[Bug 1629145] Re: Fix CVE-2016-7787

2016-09-29 Thread Simon Quigley
Thanks for your help, Seth! :) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1629145 Title: Fix CVE-2016-7787 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source

[Bug 1629145] Re: Fix CVE-2016-7787

2016-09-29 Thread Seth Arnold
Thanks Simon! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1629145 Title: Fix CVE-2016-7787 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/kde-cli-tools/+b

[Bug 1629145] Re: Fix CVE-2016-7787

2016-09-29 Thread Launchpad Bug Tracker
This bug was fixed in the package kde-cli-tools - 4:5.5.5-0ubuntu1.1 --- kde-cli-tools (4:5.5.5-0ubuntu1.1) xenial-security; urgency=high * SECURITY UPDATE: kdesu may show a different string than it would execute with elevated privileges. (LP: #1629145) - debian/patches/01-p

[Bug 1629145] Re: Fix CVE-2016-7787

2016-09-29 Thread Simon Quigley
Seth, yes, it works exactly as intended. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1629145 Title: Fix CVE-2016-7787 To manage notifications about this bug go to: https://bugs.launchpad.net/ubun

[Bug 1629145] Re: Fix CVE-2016-7787

2016-09-29 Thread Seth Arnold
Simon, does kdesu still work as expected? Thanks -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1629145 Title: Fix CVE-2016-7787 To manage notifications about this bug go to: https://bugs.launchpad

[Bug 1629145] Re: Fix CVE-2016-7787

2016-09-29 Thread Simon Quigley
Hey Seth, I can confirm that this package does build correctly. I built it locally. As for testing, the instructions for reproducing this CVE are not entirely clear (I don't know what "specially crafted" command they are referring to, it could be a lot of things). Again, I'm new to this process a

[Bug 1629145] Re: Fix CVE-2016-7787

2016-09-29 Thread Seth Arnold
Thanks Simon, the patch looks good; I changed the debian/changelog to match our usual style: * SECURITY UPDATE: kdesu may show a different string than it would execute with elevated privileges. (LP: #1629145) - debian/patches/01-patch-kde-CVE-2016-7787.diff - CVE-2016-7787 https:/

[Bug 1629145] Re: Fix CVE-2016-7787

2016-09-29 Thread Simon Quigley
** Changed in: kde-cli-tools (Ubuntu) Assignee: (unassigned) => Simon Quigley (tsimonq2) ** Changed in: kde-cli-tools (Ubuntu) Status: New => In Progress ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2016-7787 -- You received this bug notification because you are

[Bug 1629145] Re: Fix CVE-2016-7787

2016-09-29 Thread Seth Arnold
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1629145 Title: Fix CVE-2016-7787 To manage notifications about this bug go to: htt