[Bug 2075145] Re: exfatprogs CVE-2023-45897 backport to jammy

2024-08-20 Thread Marc Deslauriers
Update has been published now, thanks for testing! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2075145 Title: exfatprogs CVE-2023-45897 backport to jammy To manage notifications about this bug go

[Bug 2075145] Re: exfatprogs CVE-2023-45897 backport to jammy

2024-08-20 Thread Launchpad Bug Tracker
This bug was fixed in the package exfatprogs - 1.1.3-1ubuntu0.1 --- exfatprogs (1.1.3-1ubuntu0.1) jammy-security; urgency=medium * Backport security fix for CVE-2023-45897 (LP: #2075145) -- Alessandro Astone Tue, 30 Jul 2024 11:58:06 +0200 ** Changed in: exfatprogs (Ubuntu

[Bug 2075145] Re: exfatprogs CVE-2023-45897 backport to jammy

2024-08-20 Thread Alessandro Astone
Verified mkfs.exfat, fsck.exfat, dump.exfat, tune.exfat and exfatlabel from exfatprogs=1.1.3-1ubuntu0.1 in Jammy amd64 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2075145 Title: exfatprogs CVE-202

[Bug 2075145] Re: exfatprogs CVE-2023-45897 backport to jammy

2024-08-19 Thread Marc Deslauriers
Thanks for the debdiff for this issue. I've validated that that is the only commit that affects jammy. I have uploaded this package for building in the security team PPA here: https://launchpad.net/~ubuntu-security- proposed/+archive/ubuntu/ppa/+packages Once the package has finished building, c

[Bug 2075145] Re: exfatprogs CVE-2023-45897 backport to jammy

2024-08-14 Thread Alessandro Astone
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-45897 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2075145 Title: exfatprogs CVE-2023-45897 backport to jammy To manage notificati

[Bug 2075145] Re: exfatprogs CVE-2023-45897 backport to jammy

2024-08-02 Thread Jeremy Bícha
** Changed in: exfatprogs (Ubuntu Jammy) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2075145 Title: exfatprogs CVE-2023-45897 backport to jammy To manage notificat

[Bug 2075145] Re: exfatprogs CVE-2023-45897 backport to jammy

2024-08-02 Thread Jeremy Bícha
** Information type changed from Public to Public Security ** Changed in: exfatprogs (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2075145 Title: exfatpr

[Bug 2075145] Re: exfatprogs CVE-2023-45897 backport to jammy

2024-07-30 Thread Alessandro Astone
Backport of the patch: https://github.com/exfatprogs/exfatprogs/commit/ec78688e5fb5a70e13df82b4c0da1e6228d3ccdf The CVE was released with 3 patches, but only that one seems to apply to version 1.1.3, while the other patches are for vulnerabilities introduced in later versions. ** Patch added: "ex