[Bug 1668744] Re: shell metacharacters mishandled
I added trusty, xenial, and zesty tasks for this bug without verifying which releases need work. Thanks ** Also affects: firejail (Ubuntu Zesty) Importance: Undecided Status: New ** Also affects: firejail (Ubuntu Xenial) Importance: Undecided Status: New ** Also affects: firejail (Ubuntu Trusty) Importance: Undecided Status: New ** Changed in: firejail (Ubuntu) Status: Incomplete => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1668744 Title: shell metacharacters mishandled To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/firejail/+bug/1668744/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1668744] Re: shell metacharacters mishandled
It's good that there is a fix in 17.10, but this remote vulnerability remains unfixed in other versions, including LTS releases. I reported this as a xenial bug (like you can see from tags) and there it remains unfixed. I'm not well versed in launchpad usage, how should this be marked in the bug status info? ** Tags added: security ** Changed in: firejail (Ubuntu) Status: Fix Released => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1668744 Title: shell metacharacters mishandled To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/firejail/+bug/1668744/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1668744] Re: shell metacharacters mishandled
Tested with latest upstream version (0.9.50) and can't reproduce the bug. This is included in Ubuntu 17.10. ** Changed in: firejail (Ubuntu) Status: Incomplete => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1668744 Title: shell metacharacters mishandled To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/firejail/+bug/1668744/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1668744] Re: shell metacharacters mishandled
Is the "Fix Released" status correct for this bug? In https://wiki.ubuntu.com/Bugs/Bug%20statuses it says this indicates the bug is fixed in Ubuntu, but this does not seem to be the case? ** Changed in: firejail (Ubuntu) Status: Fix Released => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1668744 Title: shell metacharacters mishandled To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/firejail/+bug/1668744/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1668744] Re: shell metacharacters mishandled
** Changed in: firejail (Ubuntu) Status: Incomplete => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1668744 Title: shell metacharacters mishandled To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/firejail/+bug/1668744/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1668744] Re: shell metacharacters mishandled
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures ** Information type changed from Private Security to Public Security ** Changed in: firejail (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1668744 Title: shell metacharacters mishandled To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/firejail/+bug/1668744/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs