[Bug 1971192] Re: CVE-2022-0330

2022-05-06 Thread Seth Arnold
Hello Luís, we released a fix for this CVE for linux-azure-fde on 22 February 2022 in USN-5294-2: https://ubuntu.com/security/notices/USN-5294-2 The linux-azure-fde source package is actually just some scripts, and our kernel update tooling shows incorrect results on the webpage as a result. Hopef

[Bug 1971101] Re: package linux-image-5.13.0-40-generic 5.13.0-40.45~20.04.1 failed to install/upgrade: run-parts: /etc/kernel/postinst.d/initramfs-tools exited with return code 1

2022-05-06 Thread Seth Arnold
Hello, note your filesystem is full: Filesystem 1K-blocks Used Available Use% Mounted on udev 9812920981292 0% /dev tmpfs 202808 1508201300 1% /run /dev/sda5 11167656 11000192 0 100% / That causes errors like this: cp: error

[Bug 1971098] Re: package usrmerge 25ubuntu1.1 failed to install/upgrade: »installiertes usrmerge-Skript des Paketes post-installation«-Unterprozess gab den Fehlerwert 1 zurück

2022-05-06 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1971098] Re: package usrmerge 25ubuntu1.1 failed to install/upgrade: »installiertes usrmerge-Skript des Paketes post-installation«-Unterprozess gab den Fehlerwert 1 zurück

2022-05-06 Thread Seth Arnold
Hello, your bug has a few things: cp: reguläre Datei '/usr/opt/eset/esets/lib/libesets_pac.so' kann nicht angelegt werden: Datei oder Verzeichnis nicht gefunden This error message means something is broken with your antivirus program. I suggest contacting ESET about this. Give them a link to this

[Bug 1970751] Re: package grub-pc 2.04-1ubuntu26.15 failed to install/upgrade: installed grub-pc package post-installation script subprocess returned error exit status 10

2022-05-06 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1970779] Re: Multiple vulnerabilities in Bionic, Focal and Impish

2022-05-06 Thread Seth Arnold
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970779 Title: Multiple vulnerabilities in Bionic, Focal and Impish To manage noti

[Bug 1970748] Re: package slack (not installed) failed to install/upgrade: el subproceso instalado paquete slack script pre-removal devolvió el código de salida de error 2

2022-05-06 Thread Seth Arnold
This looks like a third-party package, not the 'slack' configuration management package. I suggest filing a bug report with whoever provided the slack-desktop package you're installing. Thanks ** Package changed: slack (Ubuntu) => ubuntu -- You received this bug notification because you are a m

[Bug 1970748] Re: package slack (not installed) failed to install/upgrade: el subproceso instalado paquete slack script pre-removal devolvió el código de salida de error 2

2022-05-06 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1970674]

2022-05-06 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 1970593] Re: package firefox-locale-de 1:1snap1-0ubuntu2 failed to install/upgrade: Abhängigkeitsprobleme - verbleibt unkonfiguriert

2022-05-06 Thread Seth Arnold
Hello, this looks like the starting point of the problem: Start-Date: 2022-04-17 16:08:22 Commandline: apt-get purge firefox Purge: firefox-locale-de:amd64 (1:1snap1-0ubuntu2), firefox:amd64 (1:1snap1-0ubuntu2) End-Date: 2022-04-17 16:08:24 Start-Date: 2022-04-17 16:12:17 Commandline: apt-get

[Bug 1970425] Re: clamtk can't quarantine or delete specific malware

2022-05-06 Thread Seth Arnold
Thanks for reporting it; this is surprisingly the best resolution I've ever seen for "this file trips a security scanner" I've ever seen. Nice. :) ** Information type changed from Private Security to Public Security ** Changed in: clamtk (Ubuntu) Status: New => Invalid -- You received th

[Bug 1970507]

2022-05-06 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 1970294] Re: fwsnort --ipt-apply

2022-05-06 Thread Seth Arnold
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970294 Title: fwsnort --ipt-apply To manage notifications about this bug go to: h

[Bug 1970260] Re: SECURITY: safe.directory backport doesn't check key name

2022-05-06 Thread Seth Arnold
Thanks, Ray ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970260 Title: SECURITY: safe.directory backport doesn't check key nam

[Bug 1970158] Re: Login Password error

2022-05-06 Thread Seth Arnold
I'm sorry, this doesn't make enough sense for me to know where to re- assign this. I suggest giving a lot more details about what applications you're using, etc. Thanks ** Information type changed from Private Security to Public ** Package changed: linux (Ubuntu) => ubuntu -- You received this

[Bug 1970160] Re: Kubuntu iso Image GPT problem

2022-05-06 Thread Seth Arnold
This may be a hardware problem, or a mistake on how your drive is formatted. Hopefully someone else will know what questions to ask. ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to U

[Bug 1970206] Re: Cursor goes missing in games

2022-05-06 Thread Seth Arnold
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1970206 Title: Cursor goes missing in games To manage notifications about this bug go to: h

[Bug 1970228]

2022-05-06 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

Re: [Bug 1971888] [NEW] Can not ssh to github.com or gitlab.com when upgrading to 22.04

2022-05-05 Thread Seth Arnold
On Thu, May 05, 2022 at 09:09:07PM -, Alvaro wrote: > acs@lsp-022:~$ ssh -vT g...@github.com > ... > debug1: connect to address 140.82.121.4 port 22: Connection timed out Note that "Connection timed out" is an error at the TCP level, that indicates that your computer wasn't able to establish a

[Bug 1971650] Re: wrong check for "server" in libssl3.postinst

2022-05-05 Thread Seth Arnold
Possibly related to https://bugs.launchpad.net/bugs/1832421 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1971650 Title: wrong check for "server" in libssl3.postinst To manage notifications about t

[Bug 1971504] Re: Multiple vulnerabilities in Bionic, Focal, Impish, Jammy and Kinetic

2022-05-04 Thread Seth Arnold
Hello Luís, thanks; I just glanced at the debdiffs quickly, and noticed this one appears to missing the quilt series changes: +varnish (6.6.1-1ubuntu0.1) jammy-security; urgency=medium Please also report back how you've tested the patches. Thanks -- You received this bug notification because y

[Bug 1970480] Re: please remove elog

2022-05-03 Thread Seth Arnold
Thanks Steve; I mentioned to the upstream maintainers that we would probably not remove it from supported releases, and they seemed okay with this. Thanks! ** Changed in: elog (Ubuntu) Status: Incomplete => Fix Released -- You received this bug notification because you are a member of Ubu

[Bug 1971214] [NEW] archive is missing dsc index

2022-05-02 Thread Seth Arnold
Public bug reported: Hello, I wanted to use apt-file -I dsc recently and found that Ubuntu's archive is missing the Contents-source files that the Debian repo has, compare: http://ftp.debian.org/debian/dists/bookworm/main/ vs http://archive.ubuntu.com/ubuntu/dists/kinetic The Contents-source.gz

[Bug 1963834] Re: openssl 3.0 - SSL: UNSAFE_LEGACY_RENEGOTIATION_DISABLED]

2022-04-26 Thread Seth Arnold
Yes, managing the configurations for the huge variety of cryptography toolkits on a Linux system is definitely something of a chore. It would be nice to give people one command they could use to return to unsafe- but-compatible cryptography -- or enforce only modern cryptography. Our friends at Re

[Bug 1970459] Re: import of ca-certificate in browser does not work

2022-04-26 Thread Seth Arnold
I switched this from ca-certificates to firefox and chromium-browser, since both browsers manage their own certificate lists and don't use the system-provided ca-certificates. (You manage that with different tools, see the first few lines of /etc/ca-certificates.conf for details.) Thanks ** Packa

[Bug 1970480] [NEW] please remove elog

2022-04-26 Thread Seth Arnold
Public bug reported: Hello, the upstream developers of elog have asked Debian and Ubuntu to remove elog from the repositories because the packages are unmaintained: https://bugs.debian.org/1010196 https://bugs.debian.org/1010197 https://ubuntu.com/security/cves?q=&package=elog&priority=&version=&

[Bug 1969943] Re: System updates fail to complete.

2022-04-22 Thread Seth Arnold
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see https://wiki.ubuntu.

[Bug 1969938] Re: Ao tentar atualizar os programas pelo atualizador ele informa que não há conexão com a internet mesmo ela estando conectada

2022-04-22 Thread Seth Arnold
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1969938 Title: Ao tentar atualizar os programas pelo atualizador ele informa que não há co

[Bug 1969741] Re: package snort (not installed) failed to install/upgrade: installed snort package post-installation script subprocess returned error exit status 1

2022-04-21 Thread Seth Arnold
Hello Adil, looking through the terminal log it looks like you've selected an incorrect interface for snort to listen on; this is probably not a bug. Thanks ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 1969679]

2022-04-20 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 1969614] Re: package linux-image-5.13.0-40-generic (not installed) failed to install/upgrade: unable to open '/boot/vmlinuz-5.13.0-40-generic.dpkg-new': Operation not permitted

2022-04-20 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1969593] Re: rules to prevent non-root users from rebooting not taken into account

2022-04-20 Thread Seth Arnold
** Also affects: systemd (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1969593 Title: rules to prevent non-root users from rebooting not taken in

[Bug 1969593] Re: rules to prevent non-root users from rebooting not taken into account

2022-04-20 Thread Seth Arnold
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1969593 Title: rules to prevent non-root users from rebooting not taken into accoun

[Bug 1968806] Re: Clamscan reports Unix.Tool.Pnscan-8031486-0 in 1.12+git20180612-2 pnscan version

2022-04-19 Thread Seth Arnold
The frog is definitely weird, but clamscan is almost certainly just reporting a tool that might be used by attackers. There's lots of those. Does it also report tcpdump? wireshark? ettercap? nc? telnet? nmap? socat? stunnel? Thanks -- You received this bug notification because you are a member o

[Bug 1968845] Re: Upgrade to 22.04 from 20.04 ends with dbus installation asking for a reboot

2022-04-19 Thread Seth Arnold
This may be a duplicate of https://launchpad.net/bugs/1969162 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1968845 Title: Upgrade to 22.04 from 20.04 ends with dbus installation asking for a rebo

[Bug 1969502] Re: package latex-cjk-common 4.8.4+git20170127-2 failed to install/upgrade: o subprocesso instalado, do pacote latex-cjk-common, o script post-installation retornou erro do status de saí

2022-04-19 Thread Seth Arnold
This looks like an emacs failure to me: Install emacsen-common for emacs emacsen-common: Handling install of emacsen flavor emacs emacs: error while loading shared libraries: libotf.so.0: cannot open shared object file: No such file or directory ERROR: install script from emacsen-common package f

[Bug 1969231] Re: Touch pad not working

2022-04-19 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1969416] Re: league of legends crashed

2022-04-19 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1969144] Re: /Dev/Sda1 (en resumen) fue lo que me encontré al encender mi ordenador seguido de varios numeros

2022-04-19 Thread Seth Arnold
** Package changed: ubuntu-docs (Ubuntu) => ubuntu ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1969144 Title: /Dev/Sda1 (en resumen) fu

[Bug 1969118] Re: Certificate viewer shows extra bytes for RSA keys

2022-04-19 Thread Seth Arnold
Hello Mikko, thanks for the report; I believe that's working as intended, those bytes are part of the DER encoding; there's an excellent answer at https://crypto.stackexchange.com/a/19982/1400 that describes the meanings of each of those bytes. Thanks ** Information type changed from Private Secu

[Bug 1968845] Re: Upgrade to 22.04 from 20.04 ends with dbus installation asking for a reboot

2022-04-19 Thread Seth Arnold
Here's the postinst I've got for that package. Maybe the reload_dbus_config() could use a --reply-timeout=5000 or something? Thanks $ cat /fst/trees/ubuntu/main/d/dbus/dbus_1.12.20-2ubuntu4/debian/dbus.postinst #!/bin/sh # Copyright © 2003 Colin Walters # Copyright © 2006 Sjoerd Simons set -e

[Bug 1968806] Re: Clamscan reports Unix.Tool.Pnscan-8031486-0 in 1.12+git20180612-2 pnscan version

2022-04-19 Thread Seth Arnold
Hello, my guess is clamav is helpfully pointing out that the program exists at all; I doubt it has any intelligence beyond looking for a few markers for pnscan within files named pnscan. Diagnosing load issues takes a bit of work; I suggest starting with https://www.brendangregg.com/blog/2015-12-0

[Bug 1968845] Re: Upgrade to 22.04 from 20.04 ends with dbus installation asking for a reboot

2022-04-19 Thread Seth Arnold
Yikes, does it actually *stop* at that point? That's .. not ideal. Thanks -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1968845 Title: Upgrade to 22.04 from 20.04 ends with dbus installation asking

[Bug 1968806] Re: Clamscan reports Unix.Tool.Pnscan-8031486-0 in 1.12+git20180612-2 pnscan version

2022-04-19 Thread Seth Arnold
** Information type changed from Private Security to Public Security ** Changed in: pnscan (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1968806 Title: Cla

[Bug 1964827] Re: zfs-linux upstream at 2.1.4, jammy has 2.1.2

2022-04-19 Thread Seth Arnold
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1964827 Title: zfs-linux upstream at 2.1.4, jammy has 2.1.2 To manage notifications about th

[Bug 1968334] Re: libssh2 upgrade

2022-04-19 Thread Seth Arnold
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1968334 Title: libssh2 upgrade To manage notifications about this bug go to: https

[Bug 1968305] Re: sshd_config.d overrides not working

2022-04-08 Thread Seth Arnold
This reminds me of several previous bugs; this may or may not be a duplicate, and this may or may not be intentional behaviour. Hopefully these are are useful and save some debugging effort: https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/1922212 https://bugs.launchpad.net/ubuntu/+source/op

[Bug 1968047] Re: Ubuntu 22.04 Beta - Unable to compile ruby version 2.7.5, 3.0.3 and 3.3.3 problem with the openssl-dev package

2022-04-06 Thread Seth Arnold
Hopefully this is helpful for you: https://sources.debian.org/data/main/r/ruby3.0/3.0.3-1/debian/patches/Update- openssl-to-version-3.0.0.patch Thanks -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/19

[Bug 1948748] Re: [MIR] swtpm

2022-03-31 Thread Seth Arnold
I reviewed libtpms 0.9.0-0ubuntu4 as checked into jammy. This shouldn't be considered a full audit but rather a quick gauge of maintainability. I certainly didn't carefully review if libtpms is fit for use as a software TPM. It appears to have been programmed with care and dilligence and the upstr

[Bug 1967450] Re: When switching from 175% fractional scaling back to integer scaling, only a quarter of the screen is used

2022-03-31 Thread Seth Arnold
But who would keep that resolution when it sure *looks* broken? I can understand the "it's not new and we don't know how to fix it" :) but probably users won't know that they'll be fine after a reboot. Thanks -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1966572] Re: Chromium Zero Day

2022-03-31 Thread Seth Arnold
B[], aha, you've received no Chromium updates since November 2021 because the author of that PPA hasn't provided any. apt-file will report what files are in the Ubuntu package whether or not you have it installed. It's very handy to see what files are in an Ubuntu package without installing it. d

[Bug 1966572] Re: Chromium Zero Day

2022-03-30 Thread Seth Arnold
The 20.04 LTS chromium-browser deb package exists only to install the chromium snap and deliver a few files to the filesystem outside the snap packaging system: $ apt-file show chromium-browser chromium-browser: /usr/bin/chromium-browser chromium-browser: /usr/share/applications/chromium-browser.d

[Bug 1948748] Re: [MIR] swtpm

2022-03-29 Thread Seth Arnold
libtpms might need to pull in https://github.com/stefanberger/libtpms/commit/d78a4520ba3157087e1e438b519618f26d85fae3 -- I think without this fix, the following algorithms may not work right: #define ALG_KDF1_SP800_56A_VALUE0x0020 #define TPM_ALG_KDF1_SP800_56A (TPM_ALG_ID)(ALG_KD

[Bug 1948748] Re: [MIR] swtpm

2022-03-25 Thread Seth Arnold
I reviewed swtpm 0.6.1-0ubuntu5 as checked into jammy. This shouldn't be considered a full audit but rather a quick gauge of maintainability. I especially didn't audit the fuse/cuse interface, nor suitability of the software tpm to replace a hardware tpm. And especially especially I didn't invest

[Bug 1953363] Re: [MIR] python-xmlschema, elementpath, importlib-resources

2022-03-25 Thread Seth Arnold
I'm not entirely sure when the actual real for real really deadline is, but if it's monday, probably not. Sorry. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1953363 Title: [MIR] python-xmlschema,

[Bug 1965958] Re: list-oem-metapackages crashed with AttributeError in packages_for_modalias(): 'Cache' object has no attribute 'packages'

2022-03-22 Thread Seth Arnold
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1965958 Title: list-oem-metapackages crashed with AttributeError in packages_for_modalias(

[Bug 1965857] Re: software-properties-gtk crashed with AttributeError in packages_for_modalias(): 'Cache' object has no attribute 'packages'

2022-03-22 Thread Seth Arnold
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1965857 Title: software-properties-gtk crashed with AttributeError in packages_for_modalia

[Bug 1965661] Re: software-properties-gtk crashed with AttributeError in packages_for_modalias(): 'Cache' object has no attribute 'packages'

2022-03-22 Thread Seth Arnold
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1965661 Title: software-properties-gtk crashed with AttributeError in packages_for_modalia

[Bug 1948748] Re: [MIR] swtpm

2022-03-18 Thread Seth Arnold
Can an update for this issue be incorporated before a release? https://github.com/stefanberger/swtpm/security/advisories/GHSA-2qgm-8xf4-3hqw It's something Coverity spotted in our version, and I was very pleased to see that there's already an advisory for this :) saving me some effort. Thanks -

[Bug 1885990] Re: server: Match has no effect in include file (upstream 3122)

2022-03-16 Thread Seth Arnold
I can't speak for the SRU team, but it's entirely possible that if you prepare and test a debdiff, and show that this can be fixed, you could drive an SRU through to completion; see https://wiki.ubuntu.com/StableReleaseUpdates for more information. Thanks -- You received this bug notification be

[Bug 1964098] Re: [FFe] Versioned packages for Rust toolchain

2022-03-14 Thread Seth Arnold
I can really appreciate the appeal of a "do nothing today" solution but I'm worried about how much work, and unknown surprises, await us on our *first* update in the future. At some point, we'll have a security issue in a rust program that can only be solved in coordination with a toolchain update

[Bug 1964642] Re: Packer virtualbox ssh can't connect to unattended Ubuntu 20.04.1/2/3/4 but can connect to Ubuntu 20.4

2022-03-14 Thread Seth Arnold
Yeah it seems unlikely to be ssh to me -- can you ping the machine? does virtualbox networking do interfaces that can ping? Does virtualbox offer a 'console view' that you can use to debug the system? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscrib

[Bug 1964561] Re: package libpam-runtime 1.3.1-5ubuntu4.3 failed to install/upgrade: installed libpam-runtime package post-installation script subprocess returned error exit status 255

2022-03-11 Thread Seth Arnold
Corruption was my first idea, too, but the Dependencies.txt didn't report debsums mismatches. Thanks for the explanations. ** Also affects: debconf (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscri

[Bug 1957077] Re: SIGSEGV during processing of unicode string

2022-03-11 Thread Seth Arnold
** Changed in: unzip (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1957077 Title: SIGSEGV during processing of unicode string To manage notifications about

[Bug 1960953] Re: lockscreen is bypassed after screensaver segfault

2022-03-11 Thread Seth Arnold
** Changed in: mate-screensaver (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1960953 Title: lockscreen is bypassed after screensaver segfault To ma

[Bug 1961457] Re: package linux-image-5.13.0-28-generic 5.13.0-28.31 failed to install/upgrade: triggers looping, abandoned

2022-03-11 Thread Seth Arnold
Hello, the tail end of the dpkg terminal log suggests mesa-amdgpu-vdpau- drivers might be to blame; I don't see that package on my local mirror, did this come from outside Ubuntu? If so, you may need to report the issue there. Thanks -- You received this bug notification because you are a member

[Bug 1961457] Re: package linux-image-5.13.0-28-generic 5.13.0-28.31 failed to install/upgrade: triggers looping, abandoned

2022-03-11 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1961854] Re: Thunderbid saves accepted calendar events in different identity

2022-03-11 Thread Seth Arnold
Hello Bartłomiej, can you report this to the upstream developers? This will need their input to address. Thanks ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. http

[Bug 1962041] Re: package linux-azure-tools-5.4.0-1070 (not installed) failed to install/upgrade: trying to overwrite '/usr/lib/libcpupower.so.5.4.0-1070', which is also in package linux-azure-cvm-too

2022-03-11 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1962212] Re: package nvidia-dkms-470 470.103.01-0ubuntu0.20.04.1 failed to install/upgrade: installed nvidia-dkms-470 package post-installation script subprocess returned error exit status 10

2022-03-11 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1962358] Re: grub unable to instal

2022-03-11 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1962705] Re: package qmail 1.06-6.2~deb10u1build0.20.04.1 failed to install/upgrade: el subproceso instalado paquete qmail script post-installation devolvió el código de salida de error 1

2022-03-11 Thread Seth Arnold
Hello Alejandro, the error message from the package installation script is: --- The hostname -f command returned: amora-diarioas Your system needs to have a fully qualified domain name (fqdn) in order to install the var-qmail packages. Installation aborted --- You can probably fix this via th

[Bug 1962705] Re: package qmail 1.06-6.2~deb10u1build0.20.04.1 failed to install/upgrade: el subproceso instalado paquete qmail script post-installation devolvió el código de salida de error 1

2022-03-11 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1962740] Re: Out-of-bounds read during processing 7zip archive

2022-03-11 Thread Seth Arnold
Hello Nils, have you reported this issue upstream yet? Has a bug or fix already been created? Thanks ** Changed in: p7zip (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpa

[Bug 1963714] Re: Internal hard disk partition cannot be mounted manually

2022-03-11 Thread Seth Arnold
Hello Girish, there's some errors in your dmesg that make me think you may have hardware problems. It's not clear, but it's possible. Also, there's some packages in the Dependencies.txt marked with [origin: unknown] that might be worth investigating. Thanks ** Information type changed from Privat

[Bug 1963715] Re: issue upon installation of ubuntu along side win 10

2022-03-11 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1963861] Re: Can't tell what application will be launched with custom schemes

2022-03-11 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1964561] Re: package libpam-runtime 1.3.1-5ubuntu4.3 failed to install/upgrade: installed libpam-runtime package post-installation script subprocess returned error exit status 255

2022-03-11 Thread Seth Arnold
These lines from the logs look most relevant: Unpacking libpam-runtime (1.3.1-5ubuntu4.3) over (1.3.1-5ubuntu4.1) ... Setting up libpam-runtime (1.3.1-5ubuntu4.3) ... Can't locate object method "new" via package "Debconf::Element::Noninteractive::Multiselect" (perhaps you forgot to load "Debconf

[Bug 1964461] Re: under 22.04 development release, fail2ban won't start

2022-03-10 Thread Seth Arnold
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1964461 Title: under 22.04 development release, fail2ban won't start To manage notification

[Bug 1964370] Re: Vulnerability in Kernel 5.4.0-104

2022-03-09 Thread Seth Arnold
Linux Mint replaces the kernel; if you're having errors with basic kernel operations you'll need to seek support from the Mint community. Thanks. ** Information type changed from Private Security to Public ** Changed in: linux (Ubuntu) Status: New => Invalid -- You received this bug noti

[Bug 1964319] Re: install over Zorin OS 16 - after gparted wipe of Zorin OS

2022-03-09 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privile

[Bug 1964319] Re: install over Zorin OS 16 - after gparted wipe of Zorin OS

2022-03-09 Thread Seth Arnold
Hello Johnny, there's indications in your logs that suggest you may have broken firmware or perhaps broken hardware. It's possible that your problems here are caused by whatever the logs have reported, but it might also be something unrelated. It'd be worth trying to do a BIOS update for your moth

[Bug 1964118] Re: package nvidia-utils-510 (not installed) failed to install/upgrade: trying to overwrite '/usr/bin/nvidia-bug-report.sh', which is also in package nvidia-340 340.108-0ubuntu5.20.04.2

2022-03-08 Thread Seth Arnold
** Also affects: nvidia-graphics-drivers-340 (Ubuntu) Importance: Undecided Status: New ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/b

[Bug 1963751] Re: focal security update 2.34.6-0ubuntu0.20.04.1 cannot be automatically installed due to new dependency

2022-03-07 Thread Seth Arnold
Thanks for doing the digging to confirm the cause; I suspect unattended- upgrades should be modified to perform something similar to apt upgrade, rather than apt-get upgrade, and bring in new dependencies when necessary. A lot of systems never have interactive users any more. Thanks ** Changed in

[Bug 1963861] Re: Can't tell what application will be launched with custom schemes

2022-03-07 Thread Seth Arnold
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1963861 Title: Can't tell what application will be launched with custom schemes To

[Bug 1963834] Re: openssl 3.0 - SSL: UNSAFE_LEGACY_RENEGOTIATION_DISABLED]

2022-03-07 Thread Seth Arnold
It looks like this was added in: https://github.com/openssl/openssl/commit/72d2670bd21becfa6a64bb03fa55ad82d6d0c0f3 in order to address servers that have not yet been updated for CVE-2009-3555. It's possible to add a flag at the C level to connect insecurely, SSL_OP_LEGACY_SERVER_CONNECT, but I

[Bug 1963751] Re: focal security update 2.34.6-0ubuntu0.20.04.1 cannot be automatically installed due to new dependency

2022-03-07 Thread Seth Arnold
Hello Steve, thanks for the report; can you run a manual: sudo apt update && sudo apt upgrade and report back the apt output, which will give a better idea of what exactly is holding back the upgrade? Thanks ** Changed in: webkit2gtk (Ubuntu) Status: New => Incomplete -- You receiv

[Bug 1963751] Re: focal security update 2.34.6-0ubuntu0.20.04.1 cannot be automatically installed due to new dependency

2022-03-07 Thread Seth Arnold
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1963751 Title: focal security update 2.34.6-0ubuntu0.20.04.1 cannot be automaticall

[Bug 1936907] Re: [MIR] ADSys

2022-02-23 Thread Seth Arnold
I reviewed adsys 0.8 as checked into jammy. This shouldn't be considered a full audit but rather a quick gauge of maintainability. As usual with golang code, there's vastly more code in the package than we've authored, and it's not feasible to review the entirety. adsys allows network administrat

[Bug 1962036] Re: dbus was stopped during today's jammy update, breaking desktop

2022-02-23 Thread Seth Arnold
This reminds me a lot of https://bugs.launchpad.net/bugs/1871538 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1962036 Title: dbus was stopped during today's jammy update, breaking desktop To manag

[Bug 1961972] Re: NFS update demands removal of SSSD

2022-02-23 Thread Seth Arnold
Thanks for the concern, probably it's just packages that haven't moved through the full publishing process yet. If it's still around, maybe including the full apt-get upgrade output would help. Thanks ** Information type changed from Private Security to Public -- You received this bug notifica

[Bug 1961459] Re: adsys pam issues

2022-02-22 Thread Seth Arnold
Heh, so Dmitry might actually remove the other 'free' calls in the error paths :) -- and he spotted that the strdup() calls are unchecked: https://github.com/linux-pam/linux-pam/issues/444 It might be worth mirroring whatever he decides to do. Thanks ** Bug watch added: github.com/linux-pam/lin

[Bug 1961459] Re: adsys pam issues

2022-02-22 Thread Seth Arnold
Oh yes, the waitpid() stuff.. if it works in testing, leaving it alone is probably fine then. Thanks. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1961459 Title: adsys pam issues To manage notific

[Bug 1961459] Re: adsys pam issues

2022-02-22 Thread Seth Arnold
Hah so I've got another bug to report then? :) Thanks! ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1961459 Title: adsys pam issues To

[Bug 1950317] Re: [MIR] Wireguard

2022-02-22 Thread Seth Arnold
** Changed in: wireguard (Ubuntu) Status: Confirmed => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1950317 Title: [MIR] Wireguard To manage notifications about this bug go to

[Bug 1960863] Re: armv8 paca: poly1305 users see segfaults when pointer authentication in use on AWS Graviton 3 instances

2022-02-16 Thread Seth Arnold
None of us are ARM architecture experts but the upstream code nearby doesn't look like it's changed since this patch was introduced: https://github.com/openssl/openssl/blame/master/crypto/poly1305/asm/poly1305-armv8.pl https://github.com/openssl/openssl/blame/OpenSSL_1_1_1-stable/crypto/poly1305/a

[Bug 1960264] Re: 503 errors for Jammy PPAs

2022-02-11 Thread Seth Arnold
Are there any log entries in your proxy that might help explain what's happening? Thanks -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1960264 Title: 503 errors for Jammy PPAs To manage notificati

[Bug 1953022] Re: refcount leak in pep_sock_accept

2022-02-02 Thread Seth Arnold
It looks like I lost track of this browser tab a lot longer than I expected. Thanks Hangyu Hua for the fixes! :) ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. htt

[Bug 1959841] Re: Lower 8 bits are always zero in stackguard value

2022-02-02 Thread Seth Arnold
Ah, sorry, I see I lost a race condition :) thanks ** Changed in: gcc-defaults (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1959841 Title: Lower 8 bi

[Bug 1959841] Re: Lower 8 bits are always zero in stackguard value

2022-02-02 Thread Seth Arnold
Hello, the stack checking is intended to detect simplistic overwrites of stack control structures. If an attacker is able to overwrite a single NUL in the canary with a NUL supplied from an input string, but no further, then the stack control structures are still intact and undamaged. As far as the

<    1   2   3   4   5   6   7   8   9   10   >