[Bug 2067742] Re: [SRU] CVE-2024-36041 Fix ksmserver: Unauthorized users can access session manager

2024-06-19 Thread Marc Deslauriers
I have built packages in the security team proposed PPA for testing. Additional packages required no-change rebuilds in the -security pocket also. For Jammy, the additional packages are breeze, libksysguard, layer-shell-qt, kwin, kwayland-server. For Focal, the additional packages are kwin and bree

[Bug 2067742] Re: [SRU] CVE-2024-36041 Fix ksmserver: Unauthorized users can access session manager

2024-06-18 Thread Marc Deslauriers
ACK on the debdiffs, packages are building now! -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to plasma-workspace in Ubuntu. https://bugs.launchpad.net/bugs/2067742 Title: [SRU] CVE-2024-36041 Fix ksmserver: Unauthorized users can access

[Bug 2046653] Re: kioslave5 assert failure: *** buffer overflow detected ***: terminated

2024-01-19 Thread Marc Deslauriers
** Changed in: kio (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to kio in Ubuntu. https://bugs.launchpad.net/bugs/2046653 Title: kioslave5 assert failure: *** buffer overflow detected ***: terminate

[Bug 1971242] Re: printing PDF appears always grey, no color

2023-09-12 Thread Marc Deslauriers
I have tested the lunar-proposed package (2.4.2-3ubuntu2.3), and after updating the package, and recreating the printer, it now defaults to printing in colour when using Okular. ** Tags removed: verification-needed verification-needed-lunar ** Tags added: verification-done verification-done-lunar

[Bug 1971242] Re: printing PDF appears always grey, no color

2023-06-22 Thread Marc Deslauriers
Unfortunately the package in -proposed was superseded by a security update, and will need to be updated again. -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to okular in Ubuntu. https://bugs.launchpad.net/bugs/1971242 Title: printing PDF ap

[Bug 1989823] Re: plasmashell crashed with SIGSEGV in QQuickItem::~QQuickItem()

2022-09-16 Thread Marc Deslauriers
** Attachment removed: "CoreDump.gz" https://bugs.launchpad.net/ubuntu/+source/plasma-workspace/+bug/1989823/+attachment/5616227/+files/CoreDump.gz ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Kubuntu Bugs, whic

[Bug 1962862] Re: usb creator crashes on startup

2022-03-04 Thread Marc Deslauriers
Great, I uploaded a new package to jammy a few minutes ago. -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1962862 Title: usb creator crashes on startup To manage notifications about this b

[Bug 1962862] Re: usb creator crashes on startup

2022-03-04 Thread Marc Deslauriers
usbcreator/misc.py, line 44 probably needs to change from: return isinstance(obj, collections.Callable) to return isinstance(obj, collections.abc.Callable) I'll install jammy and test it when I get a minute. -- You received this bug notification because you are a member of Kub

[Bug 1768649] Re: [CVE] Access to privileged files

2018-05-24 Thread Marc Deslauriers
Since there is no actionable item to be sponsored here, unsubscribing the ubuntu-security-sponsors. If someone adds a new debdiff to this bug, please subscribe ubuntu-security-sponsors again. Thanks! -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscrib

[Bug 1696015] Re: package kmail (not installed) failed to install/upgrade: a tentar sobre-escrever '/usr/bin/mboximporter', que também está no pacote mbox-importer 16.12.3-0ubuntu1~ubuntu17.04~ppa2

2017-06-09 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1689759] Re: CVE 2017-8422 - kauth: Local privilege escalation

2017-05-15 Thread Marc Deslauriers
** Changed in: kde4libs (Ubuntu Trusty) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to kauth in Ubuntu. https://bugs.launchpad.net/bugs/1689759 Title: CVE 2017-8422 - kauth: Local privilege escal

[Bug 1668552] Re: KDE Project Security Advisory: ktnef: Directory Traversal

2017-04-06 Thread Marc Deslauriers
Since there is nothing left to sponsor, I am unsubscribing ubuntu- security-sponsors. Please re-subscribe the group when attaching another debdiff. Thanks! -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to kdepim in Ubuntu. https://bugs.launchp

[Bug 1668871] Re: kio: Information Leak when accessing https when using a malicious PAC file

2017-03-02 Thread Marc Deslauriers
ACK on the debdiffs in comments #9 and #10. Packages are building with a changelog whitespace and pocket change and will be released as security updates. Thanks! -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to kde4libs in Ubuntu. https://bugs

[Bug 1668871] Re: kio: Information Leak when accessing https when using a malicious PAC file

2017-03-01 Thread Marc Deslauriers
There was no build log, probably a launchpad failure. I've mashed the retry button. -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to kde4libs in Ubuntu. https://bugs.launchpad.net/bugs/1668871 Title: kio: Information Leak when accessing htt

[Bug 1655507] Re: CVE-2017-5330 - Ark: unintended execution of scripts and executable files

2017-01-17 Thread Marc Deslauriers
Subscribing ubuntu-security-sponsors so this gets looked at. -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to ark in Ubuntu. https://bugs.launchpad.net/bugs/1655507 Title: CVE-2017-5330 - Ark: unintended execution of scripts and executable

[Bug 1633855] Re: akonadi fails to start after upgrade to yakkety

2016-10-28 Thread Marc Deslauriers
** No longer affects: mysql-5.5 (Ubuntu) -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to akonadi in Ubuntu. https://bugs.launchpad.net/bugs/1633855 Title: akonadi fails to start after upgrade to yakkety To manage notifications about this

[Bug 1633855] Re: akonadi fails to start after upgrade to yakkety

2016-10-28 Thread Marc Deslauriers
Lars, Akonadi is failing because of the new secure_file_priv default location. Since akonadi doesn't install the full mysql-server-5.5 package, but only the mysql-server-core-5.5 package, the secure_file_priv directory isn't created, and mysql won't start. This was fixed by having Akonadi set the

[Bug 1633855] Re: akonadi fails to start after upgrade to yakkety

2016-10-27 Thread Marc Deslauriers
After installing updated akonadi packages, users may still be required to remove their ~/.local/share/akonadi/mysql.conf file to get the system one copied over again. -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to akonadi in Ubuntu. https://

[Bug 1633855] Re: akonadi fails to start after upgrade to yakkety

2016-10-27 Thread Marc Deslauriers
onadi (Ubuntu Precise) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: akonadi (Ubuntu Trusty) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to akonad

[Bug 1630700] Re: CVE - KMail - HTML injection in plain text viewer

2016-10-12 Thread Marc Deslauriers
Unsubscribing ubuntu-security-sponsors for now since there is nothing to sponsor. Once a debdiff is attached, please re-subscribe the group. Thanks! ** Changed in: kcoreaddons (Ubuntu Trusty) Status: New => Fix Released ** Changed in: kcoreaddons (Ubuntu Precise) Status: In Progress

[Bug 1629704] Re: konqueror crashed with signal 5 in g_main_context_dispatch()

2016-10-06 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1567851] Re: kdenlive crashed with SIGSEGV in mlt_filter_process()

2016-04-08 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1554656] Re: plasma-workspace CVE-2016-2312

2016-03-08 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to plasma-workspace in Ubuntu. https://bugs.launchpad.net/bugs/1554656 Title: plasma-workspace CVE-2016-2312 To manage notif

[Bug 1505249] Re: package libkresources4 4:4.14.6-0ubuntu1 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration

2015-10-29 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1393479] Re: security: Insufficient Input Validation By IO Slaves and Webkit Part

2014-11-24 Thread Marc Deslauriers
** Changed in: kio-extras (Ubuntu Precise) Status: New => Invalid ** Changed in: kio-extras (Ubuntu Trusty) Status: New => Invalid ** Changed in: kio-extras (Ubuntu Utopic) Status: New => Invalid -- You received this bug notification because you are a member of Kubuntu Bugs

[Bug 1389665] Re: privilage escalation in clock kcontrol

2014-11-17 Thread Marc Deslauriers
** Changed in: kde-workspace (Ubuntu Vivid) Status: New => Invalid -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to kde-workspace in Ubuntu. https://bugs.launchpad.net/bugs/1389665 Title: privilage escalation in clock kcontrol To ma

[Bug 1350019] Re: CVE-2014-5033: kauth authentication bypass

2014-07-30 Thread Marc Deslauriers
ACK on the debdiffs. Building now, thanks! ** Changed in: kde4libs (Ubuntu Precise) Status: New => In Progress ** Changed in: kde4libs (Ubuntu Trusty) Status: New => In Progress -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to

[Bug 1292487] Re: ubuntu-sdk can't resolve symbols

2014-03-14 Thread Marc Deslauriers
Looks like libdbusmenu-qt was built against qt 5.2.1, which is still in -proposed ** Package changed: ubuntu-touch-meta (Ubuntu) => libdbusmenu-qt (Ubuntu) ** Summary changed: - ubuntu-sdk can't resolve symbols + libdbusmenu-qt can't resolve symbols -- You received this bug notification becaus

[Bug 1179380] Re: paste widget "password" generator uses (very) insecure randomness

2013-08-16 Thread Marc Deslauriers
This issue has been rated "low" by the security team, so a fix for this issue will be bundled in the next security update that contains a "medium" or higher. Unsubscribing sponsors for now. -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to kde

[Bug 1172519] Re: package kdelibs5-data (not installed) failed to install/upgrade: sub-processo novo script pre-installation retornou estado de saída de erro 1

2013-04-30 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1078412] Re: package libkdewebkit5 4:4.9.2-0ubuntu3 failed to install/upgrade: package libkdewebkit5 is not ready for configuration cannot configure (current status `half-installed')

2012-11-15 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 933225] Re: DistUpgradeViewKDE broken since lastupdate

2012-02-15 Thread Marc Deslauriers
** Summary changed: - inability to QA utterly broke DistUpgradeViewKDE + DistUpgradeViewKDE broken since lastupdate ** Summary changed: - DistUpgradeViewKDE broken since lastupdate + DistUpgradeViewKDE broken since last security update -- You received this bug notification because you are a me

[Bug 933225] Re: inability to QA utterly broke DistUpgradeViewKDE

2012-02-15 Thread Marc Deslauriers
: update-manager (Ubuntu Maverick) Importance: Undecided Status: New ** Also affects: update-manager (Ubuntu Precise) Importance: Critical Assignee: Marc Deslauriers (mdeslaur) Status: Triaged ** Changed in: update-manager (Ubuntu Hardy) Status: New => Confir

[Bug 798438] Re: rekonq is still vulnerable to CSS history fishing.

2011-07-06 Thread Marc Deslauriers
** Changed in: rekonq (Ubuntu) Importance: Undecided => Low ** Changed in: rekonq (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to rekonq in Ubuntu. https://bugs.launchpad.net/bugs/798438 Title:

[Bug 682670] Re: package libqt4-qt3support 4:4.6.2-0ubuntu5.1 failed to install/upgrade: underprocess dpkg-deb --fsys-tarfile gav felkod 2

2010-11-30 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 385999] Re: konsole leaks file descriptors for /tmp/kde-$USER/konsole*.tmp

2009-06-11 Thread Marc Deslauriers
** Bug watch added: Red Hat Bugzilla #484370 https://bugzilla.redhat.com/show_bug.cgi?id=484370 ** Also affects: kdebase via https://bugzilla.redhat.com/show_bug.cgi?id=484370 Importance: Unknown Status: Unknown ** Package changed: kdebase (Ubuntu) => kdelibs (Ubuntu) ** Bug watc

[Bug 318555] Re: integer overflows and unchecked allocation vulnerabilities

2009-01-19 Thread Marc Deslauriers
** Visibility changed to: Public -- integer overflows and unchecked allocation vulnerabilities https://bugs.launchpad.net/bugs/318555 You received this bug notification because you are a member of Kubuntu Bugs, which is subscribed to amarok in ubuntu. -- kubuntu-bugs mailing list kubuntu-bugs@l