[Bug 1819912] Re: CVE-2019-9628 XML parser class fails to trap exceptions on malformed XML declaration

2019-03-19 Thread Eduardo dos Santos Barretto
** Changed in: xmltooling (Ubuntu) Assignee: (unassigned) => Eduardo dos Santos Barretto (ebarretto) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1819912 Title: CVE-2019-9628 XML parser cl

[Bug 1816040] Re: ECDSA XML signature generation segmentation fault

2019-03-13 Thread Eduardo dos Santos Barretto
** Changed in: xml-security-c (Ubuntu) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1816040 Title: ECDSA XML signature generation segmentation fault To m

[Bug 1816040] Re: ECDSA XML signature generation segmentation fault

2019-03-11 Thread Eduardo dos Santos Barretto
Hey Alejandro, Thanks for providing the patch. Could you please test the versions that I've built? https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages?field.name_filter=xml- security-c&field.status_filter=published&field.series_filter= Thanks -- You received this bu

[Bug 1816040] Re: ECDSA XML signature generation segmentation fault

2019-03-08 Thread Eduardo dos Santos Barretto
** Changed in: xml-security-c (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1816040 Title: ECDSA XML signature generation segmentation fault To manage not

[Bug 1816040] Re: ECDSA XML signature generation segmentation fault

2019-03-07 Thread Eduardo dos Santos Barretto
** Changed in: xml-security-c (Ubuntu) Assignee: (unassigned) => Eduardo dos Santos Barretto (ebarretto) ** Changed in: xml-security-c (Ubuntu) Status: Fix Released => New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 1816040] Re: ECDSA XML signature generation segmentation fault

2019-03-07 Thread Eduardo dos Santos Barretto
** Changed in: xml-security-c (Ubuntu) Assignee: Eduardo dos Santos Barretto (ebarretto) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1816040 Title: ECDSA XML signat

[Bug 1816040] Re: ECDSA XML signature generation segmentation fault

2019-03-01 Thread Eduardo dos Santos Barretto
** Changed in: xml-security-c (Ubuntu) Assignee: (unassigned) => Eduardo dos Santos Barretto (ebarretto) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1816040 Title: ECDSA XML signat

[Bug 1813837] Re: Multiple vulnerabilities affecting 4.5.0.7

2019-02-14 Thread Eduardo dos Santos Barretto
: coturn (Ubuntu) Assignee: (unassigned) => Eduardo dos Santos Barretto (ebarretto) ** Changed in: coturn (Ubuntu) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchp

[Bug 1815695] Re: Update incorrect, introduces possible crash

2019-02-14 Thread Eduardo dos Santos Barretto
Hey Roger, I've just released the fixes for Xenial, Bionic and Cosmic. It should hit the archives in a few minutes. Please let me know in case of new security requests, I will be glad to help. Thanks again for providing the patches and opening the bug. ** Changed in: mosquitto (Ubuntu) S

[Bug 1813837] Re: Multiple vulnerabilities affecting 4.5.0.7

2019-02-13 Thread Eduardo dos Santos Barretto
** Changed in: coturn (Ubuntu) Status: Confirmed => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1813837 Title: Multiple vulnerabilities affecting 4.5.0.7 To manage notification

[Bug 1815695] Re: Update incorrect, introduces possible crash

2019-02-13 Thread Eduardo dos Santos Barretto
** Changed in: mosquitto (Ubuntu) Status: Confirmed => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1815695 Title: Update incorrect, introduces possible crash To manage notifica

[Bug 1815695] Re: Update incorrect, introduces possible crash

2019-02-13 Thread Eduardo dos Santos Barretto
Hey Roger, Thanks for sending the patch and opening the bug. I will work on it right away. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1815695 Title: Update incorrect, introduces possible crash

[Bug 1815695] Re: Update incorrect, introduces possible crash

2019-02-13 Thread Eduardo dos Santos Barretto
** Changed in: mosquitto (Ubuntu) Assignee: (unassigned) => Eduardo dos Santos Barretto (ebarretto) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1815695 Title: Update incorrect, introdu

[Bug 1814501] Re: package libgssapi-krb5-2:amd64 1.16-2ubuntu0.1 failed to install/upgrade: függőségi hibák - e csomag beállítatlan maradt

2019-02-07 Thread Eduardo dos Santos Barretto
** Changed in: krb5 (Ubuntu) Assignee: Eduardo dos Santos Barretto (ebarretto) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1814501 Title: package libgssapi-krb5-2:amd64 1

[Bug 1813837] Re: Multiple vulnerabilities affecting 4.5.0.7

2019-01-30 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public Security ** Changed in: coturn (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1813837 Title: Mult

[Bug 1805690] Re: [MIR] python-django-debreach

2019-01-24 Thread Eduardo dos Santos Barretto
I reviewed python-django-debreach version 1.5.2-0ubuntu1 as checked into disco as of this writing. This shouldn't be considered a full audit but rather a quick gauge of maintainability. Django-debreach is a project that adds basic/extra mitigation against BREACH attacks for Django projects. - No

[Bug 1809156] Re: E1000 guest to host escape

2019-01-21 Thread Eduardo dos Santos Barretto
It truly does! Thanks for the debdiffs. Regarding trusty, my colleague mentioned that you will do a version update, does it include this fix or should I update trusty anyway? Thanks again -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the

[Bug 1805690] Re: [MIR] python-django-debreach

2019-01-18 Thread Eduardo dos Santos Barretto
** Changed in: python-django-debreach (Ubuntu) Assignee: Eduardo dos Santos Barretto (ebarretto) => Ubuntu Security Team (ubuntu-security) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1805

[Bug 1809156] Re: E1000 guest to host escape

2019-01-18 Thread Eduardo dos Santos Barretto
Hi Gianfranco, >It is possible that the current version 5.2.18-dfsg-2~ubuntu18.04.1 is not >installed on some systems. >> how? I was wondering if anyone had version 5.2.18-dfsg-2 installed and didn't do updates ever since, but this is a rare case. >>5.2.18-dfsg-2~ubuntu18.04.1 updates (multiver

[Bug 1809156] Re: E1000 guest to host escape

2019-01-17 Thread Eduardo dos Santos Barretto
Hi Giangranco, Thanks for providing debdiffs for the trusty and xenial! Regarding the version on bionic, it will be 5.2.18-dfsg-2ubuntu18.04.2. It is possible that the current version 5.2.18-dfsg-2~ubuntu18.04.1 is not installed on some systems. 5.2.18-dfsg-2ubuntu18.04.2 will supersede 5.2.18-

[Bug 1811531] Re: remote execution vulnerability

2019-01-17 Thread Eduardo dos Santos Barretto
Thanks Luca, The packages are being uploaded and should be available in the archive in a few minutes. Thanks ** Changed in: zeromq3 (Ubuntu) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu

[Bug 1805690] Re: [MIR] python-django-debreach

2019-01-16 Thread Eduardo dos Santos Barretto
** Changed in: python-django-debreach (Ubuntu) Assignee: Ubuntu Security Team (ubuntu-security) => Eduardo dos Santos Barretto (ebarretto) ** Changed in: python-django-debreach (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a mem

[Bug 1459692] Re: [MIR] anope

2019-01-16 Thread Eduardo dos Santos Barretto
ssues. Security team ACK for promoting anope to main. ** Changed in: anope (Ubuntu) Status: New => Confirmed ** Changed in: anope (Ubuntu) Assignee: Eduardo dos Santos Barretto (ebarretto) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bug

[Bug 1811531] Re: remote execution vulnerability

2019-01-16 Thread Eduardo dos Santos Barretto
** Changed in: zeromq3 (Ubuntu) Status: New => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1811531 Title: remote execution vulnerability To manage notifications about this bu

[Bug 1811531]

2019-01-16 Thread Eduardo dos Santos Barretto
Thanks for opening the ticket and attaching the patch. I've generated a new version for bionic and cosmic, both can be found here: https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa/+packages?field.name_filter=zeromq3 Would anyone mind testing it before we release it? Thanks -

[Bug 1811531]

2019-01-16 Thread Eduardo dos Santos Barretto
Thanks for opening the ticket and attaching the patch. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1811531 Title: remote execution vulnerability To manage notifications about this bug go to: http

[Bug 1811531] Re: remote execution vulnerability

2019-01-15 Thread Eduardo dos Santos Barretto
** Changed in: zeromq3 (Ubuntu) Assignee: (unassigned) => Eduardo dos Santos Barretto (ebarretto) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1811531 Title: remote execution vulnerabil

[Bug 1809156] Re: E1000 guest to host escape

2019-01-11 Thread Eduardo dos Santos Barretto
Thanks for testing!! Great catch on the versioning. It actually needs to be 5.2.18-dfsg-2ubuntu18.14.2 (it could also be 5.2.18-dfsg-2ubuntu18.14.1, but I think this will be confusing for those who check the changelog). It can't be 5.2.18-dfsg-3~ubuntu18.14.1 because that would mean that we are

[Bug 1809156] Re: E1000 guest to host escape

2019-01-11 Thread Eduardo dos Santos Barretto
** Changed in: virtualbox (Ubuntu) Status: Confirmed => In Progress ** Changed in: virtualbox (Ubuntu) Importance: Undecided => High -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/180

[Bug 1809156] Re: E1000 guest to host escape

2019-01-11 Thread Eduardo dos Santos Barretto
n for cosmic as well. Thanks, Eduardo ** Changed in: virtualbox (Ubuntu) Assignee: (unassigned) => Eduardo dos Santos Barretto (ebarretto) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs

[Bug 1033899] Re: [Security] Default PAM settings allow execution of remote API commands without password

2019-01-08 Thread Eduardo dos Santos Barretto
Just confirming that the fix for precise was released: xen-api (1.3.2-5ubuntu0.1) precise-security; urgency=low * SECURITY UPDATE: PAM settings allowed any local user to issue remote API commands (LP: #1031375) - debian/patches/pam-auth-root-xapi-group: Xapi only authenticates the

[Bug 1033899] Re: [Security] Default PAM settings allow execution of remote API commands without password

2019-01-08 Thread Eduardo dos Santos Barretto
precise has seen the end of its life and is no longer receiving any updates. Marking the precise task for this ticket as 'Won't Fix'. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1033899 Title: [Se

[Bug 1015477] Re: pip does not verify SSL certificates

2019-01-08 Thread Eduardo dos Santos Barretto
precise has seen the end of its life and is no longer receiving any updates. Marking the precise task for this ticket as 'Won't Fix'. ** Changed in: python-pip (Ubuntu Precise) Status: Confirmed => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, wh

[Bug 1459692] Re: [MIR] anope

2018-12-13 Thread Eduardo dos Santos Barretto
I reviewed anope version 2.0.6-1 as checked into cosmic. This shouldn't be considered a full audit but rather a quick gauge of maintainability. Anope is a set of services for IRC networks. It allow users/admins to manage their nicks/channels/networks and more. Quick list of services: - NickServ

[Bug 1807419] Re: ubuntu-bug ubuntu-release-upgrader-core

2018-12-07 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1807325]

2018-12-07 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 1806961] Re: Lock can be circumvented by switching tty when using lightdm

2018-12-07 Thread Eduardo dos Santos Barretto
** Tags added: community-security ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1806961 Title: Lock can be circumvented by switc

[Bug 1805715]

2018-12-06 Thread Eduardo dos Santos Barretto
Daniel, since you are dealing with many reports on screensavers/screenlockers, have you seen this before? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1805715 Title: password exposed in cal

[Bug 1205384] Re: Lock can be circumvented by switching to console

2018-12-05 Thread Eduardo dos Santos Barretto
Hi smurfendrek, Please check jarnos comment #89, you need to use light-locker, using dm-tool for lock is not recommended. You could also try with other screen lockers program. Also this is an old bug, if you are still experiencing the problem, please open a new bug. I am unsubscribing the securi

[Bug 1805715] Re: password exposed in calculator input box

2018-12-04 Thread Eduardo dos Santos Barretto
Hi Peter, are you still experiencing this issue? ** Changed in: gnome-screensaver (Ubuntu) Status: New => Invalid ** Changed in: gnome-screensaver (Ubuntu) Status: Invalid => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscr

[Bug 1806687] Re: package ca-certificates 20180409 failed to install/upgrade: installed ca-certificates package post-installation script subprocess returned error exit status 23

2018-12-04 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1806747]

2018-12-04 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 1770655]

2018-12-04 Thread Eduardo dos Santos Barretto
Sorry, for the duplicate message as sarnold already mentioned. Please ignore it. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1770655 Title: nodejs is at 8.10 while 8.11 is a security release. To

[Bug 1770655]

2018-12-04 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 1802653] Re: [HDA-Intel - HDA ATI HDMI, playback] No sound at all

2018-12-04 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1806526] Re: [HDA-Intel - HDA Intel PCH, playback] No sound at all

2018-12-04 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1805614] Re: screensaver crashed on wake up

2018-12-03 Thread Eduardo dos Santos Barretto
*** This bug is a duplicate of bug 1769383 *** https://bugs.launchpad.net/bugs/1769383 Thank you for taking the time to report this bug and helping to make Ubuntu better. This particular bug has already been reported and is a duplicate of bug 1769383, so it is being marked as such. Please look

[Bug 1804949]

2018-12-03 Thread Eduardo dos Santos Barretto
*** This bug is a duplicate of bug 1769383 *** https://bugs.launchpad.net/bugs/1769383 Thank you for taking the time to report this bug and helping to make Ubuntu better. This particular bug has already been reported and is a duplicate of bug 1769383, so it is being marked as such. Please look

[Bug 1806142] Re: plantage Grub

2018-12-03 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1806285] Re: Dock is visible on lock screen

2018-12-03 Thread Eduardo dos Santos Barretto
*** This bug is a duplicate of bug 1769383 *** https://bugs.launchpad.net/bugs/1769383 Thank you for taking the time to report this bug and helping to make Ubuntu better. This particular bug has already been reported and is a duplicate of bug 1769383, so it is being marked as such and marked a

[Bug 1806307] Re: package python-requests 2.18.4-2 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration

2018-12-03 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1459692] Re: [MIR] anope

2018-11-27 Thread Eduardo dos Santos Barretto
** Changed in: anope (Ubuntu) Assignee: Ubuntu Security Team (ubuntu-security) => Eduardo dos Santos Barretto (ebarretto) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1459692 Title: [

[Bug 1799990] Re: tomcat7 doesn't start after upgrade to 7.0.68-1ubuntu0.3

2018-10-30 Thread Eduardo dos Santos Barretto
Thanks SWick! Tomcat7 with the fix published, should reach in the repositories in a few minutes. Thanks for all the feedback and in case of problems just let us know! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launc

[Bug 1799990] Re: tomcat7 doesn't start after upgrade to 7.0.68-1ubuntu0.3

2018-10-30 Thread Eduardo dos Santos Barretto
Can anyone test the tomcat7 built here: https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa/+packages My tests were successful but I would appreciate more feedback about it. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscrib

[Bug 1794999] Re: wrong null pointer check

2018-10-30 Thread Eduardo dos Santos Barretto
So I've talked to upstream and Russel mentioned that a new version is coming next year. For more information: https://sourceforge.net/p/pam-python/tickets/5/ ** Changed in: pam-python (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubun

[Bug 1799990] Re: tomcat7 doesn't start after upgrade to 7.0.68-1ubuntu0.3

2018-10-30 Thread Eduardo dos Santos Barretto
Thank you all for reporting the issue and sorry that it affected you. I'm already working on the fix and will let you know here if you can also test it before we publish it in the repository. >From what I've looked this is a Xenial issue only, so I am marking Trusty as >Invalid. ** Changed in:

[Bug 1798723] Re: package libvdpau1 (not installed) failed to install/upgrade: 尝试覆盖共享的 '/etc/vdpau_wrapper.cfg', 它与软件包 libvdpau1:amd64 中的其他实例不同

2018-10-19 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1798768] Re: package libvamp-hostsdk3v5:amd64 2.7.1~repack0-1 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration

2018-10-19 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1794999] Re: wrong null pointer check

2018-10-19 Thread Eduardo dos Santos Barretto
So I took another look at the patch and the current code and maybe I was too hard in my response. The current code is wrong as it will still make the string comparison even if dot is null. So the patch fixes this problem and should be proposed to upstream. As I mentioned the package also has oth

[Bug 1794999]

2018-10-18 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. I took a look at your patch and I don't think it is the best solution. As far as I can tell, the problem is actually caused because of toolchain (gcc) version in bionic. I've tried to build the same version of pam-py

[Bug 1798487] Re: ubuntu

2018-10-18 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1790256] Re: 1 Crash Annotation GraphicsCriticalError

2018-10-16 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1790257] Re: sudo update issue

2018-10-16 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1791397] Re: Bug

2018-10-16 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1794566] Re: package gnome-accessibility-themes 3.18.0-2ubuntu2 failed to install/upgrade: unable to open '/usr/share/icons/HighContrast/16x16/status/dialog-warning.png.dpkg-new': Operation not p

2018-10-16 Thread Eduardo dos Santos Barretto
*** This bug is a duplicate of bug 1794565 *** https://bugs.launchpad.net/bugs/1794565 Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a

[Bug 1794592] Re: Can't upgrade ubuntu 16.04 up to 18.04

2018-10-16 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1794981] Re: package libtidy5 (not installed) failed to install/upgrade: trying to overwrite '/usr/lib/libtidy.so.5', which is also in package tidy 5.4.0

2018-10-16 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1795006] Re: package libxslt1.1:amd64 1.1.28-2.1 failed to install/upgrade: package libxslt1.1:amd64 is not ready for configuration cannot configure (current status 'half-installed')

2018-10-16 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1795395] Re: plymouthd crashed with SIGSEGV in ply_keyboard_stop_watching_for_renderer_input()

2018-10-16 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1795039] Re: сбой ри обновлении

2018-10-16 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1797707] Re: system friert ständig ein, 18.04.1

2018-10-15 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1797785] Re: heap buffer overflow in ft_font_face_hash of gxps-fonts.c CVE-2018-10733

2018-10-15 Thread Eduardo dos Santos Barretto
** Changed in: libgxps (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1797785 Title: heap buffer overflow in ft_font_face_hash of gxps-fonts.c CVE-2018-1073

[Bug 1797898] Re: evebody

2018-10-15 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1797858] Re: Bug in Ubuntu 18.10 Cosmic Cuttlefish development branch

2018-10-15 Thread Eduardo dos Santos Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1786910] Re: Latest patch breaks command line 'restart all'

2018-10-11 Thread Eduardo dos Santos Barretto
Hi shaochieh.chiang, Thanks for getting back to me. I still need more information, how many services, processes and so on are you monitoring? Can you share your monitrc configuration? Your log also contain errors from nginx ... have you tried to solve them? I'm still not convinced that your

[Bug 1786910] Re: Latest patch breaks command line 'restart all'

2018-10-08 Thread Eduardo dos Santos Barretto
Hi shaochieh.chiang, Could you try to downgrade the package version as below: sudo apt-get install monit=1:5.16-2 And see if you can reproduce the error? I've also found this on monit bug tracker: https://bitbucket.org/tildeslash/monit/issues/327 It might be related to what you're facing. --

[Bug 1786910] Re: Latest patch breaks command line 'restart all'

2018-10-08 Thread Eduardo dos Santos Barretto
Hi shaochieh.chiang, I appreciate you taking the time to report it and helping make Ubuntu better. My tests didn't give the "cannot parse response", and from the feedback received above, it appears that no one faced this so far. So could you give more information? Which are the steps to reprodu

[Bug 1786910] Re: Latest patch breaks command line 'restart all'

2018-10-01 Thread Eduardo dos Santos Barretto
Thanks for testing the package and giving feedback! I really appreciate it. So based on your feedback and on my tests, we just released monit 1:5.16-2ubuntu0.2 to the repository. It should be available for upgrade in a few minutes depending on the mirrors. If you encounter any problems, please

[Bug 1786910] Re: Latest patch breaks command line 'restart all'

2018-09-28 Thread Eduardo dos Santos Barretto
Thanks to Carlos Peñas for proposing the fix. Can anyone test the new version? You can download it from here: https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa/+packages This new version if approved will be released on Monday, as we don't want to release today and not having any

[Bug 1786910] Re: Latest patch breaks command line 'restart all'

2018-09-27 Thread Eduardo dos Santos Barretto
Has anyone seen the same problem in Trusty (Ubuntu 14.04)? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1786910 Title: Latest patch breaks command line 'restart all' To manage notifications about

[Bug 1786910] Re: Latest patch breaks command line 'restart all'

2018-09-27 Thread Eduardo dos Santos Barretto
** Changed in: monit (Ubuntu) Assignee: (unassigned) => Eduardo dos Santos Barretto (ebarretto) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1786910 Title: Latest patch breaks command l

[Bug 1786910] Re: Latest patch breaks command line 'restart all'

2018-09-27 Thread Eduardo dos Santos Barretto
Thanks for reporting this bug and helping make Ubuntu better. I'm sorry this affected you all. I would like you to ask the reporter and all the involved people in the thread to always include the last person listed as Maintainer for the package (you can check this in the debian/changelog) in the

[Bug 1789700] Re: Security issue - I can bypass the password login with Caps Lock.

2018-09-03 Thread Eduardo dos Santos Barretto
** Changed in: gksu (Ubuntu) Status: Incomplete => Invalid ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1789700 Title: S

[Bug 1789703] Re: Errors were encountered while processing: cups-pk-helper E: sub-process /usr/bin/dpkg returned an error code (1)

2018-08-30 Thread Eduardo dos Santos Barretto
*** This bug is a duplicate of bug 1783245 *** https://bugs.launchpad.net/bugs/1783245 ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/178

[Bug 1789528] Re: INSTALL CRASH

2018-08-29 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1789528 Title: INSTALL CRASH To manage notifications about this bug go to: https://bugs.lau

[Bug 1789585] Re: package python-pyparsing 2.0.3+dfsg1-1ubuntu0.1 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration

2018-08-29 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1789585 Title: package python-pyparsing 2.0.3+dfsg1-1ubuntu0.1 failed to install/upgrade:

[Bug 1789630] Re: package systemd-sysv 237-3ubuntu10.3 failed to install/upgrade: installed systemd-shim package post-removal script subprocess returned error exit status 2

2018-08-29 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1789630 Title: package systemd-sysv 237-3ubuntu10.3 failed to install/upgrade: installed s

[Bug 1789328] Re: 'grub-efi-amd64-signed' failed to install into target/

2018-08-28 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1789328 Title: 'grub-efi-amd64-signed' failed to install into target/ To manage notificatio

[Bug 1789072] Re: package phpmyadmin 4:4.6.6-5 failed to install/upgrade: installed phpmyadmin package post-installation script subprocess returned error exit status 1

2018-08-27 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1789072 Title: package phpmyadmin 4:4.6.6-5 failed to install/upgrade: installed phpmyadmi

[Bug 1789116] Re: grub isn't install

2018-08-27 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1789116 Title: grub isn't install To manage notifications about this bug go to: https://bug

[Bug 1789143] Re: package base-files 9.4ubuntu4.7 failed to install/upgrade: package base-files is already installed and configured

2018-08-27 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1789143 Title: package base-files 9.4ubuntu4.7 failed to install/upgrade: package base-fil

[Bug 1789213] Re: package libavcodec-extra 7:3.4.2-2 failed to install/upgrade: dpkg-deb --fsys-tarfile el subproceso devolvió un error con estado de salida 2

2018-08-27 Thread Eduardo dos Santos Barretto
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1789213 Title: package libavcodec-extra 7:3.4.2-2 failed to install/upgrade: dpkg-deb --fs

<    1   2