[Touch-packages] [Bug 1549609] Re: Stack Corruption in PCRE 8.35

2016-03-30 Thread Marc Deslauriers
These should now be fixed by the following update: http://www.ubuntu.com/usn/usn-2943-1/ ** Changed in: pcre3 (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to pcre3 in Ubuntu. h

[Touch-packages] [Bug 1547133] Re: After automatically upgrading Xubuntu library libnss3 to version 2:3.21-0ubuntu0.15.10.1 some apps stop working

2016-03-24 Thread Marc Deslauriers
This is a bug in QtWebEngine. The file src/3rdparty/chromium/net/third_party/nss/patches/chacha20poly1305.patch contains the following: +/* This is a bodge to allow this code to be compiled against older NSS + * headers. */ +#ifndef CKM_NSS_CHACHA20_POLY1305 +#define CKM_NSS_CHACHA20_POLY1305

[Touch-packages] [Bug 1558114] Re: package libpam-modules 1.1.8-3.1ubuntu3.1 failed to install/upgrade: trying to overwrite shared '/usr/share/man/man8/pam_unix.8.gz', which is different from other in

2016-03-19 Thread Marc Deslauriers
** Also affects: pam (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: pam (Ubuntu Xenial) Importance: Critical Assignee: Marc Deslauriers (mdeslaur) Status: Triaged ** Changed in: pam (Ubuntu Precise) Status: New => Triaged ** Changed in:

[Touch-packages] [Bug 1543070] Re: Security breach: bubble displays message preview when screen is unlocked

2016-03-11 Thread Marc Deslauriers
** Changed in: messaging-app (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to messaging-app in Ubuntu. https://bugs.launchpad.net/bugs/1543070 Title: Security breach: bubble displays me

[Touch-packages] [Bug 1554935] Re: package libandroid-properties1 0.1.0+git20131207+e452e83-0ubuntu40~gcc5.1 failed to install/upgrade: package libandroid-properties1 is already installed and configur

2016-03-11 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1444656] Re: GnuTLS TLS 1.2 handshake failure

2016-03-10 Thread Marc Deslauriers
It looks like the servers listed in the bug description require SIGN- RSA-SHA384, which gnutls26 doesn't support. The issue can be reproduced with gnutls28 by disabling the additional signature algorithms: gnutls-cli --priority "NORMAL:-SIGN-ECDSA-SHA256:-SIGN-RSA-SHA384:-SIGN- ECDSA-SHA384:-SIGN

[Touch-packages] [Bug 1553819] Re: Regression in trusty's gnutls26, can't connect to servers with RSA-MD5 certs (cacert)

2016-03-06 Thread Marc Deslauriers
The point of the USN-2865-1 security update was to remove support for RSA-MD5 certificates which are considered insecure and were previously accepted in GnuTLS because of a design flaw. See the following for more information: http://lists.gnutls.org/pipermail/gnutls-devel/2015-April/007572.html h

[Touch-packages] [Bug 1551615] Re: Alternative chain verification failure after 1024b root CAs removal

2016-03-03 Thread Marc Deslauriers
Marcin, It looks like your bank renewed their SSL cert on Feb 9th, and they forgot to include the intermediate certificate. This is a configuration problem on their end and has nothing to do with Ubuntu updates. Tell them to go to the following page and type in ebank.db-pbc.pl for more informati

[Touch-packages] [Bug 1551615] Re: Alternative chain verification failure after 1024b root CAs removal

2016-03-01 Thread Marc Deslauriers
Glad that it's working, thanks! I'm closing this bug. ** Changed in: ca-certificates (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ca-certificates in Ubuntu. https://bugs.launc

[Touch-packages] [Bug 1551615] Re: Alternative chain verification failure after 1024b root CAs removal

2016-03-01 Thread Marc Deslauriers
We released updated openssl packages to handle that case: http://www.ubuntu.com/usn/usn-2913-3/ What version of openssl do you have installed? What specific site are you unable to access? ** Changed in: ca-certificates (Ubuntu) Status: New => Incomplete -- You received this bug notifica

[Touch-packages] [Bug 1550423] Re: ERR_SSL_PROTOCOL_ERROR

2016-02-27 Thread Marc Deslauriers
Chrome 45 is too old. You need to update to Chrome 47 or later, preferably to the current version, Chrome 48. I am closing this bug as running an old version of Chrome is not supported. ** Changed in: nss (Ubuntu) Status: Incomplete => Won't Fix -- You received this bug notification beca

[Touch-packages] [Bug 1550643] Re: Please backport OpenSSL SNI signature algorithms fix.

2016-02-27 Thread Marc Deslauriers
tus: New => Confirmed ** Changed in: openssl (Ubuntu Precise) Importance: Undecided => Medium ** Changed in: openssl (Ubuntu Trusty) Importance: Undecided => Medium ** Changed in: openssl (Ubuntu Precise) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Chan

[Touch-packages] [Bug 1528645] Re: Please update ca-certificates on Trusty

2016-02-26 Thread Marc Deslauriers
You need to restart everything that uses libssl, perhaps only the web server, you'll see when you try it. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ca-certificates in Ubuntu. https://bugs.launchpad.net/bugs/1528645 Titl

[Touch-packages] [Bug 1528645] Re: Please update ca-certificates on Trusty

2016-02-26 Thread Marc Deslauriers
Did you restart your server after the update in order to use the new version of libssl? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ca-certificates in Ubuntu. https://bugs.launchpad.net/bugs/1528645 Title: Please update

[Touch-packages] [Bug 1550423] Re: ERR_SSL_PROTOCOL_ERROR

2016-02-26 Thread Marc Deslauriers
What version of Chrome are you running? ** Package changed: ca-certificates (Ubuntu) => nss (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ca-certificates in Ubuntu. https://bugs.launchpad.net/bugs/1550423 Title:

[Touch-packages] [Bug 1549709] Re: getting "unable to get local issuer certificate" for valid domains after upgrading to 20160104ubuntu0.14.04.1

2016-02-25 Thread Marc Deslauriers
Thanks! I've closed the bug. ** Changed in: ca-certificates (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ca-certificates in Ubuntu. https://bugs.launchpad.net/bugs/1549709 Tit

[Touch-packages] [Bug 1549709] Re: getting "unable to get local issuer certificate" for valid domains after upgrading to 20160104ubuntu0.14.04.1

2016-02-25 Thread Marc Deslauriers
The openssl tools in Ubuntu 14.04 never did use the system CA file by default. That was fixed in later releases. So it's normal that you don't need to specify it manually when using 15.10 for example, but do need to specify it in 14.04. The path to it has always been /etc/ssl/certs/ca-certificates

[Touch-packages] [Bug 1549709] Re: getting "unable to get local issuer certificate" for valid domains after upgrading to 20160104ubuntu0.14.04.1

2016-02-25 Thread Marc Deslauriers
Your example command doesn't work. You need to tell openssl where the certificate store is, like so: echo | openssl s_client -CAfile /etc/ssl/certs/ca-certificates.crt -connect www.google.com:443 What version is your openssl package? Please do: apt-cache policy libssl1.0.0 Thanks. ** Changed i

[Touch-packages] [Bug 1528645] Re: Please update ca-certificates on Trusty

2016-02-24 Thread Marc Deslauriers
ca-certificates is now updated in all stable releases: http://www.ubuntu.com/usn/usn-2913-1/ ** Changed in: ca-certificates (Ubuntu Precise) Status: Confirmed => Fix Released ** Changed in: ca-certificates (Ubuntu Trusty) Status: Confirmed => Fix Released ** Changed in: ca-certifi

[Touch-packages] [Bug 1528645] Re: Please update ca-certificates on Trusty

2016-02-24 Thread Marc Deslauriers
rtificates (Ubuntu Wily) Importance: Undecided => Low ** Changed in: ca-certificates (Ubuntu Precise) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: ca-certificates (Ubuntu Trusty) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: c

[Touch-packages] [Bug 1546459] Re: segfault at b774bd9d ip b7352a0d sp bfda8f30 error 7 in libresolv-2.19.so[b7349000+13000]

2016-02-23 Thread Marc Deslauriers
@born2chill: It is fixed by using the mini.iso in trusty-updates. Please use the links in comment #10. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to eglibc in Ubuntu. https://bugs.launchpad.net/bugs/1546459 Title: segfau

[Touch-packages] [Bug 1546459] Re: segfault at b774bd9d ip b7352a0d sp bfda8f30 error 7 in libresolv-2.19.so[b7349000+13000]

2016-02-18 Thread Marc Deslauriers
I can reproduce this issue with the mini.iso from the release version of 14.04. Could you please try again with the newer mini.iso from trusty-updates (available here:) http://archive.ubuntu.com/ubuntu/dists/trusty-updates/main/installer-amd64/current/images/netboot/mini.iso http://archive.ubuntu

[Touch-packages] [Bug 1547147] Re: libnss3-dev adds epoch 2 to the Version in pkg-config's pc file

2016-02-18 Thread Marc Deslauriers
Confirmed, the epoch wasn't supposed to get bumped in precise. ** Also affects: nss (Ubuntu Precise) Importance: Undecided Status: New ** Changed in: nss (Ubuntu Precise) Status: New => Confirmed ** Changed in: nss (Ubuntu Precise) Assignee: (unassigned)

[Touch-packages] [Bug 1546459] Re: segfault at b774bd9d ip b7352a0d sp bfda8f30 error 7 in libresolv-2.19.so[b7349000+13000]

2016-02-18 Thread Marc Deslauriers
How are you installing this? What image are you using? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to eglibc in Ubuntu. https://bugs.launchpad.net/bugs/1546459 Title: segfault at b774bd9d ip b7352a0d sp bfda8f30 error 7 in

[Touch-packages] [Bug 1451438] Re: graphite2 fails to build in trusty on i386

2016-02-17 Thread Marc Deslauriers
Fixed in (1.2.4-1ubuntu1.1). ** Changed in: graphite2 (Ubuntu Trusty) Status: New => Fix Released ** Changed in: graphite2 (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed

[Touch-packages] [Bug 1526959] Re: openssl 1.0.2e breaks sbsigntool

2016-02-12 Thread Marc Deslauriers
** Changed in: openssl (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bugs/1526959 Title: openssl 1.0.2e breaks sbsigntool Status

[Touch-packages] [Bug 1540811] Re: [GDK] patch - avoid integer overflow when allocating a large block of memory

2016-02-12 Thread Marc Deslauriers
signed) => Marc Deslauriers (mdeslaur) ** Changed in: gtk+3.0 (Ubuntu Trusty) Status: New => Fix Released ** Changed in: gtk+3.0 (Ubuntu Wily) Status: New => Fix Released ** Changed in: gtk+3.0 (Ubuntu Xenial) Status: New => Fix Released -- You received this bug no

[Touch-packages] [Bug 1540811] Re: [GDK] patch - avoid integer overflow when allocating a large block of memory

2016-02-12 Thread Marc Deslauriers
** Changed in: gtk+2.0 (Ubuntu Wily) Importance: Undecided => Medium ** Changed in: gtk+2.0 (Ubuntu Precise) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: gtk+2.0 (Ubuntu Trusty) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Cha

[Touch-packages] [Bug 1542846] Re: [HP ProBook 450 G3, Intel Skylake HDMI, Digital Out, HDMI] No sound at all

2016-02-11 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1543830] Re: Please DONT use webkit 1 !!!!

2016-02-11 Thread Marc Deslauriers
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to gnome-online-accounts in Ubuntu. https://bugs.launchpad.net/bugs/1543830 Title: Please DONT use webkit 1 Stat

[Touch-packages] [Bug 1501634] Re: GnuPG 1.4/2.0 requires a patch for GCC 5

2016-02-09 Thread Marc Deslauriers
pg2 (Ubuntu) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to gnupg in Ubuntu. https://bugs.launchpad.net/bugs/1501634 Title: GnuPG 1.4/2.0 requires a patch for GCC 5 S

[Touch-packages] [Bug 1541925] Re: Tries to create temp files under ~/.gnupg but doesn't create the dir

2016-02-08 Thread Marc Deslauriers
Caused by 6f992d94ea708535b2f3a3de22b429401d59fac9 ** Bug watch added: bugs.gnupg.org/gnupg/ #2246 http://bugs.gnupg.org/gnupg/issue2246 ** Also affects: gnupg via http://bugs.gnupg.org/gnupg/issue2246 Importance: Unknown Status: Unknown -- You received this bug notification bec

[Touch-packages] [Bug 523113] Re: missing manpages for nss tools

2016-02-04 Thread Marc Deslauriers
Ubuntu 15.10 and up now include manpages for nss tools. Marking this bug as closed. ** Changed in: nss (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to nss in Ubuntu. https://bug

[Touch-packages] [Bug 1532648] Re: Please merge openldap 2.4.42+dfsg-2 (main) from Debian testing (main)

2016-01-19 Thread Marc Deslauriers
Merge looks good. Uploading. Thanks! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openldap in Ubuntu. https://bugs.launchpad.net/bugs/1532648 Title: Please merge openldap 2.4.42+dfsg-2 (main) from Debian testing (main)

[Touch-packages] [Bug 1517040] Re: wpa 2.4 misses one patch from Debian to improve 2.4/5 GHz AP selection

2016-01-19 Thread Marc Deslauriers
ACK on the debdiff in comment #1, uploading now. Thanks! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to wpa in Ubuntu. https://bugs.launchpad.net/bugs/1517040 Title: wpa 2.4 misses one patch from Debian to improve 2.4/5 GH

[Touch-packages] [Bug 1534230] Re: LDAP TLS connection stopped working

2016-01-14 Thread Marc Deslauriers
Yep, unfortunately those are signed with md5, so it's normal that gnutls will no longer connect. You need to request those certs be changed, and use the older version of gnutls26 in the meantime. Since this is expected behaviour, I am closing this bug. Thanks! ** Changed in: gnutls26 (Ubuntu)

[Touch-packages] [Bug 1534230] Re: LDAP TLS connection stopped working

2016-01-14 Thread Marc Deslauriers
ok, since you haven't pasted the actual certs, you need to run both of them though "openssl x509 -noout -text" and see what it lists as the "Signature Algorithm". -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to gnutls26 in Ubu

[Touch-packages] [Bug 1534230] Re: LDAP TLS connection stopped working

2016-01-14 Thread Marc Deslauriers
Oh, unfortunately not. I was hoping gnutls-cli would print out the certs, but it appears it stops before it gets a chance to. Perhaps: openssl s_client -connect xx.xx.xx.xx:636 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1534230] Re: LDAP TLS connection stopped working

2016-01-14 Thread Marc Deslauriers
Perhaps try: gnutls-cli -p 636 xx.xx.xx.xx -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to gnutls26 in Ubuntu. https://bugs.launchpad.net/bugs/1534230 Title: LDAP TLS connection stopped working Status in gnutls26 package

[Touch-packages] [Bug 1534230] Re: LDAP TLS connection stopped working

2016-01-14 Thread Marc Deslauriers
The gnutls26 security update disabled md5 support. Are you sure one of your server certs isn't using md5? Could you perhaps attach them here? ** Changed in: gnutls26 (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded p

[Touch-packages] [Bug 1525996] Re: missing patch in USN-2834-1 security updates

2016-01-14 Thread Marc Deslauriers
ibxml2 (Ubuntu Vivid) Status: New => Confirmed ** Changed in: libxml2 (Ubuntu Wily) Status: New => Confirmed ** Changed in: libxml2 (Ubuntu Xenial) Status: New => Confirmed ** Changed in: libxml2 (Ubuntu Precise) Assignee: (unassigned) => Marc Deslauriers (mde

[Touch-packages] [Bug 1524960] Re: [Aspire E5-571G, Realtek ALC283, Black Headphone Out, Left] Playback problem

2016-01-14 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1524953] Re: Crash again

2016-01-14 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1525255] Re: package resolvconf 1.78ubuntu1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2016-01-14 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1526999] Re: cups is intolerant to TLS 1.2

2016-01-14 Thread Marc Deslauriers
Since you managed to get this to work, I am closing this bug. Thanks! ** Changed in: cups (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/

[Touch-packages] [Bug 1532462] Re: bugs of xorg

2016-01-14 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see https://wiki.ubuntu.

[Touch-packages] [Bug 1532416] Re: Xorg freeze

2016-01-14 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1532168] Re: CVE-2015-7575 - Security update for gnutls26 package

2016-01-08 Thread Marc Deslauriers
http://www.ubuntu.com/usn/usn-2865-1/ ** Information type changed from Private Security to Public Security ** Changed in: gnutls26 (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to g

[Touch-packages] [Bug 1475050] Re: unprivileged guest to host real-root escape via lxc-attach

2015-12-18 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1475050 Title: unprivileged guest to host real-root escape

[Touch-packages] [Bug 1526999] Re: cups is intolerant to TLS 1.2

2015-12-16 Thread Marc Deslauriers
Curiously, I can't reproduce that. This is what I get: $ openssl s_client -connect localhost:631 SSL-Session: Protocol : TLSv1.2 Cipher: AES256-SHA256 Please attach the output of "apt-cache policy libssl1.0.0" and your /etc/cups/cupsd.conf Thanks! ** Information type changed fr

[Touch-packages] [Bug 1505328] Re: Cups SSL is vulnerable to POODLE

2015-12-16 Thread Marc Deslauriers
** Summary changed: - Cups SSL is vulernable to POODLE + Cups SSL is vulnerable to POODLE -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1505328 Title: Cups SSL is vulnerabl

[Touch-packages] [Bug 1525981] Re: Device can be tricked into exposing mtp service without being unlocked first

2015-12-14 Thread Marc Deslauriers
This is CVE-2015-7946 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2015-7946 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to unity8 in Ubuntu. https://bugs.launchpad.net/bugs/1525981 Title: Device can b

[Touch-packages] [Bug 1482786] Re: man-db daily cron job TOCTOU bug when processing catman pages

2015-12-14 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to pam in Ubuntu. https://bugs.launchpad.net/bugs/1482786 Title: man-db daily cron job TOCTOU bug when proces

[Touch-packages] [Bug 1525996] [NEW] missing patch in USN-2834-1 security updates

2015-12-14 Thread Marc Deslauriers
*** This bug is a security vulnerability *** Public security bug reported: USN-2834-1 contained a fix for CVE-2015-7499, but did not contain the following subsequent commit: https://git.gnome.org/browse/libxml2/commit/?id=ce0b0d0d81fdbb5f722a890432b52d363e4de57b See post from Tom Lane here: ht

[Touch-packages] [Bug 1505328] Re: Cups SSL is vulernable to POODLE

2015-12-11 Thread Marc Deslauriers
ACK on the updated debdiff, thanks! I've changed my mind, and will release it as a security update after all if testing goes well. Thanks! ** Changed in: cups (Ubuntu Trusty) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) -- You received this bug notification because y

[Touch-packages] [Bug 1519942] Re: something proble

2015-12-09 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see https://wiki.ubuntu.

[Touch-packages] [Bug 1520674] Re: Graphics issue, vertical lines on screen.

2015-12-09 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1519985] Re: package libqtcore4 4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1 failed to install/upgrade: попытка перезаписать общий «/etc/xdg/Trolltech.conf», который отличается от дру

2015-12-09 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1520701] Re: E: no se encontro el paquete

2015-12-09 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1523077] Re: ok

2015-12-09 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see https://wiki.ubuntu.

[Touch-packages] [Bug 1522190] Re: Permission denied (publickey) whereas the public key has been inserted into ~/.ssh/authorized_keys: "usePAM no" issue

2015-12-09 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1522963] Re: apt doesn't see gpg repository keys

2015-12-09 Thread Marc Deslauriers
Thanks for your comments. This does not appear to be a bug report and we are closing it. We appreciate the difficulties you are facing, but it would make more sense to raise your question in the support tracker. Please visit https://answers.launchpad.net/ubuntu/+addquestion ** Information type cha

[Touch-packages] [Bug 1523555] Re: Error

2015-12-09 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see https://wiki.ubuntu.

[Touch-packages] [Bug 1524053] Re: Gdebi 0.9.5.7 doesn't show required dependencies list on non Xubuntu Session than a line.

2015-12-09 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1523770] Re: bad

2015-12-09 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see https://wiki.ubuntu.

[Touch-packages] [Bug 1509081] Re: nano segfaults as root after upgrade to 15.10

2015-12-08 Thread Marc Deslauriers
Uploaded same fix to Wily for processing by the SRU team. ** Description changed: + [Impact] + + On systems with a long hostname, nano either segfaults or refuses to + work properly. + + [Test Case] + 1- set a long hostname with "hostname thisisareallyreallyreallylonghostname" + 2- try and edit

[Touch-packages] [Bug 1505328] Re: Cups SSL is vulernable to POODLE

2015-12-08 Thread Marc Deslauriers
This part of the patch is wrong: @@ -895,18 +922,6 @@ _cupsSetDefaults(void) * Look for ~/.cups/client.conf... */ - snprintf(filename, sizeof(filename), "%s/.cups/client.conf", home); - fp = cupsFileOpen(filename, "r"); -} -else - fp = NULL; - -if (!fp) -

[Touch-packages] [Bug 1520568] Re: All queries fails when 'google' is used: ERR_SSL_PROTOCOL_ERROR

2015-12-02 Thread Marc Deslauriers
I can't reproduce this issue in midori at all. I can reproduce it with https://te-st.ru -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to nss in Ubuntu. https://bugs.launchpad.net/bugs/1520568 Title: All queries fails when '

[Touch-packages] [Bug 1520568] Re: All queries fails when 'google' is used: ERR_SSL_PROTOCOL_ERROR

2015-12-01 Thread Marc Deslauriers
nss 3.20.1 works, nss 3.21 doesn't. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to nss in Ubuntu. https://bugs.launchpad.net/bugs/1520568 Title: All queries fails when 'google' is used: ERR_SSL_PROTOCOL_ERROR Status in ch

[Touch-packages] [Bug 1520568] Re: All queries fails when 'google' is used: ERR_SSL_PROTOCOL_ERROR

2015-12-01 Thread Marc Deslauriers
OK, a few more notes on reproducing this: 1- I can't reproduce this by installing the daily live cd in a VM 2- I can reproduce it successfully by installing the daily live cd on real hardware This means it's probably not related to which Google servers are being hit, and is likely hardware-depen

[Touch-packages] [Bug 1510163] Re: Poodle TLS1.0 issue in Trusty (and Precise)

2015-11-30 Thread Marc Deslauriers
Publishing as a security update now, thanks! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to gnutls26 in Ubuntu. https://bugs.launchpad.net/bugs/1510163 Title: Poodle TLS1.0 issue in Trusty (and Precise) Status in gnutls26

[Touch-packages] [Bug 1520568] Re: All queries fails when 'google' is used: ERR_SSL_PROTOCOL_ERROR

2015-11-30 Thread Marc Deslauriers
I can't seem to reproduce this. https://www.google.com works fine in an up-to-date image with Chromium and nss 2:3.21-1ubuntu2. Could you please give the exact steps require to see this issue? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which i

[Touch-packages] [Bug 1510163] Re: Poodle TLS1.0 issue in Trusty (and Precise)

2015-11-26 Thread Marc Deslauriers
d => High ** Changed in: gnutls26 (Ubuntu Precise) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: gnutls26 (Ubuntu Trusty) Assignee: (unassigned) => Marc Deslauriers (mdeslaur) ** Changed in: gnutls26 (Ubuntu) Status: New => Fix Released --

[Touch-packages] [Bug 1510163] Re: Poodle TLS1.0 issue in Trusty (and Precise)

2015-11-26 Thread Marc Deslauriers
Hi Bryan, Thanks for the debdiffs! Where did you obtain the patch from Hanno Boeck from? ** Also affects: gnutls26 (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: gnutls26 (Ubuntu Trusty) Importance: Undecided Status: New -- You received this bug notifi

[Touch-packages] [Bug 1507025] Re: Shell Command Injection with the hostname

2015-11-25 Thread Marc Deslauriers
I'm not sure what the attack vector here is. /etc/hostname is only writeable by root. Is there any way for an attacker to control /etc/hostname? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to bash in Ubuntu. https://bugs.lau

[Touch-packages] [Bug 1515662] Re: Major security issue with light-locker - console switching gives access to other screens for a few seconds

2015-11-25 Thread Marc Deslauriers
** Changed in: light-locker (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lightdm in Ubuntu. https://bugs.launchpad.net/bugs/1515662 Title: Major security issue with light-locker - c

[Touch-packages] [Bug 1518792] Re: Flashplayer

2015-11-25 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1518785] Re: Root-owned files being overwritten with HTML by unknown program.

2015-11-25 Thread Marc Deslauriers
** Information type changed from Private Security to Public ** Package changed: ubuntu => apt (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apt in Ubuntu. https://bugs.launchpad.net/bugs/1518785 Title: Root-owne

[Touch-packages] [Bug 1518849] Re: Not able to save user account setting

2015-11-25 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1518783] Re: i can't install programmes in that terminal thingy

2015-11-25 Thread Marc Deslauriers
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see https://wiki.ubuntu.

[Touch-packages] [Bug 1516592] Re: CVE-2015-8126: Multiple buffer overflows

2015-11-19 Thread Marc Deslauriers
** Changed in: libpng (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to libpng in Ubuntu. https://bugs.launchpad.net/bugs/1516592 Title: CVE-2015-8126: Multiple buffer overflows

[Touch-packages] [Bug 1516592] Re: CVE-2015-8126: Multiple buffer overflows

2015-11-19 Thread Marc Deslauriers
Thanks for the debdiffs, building now for a security update! -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to libpng in Ubuntu. https://bugs.launchpad.net/bugs/1516592 Title: CVE-2015-8126: Multiple buffer overflows Status

[Touch-packages] [Bug 1516592] Re: CVE-2015-8126: Multiple buffer overflows

2015-11-19 Thread Marc Deslauriers
** Also affects: libpng (Ubuntu Precise) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to libpng in Ubuntu. https://bugs.launchpad.net/bugs/1516592 Title: CVE-2015-8126: Multiple b

[Touch-packages] [Bug 1498751] Re: Please sync libxml2 2.9.2+zdfsg1-4 (main) from Debian unstable

2015-11-12 Thread Marc Deslauriers
** Changed in: libxml2 (Ubuntu) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to libxml2 in Ubuntu. https://bugs.launchpad.net/bugs/1498751 Title: Please sync libxml2 2.9.2+zdfsg1

[Touch-packages] [Bug 1512131] Re: Apparmor complains about multiple /run/dovecot file access

2015-11-10 Thread Marc Deslauriers
** Package changed: dovecot (Ubuntu) => apparmor (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1512131 Title: Apparmor complains about multiple /run/dovecot fil

[Touch-packages] [Bug 1505328] Re: Cups SSL is vulernable to POODLE

2015-11-10 Thread Marc Deslauriers
1- The debdiff in comment #9 still contains an extra cups-1.7.2/lets_patch_this.patch section. Could you please remove it? 2- Please add an origin tag to the patch that traces back to redhat's 1161172 bug, since I believe that's what you based the backport on 3- Also, I don't think we should do

[Touch-packages] [Bug 1505328] Re: Cups SSL is vulernable to POODLE

2015-11-10 Thread Marc Deslauriers
Also, please add "(LP: #1505328)" to the debian/changelog. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1505328 Title: Cups SSL is vulernable to POODLE Status in cups pack

[Touch-packages] [Bug 1512781] Re: CVE-2015-5602 - Unauthorized Privilege Escalation

2015-11-05 Thread Marc Deslauriers
** Bug watch added: bugzilla.sudo.ws/ #707 http://bugzilla.sudo.ws/show_bug.cgi?id=707 ** Also affects: sudo via http://bugzilla.sudo.ws/show_bug.cgi?id=707 Importance: Unknown Status: Unknown -- You received this bug notification because you are a member of Ubuntu Touch seeded p

[Touch-packages] [Bug 1499322] Re: Wily: No Dash Icon After Package Install Until New Session

2015-11-03 Thread Marc Deslauriers
** Package changed: dash (Ubuntu) => unity (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to dash in Ubuntu. https://bugs.launchpad.net/bugs/1499322 Title: Wily: No Dash Icon After Package Install Until New Session

[Touch-packages] [Bug 1512781] Re: CVE-2015-5602 - Unauthorized Privilege Escalation

2015-11-03 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Also affects: sudo (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: sudo (Ubuntu Wily) Importance: Undecided Status: New ** Also affects: sudo (Ubuntu Trusty) Importance: Undecided

[Touch-packages] [Bug 1499070] Re: telepathy-gabble crashed with signal 5 in g_object_unref()

2015-10-29 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1505858] Re: Segmentation fault in JPXStream::readTilePartData(JPXStream.cc:2142)

2015-10-29 Thread Marc Deslauriers
** Bug watch added: freedesktop.org Bugzilla #92450 https://bugs.freedesktop.org/show_bug.cgi?id=92450 ** Also affects: poppler via https://bugs.freedesktop.org/show_bug.cgi?id=92450 Importance: Unknown Status: Unknown ** Information type changed from Private Security to Public Se

[Touch-packages] [Bug 1506229] Re: package python3.4 3.4.3-1ubuntu1~14.04.3 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2015-10-29 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1509689] Re: the system running low graphics mode

2015-10-29 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1509902] Re: Empty entries in app-permissions section of privacy settings

2015-10-29 Thread Marc Deslauriers
** Package changed: ubuntu-system-settings (Ubuntu) => location-service (Ubuntu) ** Information type changed from Private Security to Public Security ** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 1510048] Re: package lightdm 1.14.2-0ubuntu1.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2015-10-29 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1511077] Re: package lsb-desktop 4.1+Debian11ubuntu6 failed to install/upgrade: problemas de dependência - deixando desconfigurado

2015-10-29 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Touch-packages] [Bug 1498655] Re: Steam Controller support: need read-write access to Valve-owned input event device nodes.

2015-10-29 Thread Marc Deslauriers
Uploaded packages for trusty-wily for processing by the SRU team. ** Changed in: steam (Ubuntu Trusty) Status: Confirmed => In Progress ** Changed in: steam (Ubuntu Vivid) Status: Confirmed => In Progress ** Changed in: steam (Ubuntu Wily) Status: Confirmed => In Progress -

[Touch-packages] [Bug 1498655] Re: Steam Controller support: need read-write access to Valve-owned input event device nodes.

2015-10-29 Thread Marc Deslauriers
** Changed in: steam (Ubuntu) Status: Fix Released => In Progress ** Changed in: steam (Ubuntu Wily) Status: Fix Released => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://b

[Touch-packages] [Bug 1507480] Re: Privilege escalation through Python module imports

2015-10-27 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security ** Changed in: apport (Ubuntu Xenial) Assignee: Martin Pitt (pitti) => Marc Deslauriers (mdeslaur) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed

<    3   4   5   6   7   8   9   10   11   12   >