[Bug 1872993] Re: Security vulnerabilities of version 5.7.29

2020-04-28 Thread Eduardo Barretto
** Changed in: mysql-5.7 (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1872993 Title: Security vulnerabilities of version 5.7.29 To manage

[Bug 1875261] Re: package libnvidia-gl-430 (not installed) failed to install/upgrade: new libnvidia-gl-430:i386 package pre-installation script subprocess returned error exit status 2

2020-04-27 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1875205] Re: teste

2020-04-27 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1875000] Re: [HP Pavilion dv2500 Notebook PC, Conexant CX20549 (Venice), Speaker, Internal] fails after a while. The speaker in laptop turns on and off automatically during boot time when I use U

2020-04-27 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1875783] Re: package python3-gdbm:amd64 (not installed) failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting a removal

2020-04-29 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1875943] Re: there was no space it said

2020-04-29 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1874901] Re: package dms-core 1.0.8.1-1ubuntu2 failed to install/upgrade: installed dms-core package post-installation script subprocess returned error exit status 3

2020-04-29 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1872993] Re: Security vulnerabilities of version 5.7.29

2020-05-04 Thread Eduardo Barretto
The update was released today and you can find more information here: https://usn.ubuntu.com/4350-1/ Thanks for taking the time to report this bug and helping to make Ubuntu better. Please feel free to report any other bugs you may find. -- You received this bug notification because you are a

[Bug 1873623] Re: new release to handle jdk bugs

2020-04-22 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We just released the fix for those CVEs today as you can check it here: https://usn.ubuntu.com/4337-1/ Please feel free to report any other bugs you may find. ** Changed in: openjdk-lts (Ubuntu) Status: Fix

[Bug 1889248] security audit

2020-09-15 Thread Eduardo Barretto
I reviewed libonig 6.9.5-2 as checked into groovy. This shouldn't be considered a full audit but rather a quick gauge of maintainability. libonig (or Oniguruma) is a regular expression library. It supports different encodings. - CVE History: - libonig has been assigned 13 CVEs since 2017. All

[Bug 1893465] Re: KDE Project Security Advisory: Ark: maliciously crafted TAR archive with symlinks can install files outside the extraction directory.

2020-09-01 Thread Eduardo Barretto
** Also affects: ark (Ubuntu Xenial) Importance: Undecided Status: New ** Changed in: ark (Ubuntu Xenial) Assignee: (unassigned) => Eduardo Barretto (ebarretto) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. ht

[Bug 1893465] Re: KDE Project Security Advisory: Ark: maliciously crafted TAR archive with symlinks can install files outside the extraction directory.

2020-08-31 Thread Eduardo Barretto
** Changed in: ark (Ubuntu Bionic) Assignee: (unassigned) => Eduardo Barretto (ebarretto) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1893465 Title: KDE Project Security Advisory:

[Bug 1900236] Re: unable to install 16.10

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1900199] Re: E: The value 'bionic-security' is invalid for APT::Default-Release as such a release is not available in the sources E: _cache->open() failed, please report.

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1899529] Re: My system ubuntu18 has been destroyed after installing ubuntu20

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1900100] Re: An unresolvable problem occurred while calculating the upgrade. Si rien de tout cela ne s'applique, veuillez signaler ce bogue en utilisant la commande « ubuntu-bug ubuntu-release-

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1900134] Re: package ubuntu-minimal 1.450.2 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1900442] Re: package linux-image-5.4.0-51-generic 5.4.0-51.56 failed to install/upgrade: run-parts: /etc/kernel/postinst.d/initramfs-tools exited with return code 1

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1900345] Re: It crushed

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1900288] Re: package bluez 5.48-0ubuntu3.4 failed to install/upgrade: installed bluez package post-installation script subprocess returned error exit status 1

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1899781] Re: package xapian1.3-doc (not installed) failed to install/upgrade: trying to overwrite '/usr/share/doc-base/xapian-intro', which is also in package xapian-doc 1.2.22-2

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1900353] Re: mallorca

2020-10-19 Thread Eduardo Barretto
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 1900385] Re: Dummy Output

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1900177] Re: package linux-headers-generic 5.4.0.48.51 failed to install/upgrade: impossibile accedere aupgradell'archivio "/tmp/apt-dpkg-install-dJwLNk/7-linux-headers-generic_5.4.0.51.54_amd64.

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1900151] Re: avighnaaa@avighnaaa-inspiron-15-3567:~$ sudo apt-get dist-upgrade Reading package lists... Done Building dependency tree Reading state information... Done Calculating upgrade... Done

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1900039] Re: package mariadb-server-core-10.3 1:10.3.22-1ubuntu1 failed to install/upgrade: problemas de dependência - deixando desconfigurado

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1899949] Re: bug report

2020-10-19 Thread Eduardo Barretto
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 1899393] Re: package im-config 0.29-1ubuntu12.4 failed to install/upgrade: package im-config is not ready for configuration cannot configure (current status 'half-installed')

2020-10-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1900694] Re: package gdm3 3.36.3-0ubuntu0.20.04.1 failed to install/upgrade: end of file on stdin at conffile prompt

2020-10-20 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1900673] Re: package texlive-plain-generic 2019.202000218-1 failed to install/upgrade: el paquete está en un estado muy malo e inconsistente - debe reinstalarlo antes de intentar desinstalarlo.

2020-10-20 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Your bug report is more likely to get attention if it is made in English, since this is the language understood by the majority of Ubuntu developers. Additionally, please only mark a bug as "security" if it shows

[Bug 1899704] Re: ubuntu-bug ubuntu-release-upgrader-core comm: /var/log/dmesg:

2020-10-20 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1899711] Re: -upgrater-core 1.17.10.8 ( orgin unknow ) problem type Bug

2020-10-20 Thread Eduardo Barretto
*** This bug is a duplicate of bug 1899708 *** https://bugs.launchpad.net/bugs/1899708 Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as

[Bug 1892841] Re: package libsane 1.0.29-0ubuntu5 failed to install/upgrade: unable to stat './usr/share/doc/libsane' (which I was about to install): Input/output error

2020-08-25 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1892839] Re: help

2020-08-25 Thread Eduardo Barretto
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 1892985] Re: package libegl-mesa0 20.0.8-0ubuntu1~18.04.1 [modified: usr/share/glvnd/egl_vendor.d/50_mesa.json] failed to install/upgrade: trying to overwrite shared '/usr/share/glvnd/egl_vendor.

2020-08-26 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1893312] Re: It records black screen, and only mouse cursor.

2020-08-28 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1893465] Re: KDE Project Security Advisory: Ark: maliciously crafted TAR archive with symlinks can install files outside the extraction directory.

2020-08-28 Thread Eduardo Barretto
by the same issue? ** Changed in: ark (Ubuntu) Assignee: (unassigned) => Eduardo Barretto (ebarretto) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1893465 Title: KDE Project Security Advis

[Bug 1893005] Re: the function of "ask for this password every time" is diable

2020-08-26 Thread Eduardo Barretto
Did you set "all users may connect to this network" option in network manager? Or do you have any other option set? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1893005 Title: the function of "ask

[Bug 1893005] Re: the function of "ask for this password every time" is diable

2020-08-26 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1893116] Re: IntelliJ Idea doesn't work properly. It's based on Ubuntu20.04

2020-08-26 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1892589] Re: 99

2020-08-24 Thread Eduardo Barretto
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 1892715] Re: package python3 3.7.5-1 failed to install/upgrade: new python3 package pre-removal script subprocess returned error exit status 127

2020-08-24 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1892727] Re: package chromium-browser (not installed) failed to install/upgrade: 新的 chromium-browser 软件包 pre-installation 脚本 子进程返回错误状态 1

2020-08-24 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1901119] Re: nvidia-340

2020-10-23 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1901125] Re: package bcmwl-kernel-source 6.30.223.271+bdcom-0ubuntu7 failed to install/upgrade: installed bcmwl-kernel-source package post-installation script subprocess returned error exit statu

2020-10-23 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1869215] Re: [MIR] python-jwcrypto

2020-08-06 Thread Eduardo Barretto
I reviewed python-jwcrypto 0.6.0-2 as checked into groovy. This shouldn't be considered a full audit but rather a quick gauge of maintainability. python-jwcrypto is an implementation of the Javascript Object Signing and Encryption (JOSE) Web Standards as they are being developed in the JOSE IETF

[Bug 1861268] security audit

2020-07-01 Thread Eduardo Barretto
I reviewed jeepney 0.4.3-1 as checked into groovy. This shouldn't be considered a full audit but rather a quick gauge of maintainability. jeepney is a pure Python D-Bus interface. D-Bus is an inter-process communication system. In its README file, jeepney maintainer mentions: "This project is

[Bug 1886052] Re: crash

2020-07-02 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1885496] Re: Bluetooth is disabled in gui, but audio reciever's action button still controls Ubuntu

2020-07-02 Thread Eduardo Barretto
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1885496 Title: Bluetooth is disabled in gui, but audio reciever's action button

[Bug 1884913] Re: Upgrade to 20.04 removes ecryptfs and leaves home folder unencrypted

2020-06-30 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Could you please share more details/logs from the upgrade? Also try to run: apport-collect 1884913 Thanks! ** Also affects: ubuntu-release-upgrader (Ubuntu) Importance: Undecided Status: New **

[Bug 1881780] Re: Nautilus requires SMBv1 to work from "Other Locations" without manually typing in the address.

2020-06-30 Thread Eduardo Barretto
Hi @ahasenack, @seb128 I saw you've both have dealt with smb issues. Could you please take a look on this issue? Thanks! ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 1885738]

2020-06-30 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 1847520] Re: 33 Upstream CVEs patched

2020-06-30 Thread Eduardo Barretto
This issue was addressed in: https://usn.ubuntu.com/4252-1/ ** Changed in: tcpdump (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1847520

[Bug 1493303] Re: [OSSA 2016-004] Swift proxy memory leak on unfinished read (CVE-2016-0738)

2020-07-06 Thread Eduardo Barretto
This bug was fixed in the package swift - 1.13.1-0ubuntu1.5 --- swift (1.13.1-0ubuntu1.5) trusty-security; urgency=medium [ Jamie Strandboge ] * SECURITY UPDATE: disallow unsafe tempurl operations to point to unauthorized data - debian/patches/CVE-2015-5223.patch:

[Bug 1885393] Re: Dark theme

2020-06-29 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Your bug report is more likely to get attention if it is made in English, since this is the language understood by the majority of Ubuntu developers. Additionally, please only mark a bug as "security" if it shows

[Bug 1885353] Re: I can't upgrade to latest ubuntu version

2020-06-29 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1885606] Re: install

2020-06-29 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1885613] Re: Executing grub-install/dev/sdc failed

2020-06-29 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1885407] Re: can't install ubuntu and showing grub installing error

2020-06-29 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 725556] Re: Security problems (unacceptable behaviour) in sharing content via FSStore backend

2020-07-06 Thread Eduardo Barretto
Coherence is not part of the ESM supported packages list: https://wiki.ubuntu.com/SecurityTeam/ESM/14.04#A14.04_Infrastructure_ESM_Packages So marking it Won't Fix ** Changed in: coherence (Ubuntu) Status: Triaged => Won't Fix -- You received this bug notification because you are a

[Bug 1901013] Re: failed installation on installing

2020-10-22 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1899234] Re: installer is crashed

2020-10-22 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1899305] Re: gnome-calls crashed with signal 5 in g_main_context_dispatch()

2020-10-22 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1899765] Re: sshguard no longer adds rule to INPUT chain (regression on upgrade)

2020-10-22 Thread Eduardo Barretto
** Information type changed from Private Security to Public Security ** Changed in: sshguard (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1899765 Title:

[Bug 1899768] Re: earlier, disk unmount option may have choosen, rewrote grub loader by e

2020-10-22 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1900857] Re: I tried to update my 16.04 version to 18.04, but this problem occurred

2020-10-21 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1895839] Re: CVE-2020-24977

2020-10-21 Thread Eduardo Barretto
** Changed in: libxml2 (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1895839 Title: CVE-2020-24977 To manage notifications about this bug go to:

[Bug 1900983]

2020-10-22 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 1911791] Re: Openscap can report false positives

2021-01-20 Thread Eduardo Barretto
Hey Brian, I ran the following test on Xenial, Bionic, Focal and Groovy with archive openscap and openscap from -proposed and compared the results: $ wget https://people.canonical.com/~ubuntu-security/oval/com.ubuntu.$(lsb_release -cs).cve.oval.xml.bz2 $ bunzip2 com.ubuntu.$(lsb_release

[Bug 1911791] Re: Openscap can report false positives

2021-01-21 Thread Eduardo Barretto
** Tags removed: verification-needed verification-needed-bionic verification-needed-focal verification-needed-groovy verification-needed-xenial ** Tags added: verification-done verification-done-bionic verification-done-focal verification-done-groovy verification-done-xenial -- You received

[Bug 1911791] [NEW] Openscap can report false positives

2021-01-14 Thread Eduardo Barretto
Public bug reported: [Impact] Openscap didn't implement Debian package version comparison algorithm. This can cause a user/client to get false positive results when running oscap. For example, we have a system running Bionic, with package "foo" version 1.2.3-4ubuntu1~18.04.1 installed. Ubuntu

[Bug 1911791] Re: Openscap can report false positives

2021-01-14 Thread Eduardo Barretto
** Patch added: "xenial.debdiff" https://bugs.launchpad.net/ubuntu/+source/openscap/+bug/1911791/+attachment/5453046/+files/xenial.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1911791

[Bug 1911791] Re: Openscap can report false positives

2021-01-14 Thread Eduardo Barretto
** Patch added: "bionic.debdiff" https://bugs.launchpad.net/ubuntu/+source/openscap/+bug/1911791/+attachment/5453047/+files/bionic.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1911791

[Bug 1911791] Re: Openscap can report false positives

2021-01-14 Thread Eduardo Barretto
** Patch added: "focal.debdiff" https://bugs.launchpad.net/ubuntu/+source/openscap/+bug/1911791/+attachment/5453048/+files/focal.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1911791

[Bug 1911791] Re: Openscap can report false positives

2021-01-14 Thread Eduardo Barretto
** Patch added: "groovy.debdiff" https://bugs.launchpad.net/ubuntu/+source/openscap/+bug/1911791/+attachment/5453049/+files/groovy.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1911791

[Bug 1911791] Re: Openscap can report false positives

2021-01-14 Thread Eduardo Barretto
** Patch added: "hirsute.debdiff" https://bugs.launchpad.net/ubuntu/+source/openscap/+bug/1911791/+attachment/5453050/+files/hirsute.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1911791

[Bug 1911791] Re: Openscap can report false positives

2021-01-15 Thread Eduardo Barretto
** Patch added: "bionic.debdiff" https://bugs.launchpad.net/ubuntu/+source/openscap/+bug/1911791/+attachment/5453537/+files/bionic.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1911791

[Bug 1911791] Re: Openscap can report false positives

2021-01-15 Thread Eduardo Barretto
** Patch added: "focal.debdiff" https://bugs.launchpad.net/ubuntu/+source/openscap/+bug/1911791/+attachment/5453538/+files/focal.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1911791

[Bug 1911791] Re: Openscap can report false positives

2021-01-15 Thread Eduardo Barretto
The following debdiffs added the requests from Marc. ** Description changed: [Impact] Openscap didn't implement Debian package version comparison algorithm. This can cause a user/client to get false positive results when running oscap. For example, we have a system running

[Bug 1911791] Re: Openscap can report false positives

2021-01-15 Thread Eduardo Barretto
** Patch added: "groovy.debdiff" https://bugs.launchpad.net/ubuntu/+source/openscap/+bug/1911791/+attachment/5453539/+files/groovy.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1911791

[Bug 1911791] Re: Openscap can report false positives

2021-01-15 Thread Eduardo Barretto
** Patch added: "hirsute.debdiff" https://bugs.launchpad.net/ubuntu/+source/openscap/+bug/1911791/+attachment/5453540/+files/hirsute.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1911791

[Bug 1915698] Re: Apache Subversion "mod_authz_svn" Denial of Service Vulnerability

2021-04-23 Thread Eduardo Barretto
If you're trying to bring latest release of subversion to Ubuntu, then you need to check the SRU page mentioned by Seth. The SRU has its own whole process and there will be a need for a good reason to have the SRU approved, it is not that simple. Ubuntu is based on delivering a stable system to

[Bug 1925409] Re: the screen just blink. somewhat look crash

2021-04-22 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1891953] Re: CVE-2019-8936

2021-04-28 Thread Eduardo Barretto
** Changed in: ntp (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1891953 Title: CVE-2019-8936 To manage notifications about this bug go to:

[Bug 1924936] Re: package udev 247.3-3ubuntu3 failed to install/upgrade: o subprocesso instalado, do pacote udev, o script post-installation retornou erro do status de saída 1

2021-04-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1924887] Re: system program problem detected

2021-04-19 Thread Eduardo Barretto
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 1924935] Re: installation err

2021-04-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1924184] Re: drive not showing

2021-04-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1924834] Re: esca656585

2021-04-19 Thread Eduardo Barretto
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 1923675] Re: package chromium-browser 1:85.0.4183.83-0ubuntu2 failed to install/upgrade: el subproceso nuevo paquete chromium-browser script pre-installation devolvió el código de salida de error

2021-04-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Your bug report is more likely to get attention if it is made in English, since this is the language understood by the majority of Ubuntu developers. Additionally, please only mark a bug as "security" if it shows

[Bug 1923732] Re: ksystemstats crashed with SIGSEGV in AggregateSensor::value()

2021-04-19 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Your bug report is more likely to get attention if it is made in English, since this is the language understood by the majority of Ubuntu developers. Additionally, please only mark a bug as "security" if it shows

[Bug 1923639] Re: Remarkable2 file transfer crash

2021-04-20 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1925188] Re: Mozilla Firefox Multiple Vulnerabilities

2021-04-20 Thread Eduardo Barretto
** Information type changed from Private Security to Public Security ** Changed in: firefox (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1925188 Title:

[Bug 1922654] Re: Apache Maven Multiple Security Bypass Vulnerabilities

2021-04-20 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the packages referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 1915698] Re: Apache Subversion "mod_authz_svn" Denial of Service Vulnerability

2021-04-20 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 1923544] Re: GNU Crashed

2021-04-20 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1925007] Re: Microsoft Domain Bootloader Failed Grub install

2021-04-20 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1925101] Re: GIMP segfault

2021-04-20 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1925269] Re: Freezing of applications etc

2021-04-21 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1925705] Re: 100% cpu

2021-04-23 Thread Eduardo Barretto
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

  1   2   >