[Ubuntustudio-bugs] [Bug 1393479] Re: security: Insufficient Input Validation By IO Slaves and Webkit Part

2014-11-17 Thread Launchpad Bug Tracker
This bug was fixed in the package webkitkde - 1.3.4-1ubuntu1 --- webkitkde (1.3.4-1ubuntu1) vivid; urgency=medium * SECURITY UPDATE: Insufficient Input Validation By IO Slaves and Webkit Part - Add upstream_cve-2014-8600.diff to escape protocol twice: once for i18n, and

[Ubuntustudio-bugs] [Bug 1393479] Re: security: Insufficient Input Validation By IO Slaves and Webkit Part

2014-11-17 Thread Launchpad Bug Tracker
** Branch linked: lp:ubuntu/vivid-proposed/webkitkde -- You received this bug notification because you are a member of Ubuntu Studio Bugs, which is subscribed to kde-runtime in Ubuntu. Matching subscriptions: Ubuntu Studio Bugs https://bugs.launchpad.net/bugs/1393479 Title: security: Insuffici

[Ubuntustudio-bugs] [Bug 1393479] Re: security: Insufficient Input Validation By IO Slaves and Webkit Part

2014-11-17 Thread Rohan Garg
** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Studio Bugs, which is subscribed to kde-runtime in Ubuntu. Matching subscriptions: Ubuntu Studio Bugs https://bugs.launchpad.net/bugs/1393479 Title: security: Ins

[Ubuntustudio-bugs] [Bug 1393479] [NEW] security: Insufficient Input Validation By IO Slaves and Webkit Part

2014-11-17 Thread Jonathan Riddell
Public bug reported: https://www.kde.org/info/security/advisory-20141113-1.txt verview kwebkitpart and the bookmarks:// io slave were not sanitizing input correctly allowing to some javascript being executed on the context of the referenced hostname. For example going to bookmarks

[Ubuntustudio-bugs] [Bug 1393463] [NEW] image description / title should be visible via shotwell viewer

2014-11-17 Thread Neal McBurnett
Public bug reported: When I run from the command line shotwell /tmp/river-300x224_a.jpg or when an image is viewed in shotwell via the nautilus file manager, there is no way to see the description of the image (EXIF "Description" tag). I can only get a tiny bit of other metadata, e.g. vi

[Ubuntustudio-bugs] [Bug 1393349] Re: scribus should drop ttf-vera-bitstream dependency

2014-11-17 Thread Pander
Ah, then it should be in the suggested packages. -- You received this bug notification because you are a member of Ubuntu Studio Bugs, which is subscribed to scribus in Ubuntu. Matching subscriptions: scribus https://bugs.launchpad.net/bugs/1393349 Title: scribus should drop ttf-vera-bitstream

Re: [Ubuntustudio-bugs] [Bug 1393349] Re: scribus should drop ttf-vera-bitstream dependency

2014-11-17 Thread Mattia Rizzolo
Indeed it's in the recommends field: https://tracker.debian.org/media/packages/s/scribus/control-1.4.4%2Bdfsg1-2 (otherwise apt would have removed scribus when you tried to remove ttf-bitstream-vera), but recommended packages are installed by default. On Mon, Nov 17, 2014, 4:05 PM Pander <1393...@

[Ubuntustudio-bugs] [Bug 1393349] Re: scribus should drop ttf-vera-bitstream dependency

2014-11-17 Thread Pander
Best is to drop it or keep it only as a recommendation. Scribus should be able to cope with uninstalled fonts. If you maintain also other packages that have font dependencies I am willing to review them if they are really needed. -- You received this bug notification because you are a member of

[Ubuntustudio-bugs] [Bug 1393349] Re: scribus should drop ttf-vera-bitstream dependency

2014-11-17 Thread Mattia Rizzolo
Hi Pander. I added ttf-bitstream-vera to the Reccomend here: http://anonscm.debian.org/cgit/collab-maint/scribus.git/commit/?id=a0354de6ef448f01d569aa630db548d0f6672d60 I had to add it because there is (was? just some month ago I found it, and another person confirmed me that was needed, but look

[Ubuntustudio-bugs] [Bug 1393349] Re: scribus should drop ttf-vera-bitstream dependency

2014-11-17 Thread Pander
** Package changed: ubuntu => scribus (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Studio Bugs, which is subscribed to scribus in Ubuntu. Matching subscriptions: scribus https://bugs.launchpad.net/bugs/1393349 Title: scribus should drop ttf-vera-bitstream d

[Ubuntustudio-bugs] [Bug 1393349] [NEW] scribus should drop ttf-vera-bitstream dependency

2014-11-17 Thread Launchpad Bug Tracker
You have been subscribed to a public bug: scribus should drop ttf-vera-bitstream dependency, it is unneeded $ sudo apt-get install scribus Reading package lists... Done Building dependency tree Reading state information... Done The following extra packages will be installed: icc-profiles