[Bug 1866113] Re: CVE-2019-16235, CVE-2019-16236, CVE-2019-16237

2020-03-05 Thread Eduardo dos Santos Barretto
You can find it built here: https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa/+packages ** Changed in: dino-im (Ubuntu Bionic) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1819761] Re: [MIR] containerd

2020-02-28 Thread Eduardo dos Santos Barretto
I reviewed containerd 1.3.1-0ubuntu1 as checked into focal. This shouldn't be considered a full audit but rather a quick gauge of maintainability. containerd is a daemon that manages the complete container lifecycle of its host system. Containerd controls runc. - No CVE History: - Build-Depends

[Bug 1864979] Re: Ubuntu Re-installation Aborted

2020-02-27 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1856459]

2020-02-26 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 1856922] Re: Ubuntu One Cannot Sign in. downloaded Installerfetch, Security

2020-02-26 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1856698] Re: I can see the password as I type into the password field after I reboot my PC

2020-02-26 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1862488] Re: clementine crashed with SIGSEGV in gst_element_set_state()

2020-02-26 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1862555]

2020-02-26 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 1864379] Re: plasma-discover crashed with SIGABRT in raise()

2020-02-26 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Your bug report is more likely to get attention if it is made in English, since this is the language understood by the majority of Ubuntu developers. Additionally, please only mark a bug as "security" if it shows

[Bug 1852367] Re: [MIR] mysql-router (mysql-8.0)

2020-02-26 Thread Eduardo dos Santos Barretto
I reviewed mysql-router 8.0.19-0ubuntu2 as checked into focal (when this review started). This shouldn't be considered a full audit but rather a quick gauge of maintainability. mysql-router is a binary package from mysql-8.0 that is responsible for routing connections from MySQL clients to MySQL

[Bug 1862770] Re: MySQL autopkgtest regressed in Focal release pocket

2020-02-11 Thread Eduardo dos Santos Barretto
This is the same as bug #1862364 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862770 Title: MySQL autopkgtest regressed in Focal release pocket To manage notifications about this bug go to:

[Bug 1862364] [NEW] mysql-8.0 FTBFS (focal) because of hardcoded date in test

2020-02-07 Thread Eduardo dos Santos Barretto
Public bug reported: Just similar to bug #1859100 there is another test that just started failing because of a date that expired. See the snippet of build log below: [ 51%] main.events_1w4 [ fail ] Test ended at 2020-02-07 10:46:06 CURRENT_TEST:

[Bug 1817336] Re: [MIR] runc

2020-01-17 Thread Eduardo dos Santos Barretto
I reviewed runc 1.0.0~rc8+git20190923.3e425f80-0ubuntu1 as checked into focal. This shouldn't be considered a full audit but rather a quick gauge of maintainability. runc, a lightweight universal container runtime, is a CLI tool for spawning and running containers according to the Open Container

[Bug 1859100] Re: mysql-server FTBFS (focal) because of build tests

2020-01-15 Thread Eduardo dos Santos Barretto
Thanks, I will try to test or at least let the build running on xnox's proposed mysql version. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1859100 Title: mysql-server FTBFS (focal) because of

[Bug 711061] Re: [MIR] openjpeg2

2020-01-08 Thread Eduardo dos Santos Barretto
** Changed in: openjpeg2 (Ubuntu) Assignee: Ubuntu Security Team (ubuntu-security) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/711061 Title: [MIR] openjpeg2 To manage

[Bug 711061] Re: [MIR] openjpeg2

2020-01-08 Thread Eduardo dos Santos Barretto
I reviewed openjpeg2 2.3.1-1 as checked into focal. This shouldn't be considered a full audit but rather a quick gauge of maintainability. openjpeg2 is a library to encode and decode JPEG 2000 images. JPEG 2000 is an image compression standard and coding system. OpenJPEG dates back from 2005 and

[Bug 1856456] Re: package systemd 242-7ubuntu3.2 failed to install/upgrade: package systemd is already installed and configured

2019-12-20 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1856510] Re: Gtk-Message: 23:32:48.890: Failed to load module "canberra-gtk-module" (etherape:2564): libglade-WARNING **: 23:32:48.893: Could not load support for `gnome': libgnome.so: Ne peut o

2019-12-20 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1856597] Re: sepackage mysql-server-5.7 5.7.28-0ubuntu0.18.04.4 failed to install/upgrade: instalado mysql-server-5.7 paquete post-installation guión el subproceso devolvió un error con estado de

2019-12-20 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1856771] Re: package samba 2:4.3.11+dfsg-0ubuntu0.16.04.24 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2019-12-20 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1856997] Re: Nvidia driver is not working / not supported

2019-12-20 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1856944] Re: package login 1:4.2-3.1ubuntu5.4 failed to install/upgrade: package architecture (amd64) does not match system (i386)

2019-12-20 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1857059] Re: encontre un error y me vanearon

2019-12-20 Thread Eduardo dos Santos Barretto
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 1856979] Re: GIT 2.x vulnerabilities

2019-12-19 Thread Eduardo dos Santos Barretto
Actually marking it as Fixed Released. ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1856979 Title: GIT 2.x vulnerabilities

[Bug 1855768] Re: Ubuntu-security CVE-2019-18224 web page shows incorrect info about libidn2-0 status

2019-12-10 Thread Eduardo dos Santos Barretto
Hi Srdjan, Awesome, thanks! I will give it a try. Yes, the analysis seems correct to me. So I encourage you to file a bug on Trivy Github and let them verify what's going on. If possible, keep us updated on the outcomes of your bug report. I appreciate it! Thanks, Eduardo -- You received this

[Bug 1855768] Re: Ubuntu-security CVE-2019-18224 web page shows incorrect info about libidn2-0 status

2019-12-09 Thread Eduardo dos Santos Barretto
Also, I am not aware of this Trivy tool, but could you give us more information on what you are seeing? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1855768 Title: Ubuntu-security

[Bug 1855768] Re: Ubuntu-security CVE-2019-18224 web page shows incorrect info about libidn2-0 status

2019-12-09 Thread Eduardo dos Santos Barretto
Hi Srdjan, Thanks for taking the time to report this issue and help making Ubuntu better. The USN you mentioned, applied the fix to the source package libidn2 (https://packages.ubuntu.com/source/bionic/libidn2) You can see on the mentioned page that this source package generates multiple

[Bug 1854707] Re: tcpdump vulnerability

2019-12-02 Thread Eduardo dos Santos Barretto
*** This bug is a duplicate of bug 1847520 *** https://bugs.launchpad.net/bugs/1847520 ** Also affects: tcpdump (Ubuntu) Importance: Undecided Status: New ** No longer affects: phpmyadmin (Ubuntu) ** This bug has been marked a duplicate of bug 1847520 33 Upstream CVEs patched

[Bug 1854530] Re: package pcp 4.3.4-1build1 failed to install/upgrade: installed pcp package post-installation script subprocess returned error exit status 1

2019-11-29 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1854525] Re: package libglib-perl 3:1.320-2 failed to install/upgrade: package libglib-perl is not ready for configuration cannot configure (current status 'half-installed')

2019-11-29 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1854498] Re: package libpng12-0 1.2.54-1ubuntu1 failed to install/upgrade: trying to overwrite shared '/usr/share/doc/libpng12-0/changelog.Debian.gz', which is different from other instances of p

2019-11-29 Thread Eduardo dos Santos Barretto
*** This bug is a duplicate of bug 1799215 *** https://bugs.launchpad.net/bugs/1799215 Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as

[Bug 1854373] Re: CVE affecting phpMyAdmin 4.x

2019-11-28 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 1854120] Re: Screen contents visible briefly on lock screen on resolution change

2019-11-27 Thread Eduardo dos Santos Barretto
@vanvugt, could you please take a look on this and assign it to the correct package. It might be a duplicate of another ticket. Thanks! ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1850032] Re: scanbd prevents HP printers to work correctly with HPLIP

2019-11-26 Thread Eduardo dos Santos Barretto
** Also affects: cups (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1850032 Title: scanbd prevents HP printers to work correctly with

[Bug 1853545]

2019-11-26 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 1853371] Re: discover did not ask for a password on an update

2019-11-26 Thread Eduardo dos Santos Barretto
*** This bug is a duplicate of bug 1853545 *** https://bugs.launchpad.net/bugs/1853545 ** This bug has been marked a duplicate of bug 1853545 discover did not ask for a password on an update -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1853760] Re: php 7.2 has dependency problems and they are not letting to update apache2 and php7.2 * modules

2019-11-25 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1851738] Re: cqrlog cant be remove , cant download other apps because of it

2019-11-25 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1853696] Re: linux corrompido

2019-11-25 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 711061] Re: [MIR] openjpeg2

2019-10-23 Thread Eduardo dos Santos Barretto
** Changed in: openjpeg2 (Ubuntu) Assignee: (unassigned) => Ubuntu Security Team (ubuntu-security) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/711061 Title: [MIR] openjpeg2 To manage

[Bug 1847701] Re: Buffer Overflow Write when libntlm generates NTLM request

2019-10-15 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1847701 Title: Buffer Overflow Write when libntlm generates NTLM request To

[Bug 1847831] Re: pppp

2019-10-14 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1847520] Re: 33 Upstream CVEs patched

2019-10-14 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1847520 Title: 33 Upstream CVEs patched To manage notifications about this bug go

[Bug 1847960] Re: After returning from suspend the screen content (with all previously opened programs, like code editor) is shown for 1 second before displaying login form

2019-10-14 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1847960 Title: After returning from suspend the screen content (with all

[Bug 1848076] Re: libc programme was unable to get updated

2019-10-14 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1841978] Re: package login 1:4.2-3.1ubuntu5 failed to install/upgrade: package login is already installed and configured

2019-09-02 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1815483] Re: [MIR] libhandy

2019-08-16 Thread Eduardo dos Santos Barretto
I reviewed libhandy 0.0.10-1 as checked into eoan. This shouldn't be considered a full audit but rather a quick gauge of maintainability. libhandy is a library full of GTK widgets for mobile phones. The aim of libhandy is to help with developing UI for mobile devices using GTK/GNOME. - No CVE

[Bug 1839531] Re: 14.04 LTS does not upgrade to 16.04 LTS

2019-08-08 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1839071] Re: numad sched_setaffinity bug

2019-08-06 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1814596] Re: DynamicUser can create setuid binaries when assisted by another process

2019-08-06 Thread Eduardo dos Santos Barretto
** Changed in: systemd (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1814596 Title: DynamicUser can create setuid binaries when assisted by another

[Bug 1833479] Re: libjack-jackd2-0 double close on a failure to connect to jackd which causes crashes in multithreaded programs

2019-08-05 Thread Eduardo dos Santos Barretto
** Changed in: jackd2 (Ubuntu) Status: New => Confirmed ** Changed in: jackd2 (Debian) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1833479 Title:

[Bug 1838067] Re: made Ubuntu very slow then crash

2019-08-05 Thread Eduardo dos Santos Barretto
** Changed in: clamtk (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1838067 Title: made Ubuntu very slow then crash To manage notifications about

[Bug 1838795] Re: package linux-image-extra-4.4.0-57-generic 4.4.0-57.78 failed to install/upgrade: run-parts: /etc/kernel/postinst.d/initramfs-tools exited with return code 1

2019-08-05 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1838879] Re: Nvidia MX130 Video

2019-08-05 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1836496]

2019-07-15 Thread Eduardo dos Santos Barretto
Thanks Julian! The packages will be available in a few minutes in security-proposed https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages?field.name_filter=redis_filter=published_filter= If you could also test them would be great. I will be pushing them to archive tomorrow

[Bug 1836496] Re: CVE-2019-10192 CVE-2019-10193

2019-07-15 Thread Eduardo dos Santos Barretto
** Changed in: redis (Ubuntu) Status: Confirmed => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1836496 Title: CVE-2019-10192 CVE-2019-10193 To manage notifications about this

[Bug 1836496] Re: CVE-2019-10192 CVE-2019-10193

2019-07-15 Thread Eduardo dos Santos Barretto
** Changed in: redis (Ubuntu) Assignee: (unassigned) => Eduardo dos Santos Barretto (ebarretto) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1836496 Title: CVE-2019-10192 CVE-2019-10

[Bug 1833745] Re: [MIR] required new dependency of appstream

2019-07-09 Thread Eduardo dos Santos Barretto
** Changed in: lmdb (Ubuntu) Assignee: Ubuntu Security Team (ubuntu-security) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1833745 Title: [MIR] required new dependency of

[Bug 1833745] Re: [MIR] required new dependency of appstream

2019-07-09 Thread Eduardo dos Santos Barretto
I reviewed lmdb 0.9.23-0ubuntu1 as checked into eoan. This shouldn't be considered a full audit but rather a quick gauge of maintainability. lmdb is a software library that provides a high-performance embedded transactional database in the form a key-value store. - No CVE History - Build-Depends

[Bug 1835213] Re: CVE-2019-13132

2019-07-08 Thread Eduardo dos Santos Barretto
Thanks Luca for all the help and contribution, the fix is released. Feel free to contact us in case of new issues. ** Changed in: zeromq3 (Ubuntu) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 1820233] Re: [MIR] zope.component as dependency of mailman3

2019-06-19 Thread Eduardo dos Santos Barretto
I reviewed zope.component 4.3.0-1 as checked into eoan. This shouldn't be considered a full audit but rather a quick gauge of maintainability. Zope is a free and open source web application server written in the object-oriented programming language “Python”. zope.component is a framework that

[Bug 1832679] Re: package python-secretstorage 2.3.1-2 failed to install/upgrade: le sous-processus script post-installation installé a retourné une erreur de sortie d'état 1

2019-06-13 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1822013] Re: extplorer package exposes /usr/ (and /etc/extplorer/) directory over HTTP

2019-06-12 Thread Eduardo dos Santos Barretto
** Changed in: extplorer (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1822013 Title: extplorer package exposes /usr/ (and /etc/extplorer/) directory over

[Bug 1775776] Re: GNU bc crashes on some inputs

2019-06-11 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1775776 Title: GNU bc crashes on some inputs To manage notifications about this

[Bug 1751920] Re: USN-3537-2: partially applies to MariaDB too

2019-06-11 Thread Eduardo dos Santos Barretto
Setting mariadb-10.1 to 'Fix Released' as Bionic (1:10.1.34-0ubuntu0.18.04.1) and newer releases already contain the fixes for those CVEs. ** Changed in: mariadb-10.1 (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which

[Bug 1778341] Re: 100.0% finished but not written to disk

2019-06-11 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1829557] Re: package file 1:5.25-2ubuntu1 failed to install/upgrade: package file is not ready for configuration cannot configure (current status 'half-installed')

2019-06-11 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1821957] Re: Turning off a monitor unlocks the computer

2019-06-10 Thread Eduardo dos Santos Barretto
** Changed in: gnome-screensaver (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1821957 Title: Turning off a monitor unlocks the computer To manage

[Bug 1831713] Re: Security update to libpam-u2f from Yubico

2019-06-10 Thread Eduardo dos Santos Barretto
** Changed in: pam-u2f (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1831713 Title: Security update to libpam-u2f from Yubico To manage

[Bug 1832041] Re: The mouse stops working

2019-06-10 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1830464] Re: Installer crashes at grub installation, i tried twice both the time crashed while grub installation, FYI there is working internet connection

2019-06-10 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1829407] Re: package linux-image-4.18.0-15-generic 4.18.0-15.16~18.04.1 failed to install/upgrade: installed linux-image-4.18.0-15-generic package pre-removal script subprocess returned error exi

2019-06-10 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1830570] Re: nao consigo instalar no meu pc

2019-06-10 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1832114] Re: install error

2019-06-10 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1832122] Re: Installation applet crashed during install

2019-06-10 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1832163] Re: Me acaban de dar BANNN SIN NINGUNA RAZON POR QUE ESTABA JUGANDO SKYWAR Y DE REPENDE ME DIERON BAN Llevo 3 años sin jugar me meto a un servidor a recordad los viejos tiempo y me dan b

2019-06-10 Thread Eduardo dos Santos Barretto
** Changed in: apache2 (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1832163 Title: Me acaban de dar BANNN SIN NINGUNA RAZON POR QUE ESTABA JUGANDO

[Bug 1832163] Re: Me acaban de dar BANNN SIN NINGUNA RAZON POR QUE ESTABA JUGANDO SKYWAR Y DE REPENDE ME DIERON BAN Llevo 3 años sin jugar me meto a un servidor a recordad los viejos tiempo y me dan b

2019-06-10 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1832163 Title: Me acaban de dar BANNN SIN NINGUNA RAZON POR QUE ESTABA JUGANDO SKYWAR Y

[Bug 1825572] Re: April 2019 Oracle CPU might also affect MariaDB

2019-06-05 Thread Eduardo dos Santos Barretto
Thanks Otto for providing the update for 18.04. We just released it and it should be available in the archive in some minutes. We appreciate all the work you've done. ** Changed in: mariadb-10.1 (Ubuntu) Status: In Progress => Fix Released -- You received this bug notification because

Re: [Bug 1820226] Re: [MIR] twitter-bootstrap3 as dependency of mailman3

2019-06-03 Thread Eduardo dos Santos Barretto
On Mon, 2019-06-03 at 05:54 +, Christian Ehrhardt  wrote: > > - There are different versions of twitter-bootstrap in the archive, > > after some > > search we have that > > [...] > > It is used in mailman-website where you can manage lists. It is > > unclear to > > me if the

[Bug 1820226] Re: [MIR] twitter-bootstrap3 as dependency of mailman3

2019-05-31 Thread Eduardo dos Santos Barretto
I reviewed twitter-bootstrap3 3.4.0+dfsg-4 as checked into eoan. This shouldn't be considered a full audit but rather a quick gauge of maintainability. twitter-bootstrap3 is an open source toolkit for developing with HTML, CSS, and JS. - There are different versions of twitter-bootstrap in the

[Bug 1825572] Re: April 2019 Oracle CPU might also affect MariaDB

2019-05-15 Thread Eduardo dos Santos Barretto
Hi Otto, You based your update on version 1:10.1.38-0ubuntu0.18.04.1. We currently have in the archive version 1:10.1.38-0ubuntu0.18.04.2. Could you please rebase your changes with what is in the archive? Thanks in advance! -- You received this bug notification because you are a member of

[Bug 1825572] Re: April 2019 Oracle CPU might also affect MariaDB

2019-05-15 Thread Eduardo dos Santos Barretto
I will be handling it for the security team, thanks Otto. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1825572 Title: April 2019 Oracle CPU might also affect MariaDB To manage notifications about

[Bug 1820212] Re: [MIR] python-aiosmtpd as dependency of mailman3

2019-05-13 Thread Eduardo dos Santos Barretto
I reviewed python-aiosmtpd version 1.2-3 as checked into eoan as of this writing. This shouldn't be considered a full audit but rather a quick gauge of maintainability. python-aiosmtpd is an asyncio based SMTP server. - Last commit from March - No CVE history - Build-depends: - debhelper, -

[Bug 1823786] Re: [SRU] ffmpeg 3.4.6 for bionic

2019-04-30 Thread Eduardo dos Santos Barretto
** Changed in: ffmpeg (Ubuntu Bionic) Status: Confirmed => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1823786 Title: [SRU] ffmpeg 3.4.6 for bionic To manage

[Bug 1823786] Re: [SRU] ffmpeg 3.4.6 for bionic

2019-04-29 Thread Eduardo dos Santos Barretto
) Assignee: (unassigned) => Eduardo dos Santos Barretto (ebarretto) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1823786 Title: [SRU] ffmpeg 3.4.6 for bionic To manage notifications ab

[Bug 1820211] Re: [MIR] python3-openid as dependency of mailman3

2019-04-25 Thread Eduardo dos Santos Barretto
I reviewed python3-openid version 3.1.0-1 as checked into disco as of this writing. This shouldn't be considered a full audit but rather a quick gauge of maintainability. python3-openid is a set of python packages to support use of the OpenID decentralized identity system in your application. -

[Bug 1825055] Re: hard disk faliure

2019-04-17 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1822418] Re: grub-efi

2019-04-16 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1823786] Re: [SRU] ffmpeg 3.4.6 for bionic

2019-04-16 Thread Eduardo dos Santos Barretto
** Changed in: ffmpeg (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1823786 Title: [SRU] ffmpeg 3.4.6 for bionic To manage notifications about this

[Bug 1821957] Re: Turning off a monitor unlocks the computer

2019-04-15 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public Security ** Changed in: ubuntubudgie Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1821957 Title:

[Bug 1824530] Re: Heap Buffer Overflow in UzpPassword

2019-04-15 Thread Eduardo dos Santos Barretto
** Changed in: unzip (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1824530 Title: Heap Buffer Overflow in UzpPassword To manage notifications about

[Bug 1824817] Re: Security breach with CRTL+ALT+F7

2019-04-15 Thread Eduardo dos Santos Barretto
*** This bug is a duplicate of bug 1806961 *** https://bugs.launchpad.net/bugs/1806961 ** This bug has been marked a duplicate of bug 1806961 Lock can be circumvented by switching tty when using lightdm ** Information type changed from Private Security to Public Security -- You received

[Bug 1824604] Re: how to install ubuntu on predator helios

2019-04-15 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1824678] Re: package libqt5svg5:amd64 5.11.1-2 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration

2019-04-15 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1824679] Re: package phpmyadmin 4:4.5.4.1-2ubuntu2.1 failed to install/upgrade: подпроцесс установлен сценарий post-removal возвратил код ошибки 10

2019-04-15 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1819912] Re: CVE-2019-9628 XML parser class fails to trap exceptions on malformed XML declaration

2019-03-26 Thread Eduardo dos Santos Barretto
Thanks Etienne, Updated version was released for trusty, xenial, bionic and cosmic. Thanks again for the testing and for providing the debdiffs. Any problems just let us know. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1819912] Re: CVE-2019-9628 XML parser class fails to trap exceptions on malformed XML declaration

2019-03-25 Thread Eduardo dos Santos Barretto
Hi Etienne, Yes it helps, also any other usage cases that you can run will be much appreciated. Thanks, Eduardo -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1819912 Title: CVE-2019-9628 XML

[Bug 1819912] Re: CVE-2019-9628 XML parser class fails to trap exceptions on malformed XML declaration

2019-03-21 Thread Eduardo dos Santos Barretto
Hi Etienne, I would appreciate if you could run some tests with the binaries that you can find below: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages?field.name_filter=xmltooling_filter=published_filter= Thanks -- You received this bug notification because you

[Bug 1819912] Re: CVE-2019-9628 XML parser class fails to trap exceptions on malformed XML declaration

2019-03-21 Thread Eduardo dos Santos Barretto
Hi Etienne, Thanks for taking the time to report this bug and helping to make Ubuntu better. I will be sponsoring it. I will be back to you later today and I would appreciate if you could run some tests on the built .debs. Thanks again -- You received this bug notification because you are a

[Bug 1819912] Re: CVE-2019-9628 XML parser class fails to trap exceptions on malformed XML declaration

2019-03-21 Thread Eduardo dos Santos Barretto
** Changed in: xmltooling (Ubuntu Bionic) Assignee: (unassigned) => Eduardo dos Santos Barretto (ebarretto) ** Changed in: xmltooling (Ubuntu Bionic) Status: Confirmed => In Progress ** Also affects: xmltooling (Ubuntu Trusty) Importance: Undecided Status: New *

  1   2   >