[Bug 1918482] Re: Update for CVE-2021-21381

2021-05-11 Thread Launchpad Bug Tracker
This bug was fixed in the package flatpak - 1.0.9-0ubuntu0.3 --- flatpak (1.0.9-0ubuntu0.3) bionic-security; urgency=medium * SECURITY UPDATE: Flatpak sandbox escape via crafted .desktop file (LP: #1918482) - debian/patches/CVE-2021-21381-1.patch: Disallow @@ and @@u usage

[Bug 1918482] Re: Update for CVE-2021-21381

2021-05-11 Thread Launchpad Bug Tracker
This bug was fixed in the package flatpak - 1.6.5-0ubuntu0.3 --- flatpak (1.6.5-0ubuntu0.3) focal-security; urgency=medium * SECURITY UPDATE: Flatpak sandbox escape via crafted .desktop file (LP: #1918482) - debian/patches/CVE-2021-21381-1.patch: Disallow @@ and @@u usage in

[Bug 1918482] Re: Update for CVE-2021-21381

2021-05-11 Thread Launchpad Bug Tracker
This bug was fixed in the package flatpak - 1.8.2-1ubuntu0.2 --- flatpak (1.8.2-1ubuntu0.2) groovy-security; urgency=medium * SECURITY UPDATE: Flatpak sandbox escape via crafted .desktop file (LP: #1918482) - debian/patches/CVE-2021-21381-1.patch: Disallow @@ and @@u usage

[Bug 1918482] Re: Update for CVE-2021-21381

2021-05-06 Thread Andrew Hayzen
I've also done some exploratory testing of .desktop icon related tests from the test plan on a Bionic VM and things are working normally. $ apt policy flatpak flatpak: Installed: 1.0.9-0ubuntu0.3 Candidate: 1.0.9-0ubuntu0.3 Version table: *** 1.0.9-0ubuntu0.3 500 500

[Bug 1918482] Re: Update for CVE-2021-21381

2021-04-26 Thread Andrew Hayzen
@Steve Beattie, was there any progress on this or anything I can do to help ? Or is it just stuck in a queue of items to be reviewed? :-) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1918482 Title:

[Bug 1918482] Re: Update for CVE-2021-21381

2021-04-08 Thread Andrew Hayzen
Thanks for reviewing these updates! I've done some exploratory testing of .desktop icon related tests from the test plan on a Focal VM and things are working normally. $ apt policy flatpak flatpak: Installed: 1.6.5-0ubuntu0.3 Candidate: 1.6.5-0ubuntu0.3 Version table: *** 1.6.5-0ubuntu0.3

[Bug 1918482] Re: Update for CVE-2021-21381

2021-04-07 Thread Steve Beattie
** Summary changed: - Update for GHSA-xgh4-387p-hqpp + Update for CVE-2021-21381 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1918482 Title: Update for CVE-2021-21381 To manage notifications