[Bug 1698180] Re: [CVE] Send Later with Delay bypasses OpenPGP

2018-03-26 Thread Launchpad Bug Tracker
This bug was fixed in the package kdepim - 4:4.13.3-0ubuntu0.2 --- kdepim (4:4.13.3-0ubuntu0.2) trusty-security; urgency=medium * SECURITY UPDATE: Send Later with Delay bypasses OpenPGP (LP: #1698180): - fix-CVE-2017-9604.patch - CVE-2017-9604 -- Simon Quigley

[Bug 1698180] Re: [CVE] Send Later with Delay bypasses OpenPGP

2018-03-25 Thread Simon Quigley
I have uploaded these fixes (for Xenial and Trusty) to a fresh test PPA of mine with all architectures switched on and only the security repo enabled. I then tested both in VMs of each release, and they work as intended. It also fixes the security issue. Security Team, feel free to copy my

[Bug 1698180] Re: [CVE] Send Later with Delay bypasses OpenPGP

2017-08-21 Thread Simon Quigley
kdepim no longer exists in Artful, and fixes are in artful-proposed for kmail and kf5-messagelib (it's part of the new upstream release). ** Changed in: kdepim (Ubuntu Artful) Status: In Progress => Fix Committed ** Changed in: kdepim (Ubuntu Artful) Status: Fix Committed =>