: Version 2.0.0.2-2ubuntu1.3+esm5 fails to install on Xenial

2025-03-28 Thread John Breton
The issue has been confirmed to only impact xenial. One of the newly introduced files created as part of backporting a patch appears to have been cut off incorrectly, leading to the indentation error. A fix is underway. -- You received this bug notification because you are a member of Ubuntu Bugs

[Bug 2104925] Re: Version 2.0.0.2-2ubuntu1.3+esm5 fails to install on Xenial

2025-03-28 Thread John Breton
** Changed in: ansible (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2104925 Title: Version 2.0.0.2-2ubuntu1.3+esm5 fails to install on Xenial To manage not

[Bug 2104925] Re: Version 2.0.0.2-2ubuntu1.3+esm5 fails to install on Xenial

2025-03-28 Thread John Breton
** Changed in: ansible (Ubuntu) Assignee: (unassigned) => John Breton (john-breton) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2104925 Title: Version 2.0.0.2-2ubuntu1.3+esm5 fails