[Bug 1661805] Re: Saved passwords for HTTPS sites can be accessed by HTTP sites

2017-03-31 Thread Jeremy Bicha
** Changed in: epiphany-browser (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1661805 Title: Saved passwords for HTTPS sites can be accessed by

[Bug 1661805] Re: Saved passwords for HTTPS sites can be accessed by HTTP sites

2017-03-30 Thread Launchpad Bug Tracker
This bug was fixed in the package epiphany-browser - 3.22.6-0ubuntu1 --- epiphany-browser (3.22.6-0ubuntu1) yakkety-security; urgency=medium * SECURITY UPDATE: Saved passwords were viewable by a man-in-the-middle attack website. This has been mitigated by moving all existing

[Bug 1661805] Re: Saved passwords for HTTPS sites can be accessed by HTTP sites

2017-03-30 Thread Launchpad Bug Tracker
This bug was fixed in the package epiphany-browser - 3.18.11-0ubuntu1 --- epiphany-browser (3.18.11-0ubuntu1) xenial-security; urgency=medium * SECURITY UPDATE: Saved passwords were viewable by a man-in-the-middle attack website. This has been mitigated by moving all existing

[Bug 1661805] Re: Saved passwords for HTTPS sites can be accessed by HTTP sites

2017-03-24 Thread Jeremy Bicha
I just used a bzr packaging only branch and ran 'bzr diff' to produce the diffs I posted. Grab the tarball of the debian/ directory and extract it. bzr init echo -e '[BUILDDEB]\nmerge = True' > .bzr-builddeb/default.conf bzr add bzr commit -m "Existing packaging' Apply the diff You can then

[Bug 1661805] Re: Saved passwords for HTTPS sites can be accessed by HTTP sites

2017-03-24 Thread Jeremy Bicha
de7ea87dc450702bde620033f9e2ce807859727d007396d86b09f2b82397fcc2 epiphany-browser_3.22.6.orig.tar.xz 81c4219cb68e45af7729c78faa557d93a6b9520f289aef24b6d67e3a96dfcc82 epiphany-browser_3.18.11.orig.tar.xz -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1661805] Re: Saved passwords for HTTPS sites can be accessed by HTTP sites

2017-03-24 Thread Seth Arnold
Hello Jeremy, I had trouble building these packages locally before uploading. I downloaded new tarballs from https://download.gnome.org/sources/epiphany/ and renamed them as needed, applied your debdiffs, and got the following errors when trying to build: dpkg-source: info: using source format

[Bug 1661805] Re: Saved passwords for HTTPS sites can be accessed by HTTP sites

2017-03-19 Thread Jeremy Bicha
** Patch added: "epiphany-lp1661805-xenial.debdiff" https://bugs.launchpad.net/ubuntu/+source/epiphany-browser/+bug/1661805/+attachment/4840679/+files/epiphany-lp1661805-xenial.debdiff ** Changed in: epiphany-browser (Ubuntu Xenial) Status: New => Confirmed ** Changed in:

[Bug 1661805] Re: Saved passwords for HTTPS sites can be accessed by HTTP sites

2017-03-19 Thread Jeremy Bicha
I used the simpler 3.22.6-0ubuntu1 version number since 3.22 is yakkety only (and does not conflict with zesty). Similar for xenial with 3.18. ** Description changed: Impact == Saved passwords are accessible by HTTP sites in epiphany 3.18.10-0ubuntu1 for Ubuntu 16.04 LTS,

[Bug 1661805] Re: Saved passwords for HTTPS sites can be accessed by HTTP sites

2017-02-06 Thread Seth Arnold
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 1661805] Re: Saved passwords for HTTPS sites can be accessed by HTTP sites

2017-02-05 Thread Jeremy Bicha
Fixed in zesty: https://launchpad.net/ubuntu/+source/epiphany- browser/3.22.6-1ubuntu1 ** Changed in: epiphany-browser (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1661805] Re: Saved passwords for HTTPS sites can be accessed by HTTP sites

2017-02-03 Thread Bug Watch Updater
** Changed in: epiphany-browser Status: Unknown => Fix Released ** Changed in: epiphany-browser Importance: Unknown => High -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1661805 Title:

[Bug 1661805] Re: Saved passwords for HTTPS sites can be accessed by HTTP sites

2017-02-03 Thread Adolfo Jayme
** Changed in: epiphany-browser (Ubuntu) Importance: Undecided => High ** Changed in: epiphany-browser (Ubuntu Yakkety) Importance: Undecided => High ** Changed in: epiphany-browser (Ubuntu Xenial) Importance: Undecided => High -- You received this bug notification because you are a