[Bug 1976339] Re: Openssl update to 1.0.2g-1ubuntu4.20+esm3 Breaks Php Openssl_get_cipher_methods Function

2022-05-31 Thread Paulo Flabiano Smorigo
Hello Dimitar, I've just publish a new release with the fix (1.0.2g-1ubuntu4.20+esm4) for the issue you had. Can you check if this version is fine? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1971504] Re: Multiple vulnerabilities in Bionic, Focal, Impish, Jammy and Kinetic

2022-05-24 Thread Paulo Flabiano Smorigo
Hello Luis, did you manage to test the bionic package? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1971504 Title: Multiple vulnerabilities in Bionic, Focal, Impish, Jammy and Kinetic To manage

[Bug 1973054] Re: containerd regression for CVE-2022-23648 in latest version 1.5.9-0ubuntu1~20.04.1

2022-05-12 Thread Paulo Flabiano Smorigo
** Changed in: containerd (Ubuntu) Assignee: (unassigned) => Paulo Flabiano Smorigo (pfsmorigo) ** Changed in: containerd (Ubuntu Focal) Assignee: (unassigned) => Paulo Flabiano Smorigo (pfsmorigo) ** Changed in: containerd (Ubuntu Impish) Assignee: (unassigned) => Paulo

[Bug 1971504] Re: Multiple vulnerabilities in Bionic, Focal, Impish, Jammy and Kinetic

2022-05-06 Thread Paulo Flabiano Smorigo
Hello Luís, thanks for the debdiffs. I've changed the changelog a little bit in order to follow the security format and fit the patches into the DEP-3 guidelines (some of them were missing some header elements). I uploaded the packages into our security-proposed ppa and, if possible, please test

[Bug 1915911] Re: Tomcat9 package is old version with many security issues

2022-03-31 Thread Paulo Flabiano Smorigo
Hello Evren, hmm I just published both bionic (9.0.16-3ubuntu0.18.04.2) and focal (9.0.31-1ubuntu0.2). I finished some tests yesterday. Foi bionic I had to do some changes and add an extra commit to support one of fixes. ** Changed in: tomcat9 (Ubuntu) Status: Confirmed => Fix Released --

[Bug 1915911] Re: Tomcat9 package is old version with many security issues

2022-03-25 Thread Paulo Flabiano Smorigo
Hello Evren, thanks for the debdiff. I'm using it to build the new release for Focal. I did some checks today and will continue on Monday. If all goes well I think we can have a new package in the archive next week. Meanwhile, I'm working on the bionic version. -- You received this bug

[Bug 1915911] Re: Tomcat9 package is old version with many security issues

2022-03-25 Thread Paulo Flabiano Smorigo
** Changed in: tomcat9 (Ubuntu) Assignee: (unassigned) => Paulo Flabiano Smorigo (pfsmorigo) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1915911 Title: Tomcat9 package is old vers

[Bug 1961418] Re: snap failed to run with '/usr/bin/snap wait system seed.loaded'

2022-02-22 Thread Paulo Flabiano Smorigo
What snapd version are you using? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1961418 Title: snap failed to run with '/usr/bin/snap wait system seed.loaded' To manage notifications about this

[Bug 1957106] Re: wif disconnected

2022-02-04 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1958786] Re: CRASH - [drm:amd gpu_cs_ioctl [amdgpu]] *ERROR* Failed to initialize parser -125!

2022-02-04 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1958647] Re: no idia

2022-02-04 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1959479] Re: frezzing up

2022-02-04 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1959494] Re: touchpad stopped working hp envy dv6 laptop

2022-02-04 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1960001] Re: indija

2022-02-04 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1950193] Re: libqt5svg5 affected by CVE-2021-38593

2022-01-06 Thread Paulo Flabiano Smorigo
Thanks! I didn't add the LP number because it was in the previous changelog entry. It seems that it needs to be in the latest one in order to identify it correctly. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report.

[Bug 1950193] Re: libqt5svg5 affected by CVE-2021-38593

2022-01-06 Thread Paulo Flabiano Smorigo
I've just published focal and impish updates into the -security pocket. focal: 5.12.8+dfsg-0ubuntu2.1 impish: 5.15.2+dfsg-12ubuntu1.1 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1950193

[Bug 1950193] Re: libqt5svg5 affected by CVE-2021-38593

2022-01-05 Thread Paulo Flabiano Smorigo
Hello, I'm doing build for the -security pocket as Marc suggested. Will be published soon. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1950193 Title: libqt5svg5 affected by CVE-2021-38593

[Bug 1939188] Re: CVE-2021-2389 & CVE-2021-2372 affect MariaDB in Ubuntu

2021-08-13 Thread Paulo Flabiano Smorigo
Both 10.3 (focal) and 10.5 (hirsute) updates were released yesterday https://ubuntu.com/security/notices/USN-5022-2 ** Changed in: mariadb-10.5 (Ubuntu) Importance: Undecided => Medium ** Changed in: mariadb-10.5 (Ubuntu) Status: New => Fix Released -- You received this bug

[Bug 1939188] Re: CVE-2021-2389 & CVE-2021-2372 affect MariaDB in Ubuntu

2021-08-10 Thread Paulo Flabiano Smorigo
** Changed in: mariadb-10.5 (Ubuntu) Assignee: (unassigned) => Paulo Flabiano Smorigo (pfsmorigo) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1939188 Title: CVE-2021-2389 & CVE-20

[Bug 1934941] Re: Xorg freeze

2021-07-30 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1938053] Re: HDMI Problem

2021-07-30 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1938249] Re: Xorg freeze

2021-07-30 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1931303] Re: Thinkpad T14 AMD Gen1 fresh installation bug

2021-06-11 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1925985] Re: CVE-2021-22204

2021-06-10 Thread Paulo Flabiano Smorigo
Hello Hugo, Thanks for the help! I've published your backport for bionic, focal, groovy, and hirsute. The changelog was a little different to be in the format that we use. About the version number, we use major numbers (like ubuntu1) when is a devel release otherwise we increment the minor number

[Bug 1925985] Re: CVE-2021-22204

2021-06-10 Thread Paulo Flabiano Smorigo
abiano Smorigo (pfsmorigo) ** Changed in: libimage-exiftool-perl (Ubuntu Hirsute) Assignee: (unassigned) => Paulo Flabiano Smorigo (pfsmorigo) ** Changed in: libimage-exiftool-perl (Ubuntu Focal) Assignee: (unassigned) => Paulo Flabiano Smorigo (pfsmorigo) ** Changed in: libimage-e

[Bug 1911473] Re: Update for ghsa-4ppf-fxf6-vxg2

2021-01-28 Thread Paulo Flabiano Smorigo
@Andrew, hello. Focal and Groovy with your backports are fine and ready to go. I still resistant about Bionic since I couldn't import the tests. I'll try to manually test it a little more tomorrow and if everything goes well I'll publish it on Monday. -- You received this bug notification

[Bug 1911473] Re: Update for ghsa-4ppf-fxf6-vxg2

2021-01-22 Thread Paulo Flabiano Smorigo
Thanks. I managed to backport version 1.2 to bionic (1.0.9). I had to exclude the tests because the framework is very different between both versions. I'll test in on Monday. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1911473] Re: Update for ghsa-4ppf-fxf6-vxg2

2021-01-21 Thread Paulo Flabiano Smorigo
Just a heads up. Your focal backport seems fine, no problems there. I'm working on the bionic version but, since it's based on 1.0.9, it's not straightforward. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1911473] Re: Placeholder for ghsa-4ppf-fxf6-vxg2

2021-01-14 Thread Paulo Flabiano Smorigo
Ok thanks. I've tried to backport all commits with "Part-of: GHSA-4ppf- fxf6-vxg2" for hirsute but it fails to build. More commits are required in order to work. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1911473] Re: Placeholder for ghsa-4ppf-fxf6-vxg2

2021-01-14 Thread Paulo Flabiano Smorigo
Hello Andrew, it seems that there is no CVE assigned to it, right? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1911473 Title: Placeholder for ghsa-4ppf-fxf6-vxg2 To manage notifications about

[Bug 1906968] Re: install crashed

2021-01-06 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1907744] Re: package unattended-upgrades 2.3ubuntu0.1 failed to install/upgrade: installed unattended-upgrades package post-installation script subprocess was killed by signal (Aborted)

2021-01-06 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1909338] Re: package virtualbox-guest-dkms 5.2.42-dfsg-0~ubuntu1.18.04.1 failed to install/upgrade: installed virtualbox-guest-dkms package post-installation script subprocess returned error exit

2021-01-06 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1909364] Re: Please Help My Package Is Correct and crashed

2021-01-06 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1909512] Re: its suddenly stop instaling ubuntu

2021-01-06 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1909621] Re: my gnome control center is not opeaning and working

2021-01-06 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1909765] Re: package grub-efi-amd64-signed 1.155.1+2.04-1ubuntu35.1 failed to install/upgrade: o subprocesso instalado, do pacote grub-efi-amd64-signed, o script post-installation retornou erro d

2021-01-06 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1909845] Re: TouchPad Not Working

2021-01-06 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1909896] Re: package virtualbox-ext-pack 6.1.14-2 failed to install/upgrade: installed virtualbox-ext-pack package post-installation script subprocess returned error exit status 1

2021-01-06 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1909901] Re: PCI/internal sound card not detected

2021-01-06 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1910295] Re: package nvidia-dkms-390 (not installed) failed to install/upgrade: el subproceso instalado paquete nvidia-dkms-390 script post-installation devolvió el código de salida de error 10

2021-01-06 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1910449] Re: package nvidia-dkms-390 390.138-0ubuntu0.20.04.1 failed to install/upgrade: nvidia-dkms-390 paketi post-installation betiği kuruldu alt süreci 10 hatalı çıkış kodu ile sona erdi

2021-01-06 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1907322] Re: Fatal error-file could'nt be installed

2020-12-14 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1870876] Re: docker stopped when containerd updated

2020-12-01 Thread Paulo Flabiano Smorigo
*** This bug is a duplicate of bug 1870514 *** https://bugs.launchpad.net/bugs/1870514 For the record, running "apt install --reinstall containerd" is enough to reproduce it. It seems fine after restarting it. Investigating... root@sec-bionic-amd64:~# systemctl status docker ● docker.service

[Bug 1883702] Re: [Satellite P55W-C, Realtek ALC233, Mic, Internal] Recording problem

2020-06-18 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1883454] Re: Java swing on repl.it doesn't load the GUI but the code works flawlessly

2020-06-18 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1866065] [NEW] weechat can't load python plugins (undefined symbol: _Py_NoneStruct)

2020-03-04 Thread Paulo Flabiano Smorigo
Public bug reported: I updated to focal this week and weechat fails to load python plugins. It shows the following message: Error: unable to load plugin "/usr/lib/x86_64-linux-gnu/weechat/plugins/python.so": /usr/lib/x86_64-linux-gnu/weechat/plugins/python.so: undefined symbol: _Py_NoneStruct

[Bug 1843403] Re: [MIR] nfs-ganesha, ntirpc

2020-02-14 Thread Paulo Flabiano Smorigo
I reviewed nfs-ganesha 3.0.3-0ubuntu1 as checked into focal. This shouldn't be considered a full audit but rather a quick gauge of maintainability. nfs-ganesha is an user-mode file server for NFS v3, 4.0, 4.1, 4.1 pNFS, and 4.2; and for 9P from the Plan9 operating system. It provides a

[Bug 1861923] Re: install error

2020-02-13 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1862459] Re: ubuntu 18 screen flicker/blink

2020-02-13 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1862476] Re: Bug install grub in /dev/sda

2020-02-13 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1862553] Re: gnome-control-center crashed with SIGSEGV in cc_panel_get_title_widget()

2020-02-13 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1862658] Re: el applet meteorológico falla al cerrar sesión

2020-02-13 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1862521] Re: nvidia-kernel-source-390 390.116-0ubuntu0.18.04.3: nvidia kernel module failed to build

2020-02-13 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1862530] Re: package mariadb-common 1:10.3.22-0ubuntu0.19.10.1 failed to install/upgrade: o subprocesso instalado, do pacote mariadb-common, o script post-installation retornou erro do status de

2020-02-13 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1862586] Re: Grub is not getting installed

2020-02-13 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1863049] Re: plz rectify this bugs

2020-02-13 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1863050] Re: package nvidia-340 (not installed) failed to install/upgrade: a tentar sobre-escrever '/lib/udev/rules.d/71-nvidia.rules', que também está no pacote nvidia-kernel-common-390 390.132-

2020-02-13 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1790856] Re: [MIR] pmdk

2020-01-20 Thread Paulo Flabiano Smorigo
I reviewed pmdk 1.7-1ubuntu1 as checked into focal. This shouldn't be considered a full audit but rather a quick gauge of maintainability. pmdk comes from Persistent Memory Development Kit and it's a collection of libraries and tool which allows applications to access persistent memory as

[Bug 1854373] Re: CVE affecting phpMyAdmin 4.x

2019-11-29 Thread Paulo Flabiano Smorigo
Hello it0001, I did the triage and updated the link you referred to in comment #7. This page is updated daily so you're only going to see the new status, not-affected, tomorrow. As I said, only focal was affected but it's already fixed. Trusty, xenial, bionic, and disco are not affected, the code

[Bug 1854373] Re: CVE affecting phpMyAdmin 4.x

2019-11-29 Thread Paulo Flabiano Smorigo
Hello it0001, PMASA-2019-5 points to commit 4ba7d2fac6f384. Both afected files (move.js and database_tables.twig) are only present in focal and the last release (4:4.9.2+dfsg1-1) fixed the issue. Can you clarify why the releases are affected? -- You received this bug notification because you

[Bug 1853063] Re: SQL injection and Persistent XSS in textile formatting

2019-11-25 Thread Paulo Flabiano Smorigo
Hi Lucas, I published the new version with the fix. Thanks. I made two modifications in the changelog. The first was the version. Security update uses minor version naming, so 0.1, not 1. In this update I ended up using 0.2 because I made a mistake and had to upload the source again so I burned

[Bug 1853063] Re: SQL injection and Persistent XSS in textile formatting

2019-11-21 Thread Paulo Flabiano Smorigo
I just marked precise and trusty as invalid since they are out of standard support. Xenial version will be uploaded soon. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1853063 Title: SQL injection

[Bug 1853063] Re: SQL injection and Persistent XSS in textile formatting

2019-11-21 Thread Paulo Flabiano Smorigo
** Changed in: redmine (Ubuntu Precise) Status: New => Invalid ** Changed in: redmine (Ubuntu Trusty) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1853063

[Bug 1853063] Re: SQL injection and Persistent XSS in textile formatting

2019-11-20 Thread Paulo Flabiano Smorigo
** Changed in: redmine (Ubuntu) Assignee: (unassigned) => Paulo Flabiano Smorigo (pfsmorigo) ** Changed in: redmine (Ubuntu Trusty) Assignee: (unassigned) => Paulo Flabiano Smorigo (pfsmorigo) ** Changed in: redmine (Ubuntu Xenial) Assignee: (unassigned) => Paulo Flabian

[Bug 1852566] Re: [OptiPlex 3050, Intel ID 280b, Digital Out, HDMI] No sound at all

2019-11-14 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1852525] Re: package oca-core 11.0.20180730-1 failed to install/upgrade: installed oca-core package post-installation script subprocess returned error exit status 1

2019-11-14 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1852574] Re: oggvideotools heap overflow

2019-11-14 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1852109] Re: CVE-2019-2974: MariaDB & MySQL

2019-11-12 Thread Paulo Flabiano Smorigo
** Changed in: mariadb-10.1 (Ubuntu) Assignee: Otto Kekäläinen (otto) => Paulo Flabiano Smorigo  (pfsmorigo) ** Changed in: mariadb-10.3 (Ubuntu) Assignee: Otto Kekäläinen (otto) => Paulo Flabiano Smorigo  (pfsmorigo) -- You received this bug notification because you are a

[Bug 1851887] Re: Sound only works works again if the volume is raised more than 50%

2019-11-12 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1852173] Re: GUI applications with root access don't open

2019-11-12 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1852129] Re: package sendmail 8.15.2-13 failed to install/upgrade: problemas de dependencias - se deja sin configurar

2019-11-11 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1844587] Re: weather applet crashes on logout

2019-09-19 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1844486] Re: package ssmtp 2.64-8ubuntu1 failed to install/upgrade: le sous-processus script post-installation installé a retourné une erreur de sortie d'état 1

2019-09-18 Thread Paulo Flabiano Smorigo
*** This bug is a duplicate of bug 1844487 *** https://bugs.launchpad.net/bugs/1844487 Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as

[Bug 1844487] Re: package ssmtp 2.64-8ubuntu1 failed to install/upgrade: le sous-processus script post-installation installé a retourné une erreur de sortie d'état 1

2019-09-18 Thread Paulo Flabiano Smorigo
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1844485] Re: package ssmtp 2.64-8ubuntu1 failed to install/upgrade: le sous-processus script post-installation installé a retourné une erreur de sortie d'état 1

2019-09-18 Thread Paulo Flabiano Smorigo
*** This bug is a duplicate of bug 1844487 *** https://bugs.launchpad.net/bugs/1844487 ** This bug has been marked a duplicate of bug 1844487 package ssmtp 2.64-8ubuntu1 failed to install/upgrade: le sous-processus script post-installation installé a retourné une erreur de sortie d'état 1

[Bug 1832163] Re: Me acaban de dar BANNN SIN NINGUNA RAZON POR QUE ESTABA JUGANDO SKYWAR Y DE REPENDE ME DIERON BAN Llevo 3 años sin jugar me meto a un servidor a recordad los viejos tiempo y me dan b

2019-06-10 Thread Paulo Flabiano Smorigo
** Changed in: apache2 (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1832163 Title: Me acaban de dar BANNN SIN NINGUNA RAZON POR QUE ESTABA JUGANDO SKYWAR

[Bug 1821811] Re: New upstream microrelease flatpak 1.0.8

2019-05-02 Thread Paulo Flabiano Smorigo
Hello Andrew, can you check/test if the packages bellow are working properly? https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa/+packages?field.name_filter=flatpak -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1821760] Re: CVE-2019-9917 - Invalid encoding crash

2019-04-05 Thread Paulo Flabiano Smorigo
** Changed in: znc (Ubuntu Disco) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1821760 Title: CVE-2019-9917 - Invalid encoding crash To manage notifications

[Bug 1814895] Re: display blinking and showing content of screen on sleep mode

2019-02-12 Thread Paulo Flabiano Smorigo
*** This bug is a duplicate of bug 1570053 *** https://bugs.launchpad.net/bugs/1570053 ** This bug has been marked a duplicate of bug 1570053 Screen content is fully visible after unlocking screen -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1814935] Re: Screen not locked when coming out of suspend/hibernate - Dock bar is visible

2019-02-12 Thread Paulo Flabiano Smorigo
*** This bug is a duplicate of bug 1769383 *** https://bugs.launchpad.net/bugs/1769383 ** This bug has been marked a duplicate of bug 1769383 Ubuntu dock/launcher is shown on the lock screen -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1815589] Re: launchbar allowing actions while os is locked

2019-02-12 Thread Paulo Flabiano Smorigo
*** This bug is a duplicate of bug 1769383 *** https://bugs.launchpad.net/bugs/1769383 ** This bug has been marked a duplicate of bug 1769383 Ubuntu dock/launcher is shown on the lock screen ** Information type changed from Private Security to Public Security -- You received this bug

[Bug 1815298] Re: Screen locking security issue when session is resumed

2019-02-11 Thread Paulo Flabiano Smorigo
*** This bug is a duplicate of bug 1570053 *** https://bugs.launchpad.net/bugs/1570053 ** This bug has been marked a duplicate of bug 1570053 Screen content is fully visible after unlocking screen ** Information type changed from Private Security to Public Security -- You received this

[Bug 1811122] Re: Cannot use xrdp to login to sesman-Xvnc after 0.6.1-2ubuntu0.1

2019-01-17 Thread Paulo Flabiano Smorigo
New version with the fix (0.6.1-2ubuntu0.3): https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa/+packages?field.name_filter=xrdp Please, use this new package and let me know if it's working fine. -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 1811122] Re: Cannot use xrdp to login to sesman-Xvnc after 0.6.1-2ubuntu0.1

2019-01-14 Thread Paulo Flabiano Smorigo
Yes, I hit the error when I was doing the trusty version. It works if you install the original version and then this version. It's trick. I'm working on it. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1811122] Re: Cannot use xrdp to login to sesman-Xvnc after 0.6.1-2ubuntu0.1

2019-01-14 Thread Paulo Flabiano Smorigo
in: xrdp (Ubuntu) Assignee: (unassigned) => Paulo Flabiano Smorigo (pfsmorigo) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1811122 Title: Cannot use xrdp to login to sesman-Xvnc after 0.