[Bug 238977] [NEW] [CVE-2008-1806, -1807, -1808] Multiple vulnerabilities in FreeType2

2008-06-10 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: FreeType version 2.3.6 fixes multiple local privilege escalation vulnerabilities. For more information, see: CVE-2008-1806: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=715 CVE-2008-1807: http:/

[Bug 324353] Re: gksu crashed with SIGSEGV in gdk_draw_pixbuf()

2009-02-02 Thread Alexander Konovalenko
** Attachment added: "CoreDump.gz" http://launchpadlibrarian.net/21902802/CoreDump.gz ** Attachment added: "Dependencies.txt" http://launchpadlibrarian.net/21902803/Dependencies.txt ** Attachment added: "Disassembly.txt" http://launchpadlibrarian.net/21902804/Disassembly.txt ** Attachm

[Bug 324258] [NEW] [CVE-2008-5907] libpng: png_check_keyword() in pngwutil.c might allow overwriting arbitrary memory location

2009-02-02 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: libpng12-0 Description from the NVD: "The png_check_keyword function in pngwutil.c in libpng before 1.0.42, and 1.2.x before 1.2.34, might allow context-dependent attackers to set the value of an arb

[Bug 324249] [NEW] [CVE-2009-0265] BIND 9 not properly checking the return value from OpenSSL EVP_VerifyFinal()

2009-02-02 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: bind9 CVE-2009-0265 description: "Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote atta

[Bug 325261] [NEW] Gstreamer good plugins vulnerabilities

2009-02-04 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: gstreamer0.10-plugins-good CVE-2009-0386 "Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.

[Bug 325261] Re: Gstreamer good plugins vulnerabilities

2009-02-04 Thread Alexander Konovalenko
Adding CVE references: CVE-2009-0386, CVE-2009-0387, CVE-2009-0397, CVE-2009-0398 -- Gstreamer good plugins vulnerabilities https://bugs.launchpad.net/bugs/325261 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing li

[Bug 314776] [NEW] OpenSSL signature verification API misuses

2009-01-07 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: openssl Please see the details in the oCERT advisory #2008-016: http://www.ocert.org/advisories/ocert-2008-016.html "Several functions inside the OpenSSL library incorrectly check the result after ca

[Bug 238977] Re: [CVE-2008-1806, -1807, -1808] Multiple vulnerabilities in FreeType2

2009-01-23 Thread Alexander Konovalenko
*** This bug is a duplicate of bug 251369 *** https://bugs.launchpad.net/bugs/251369 This was fixed for Hardy and earlier releases back in September 2008: http://www.ubuntu.com/usn/usn-643-1. -- [CVE-2008-1806, -1807, -1808] Multiple vulnerabilities in FreeType2 https://bugs.launchpad.net/bu

[Bug 321460] [NEW] alacarte crashed with SIGSEGV in g_closure_invoke()

2009-01-26 Thread Alexander Konovalenko
Public bug reported: Binary package hint: alacarte Here is a description of what happened. I'm using Ubuntu 8.04.2. I recently installed the Konqueror browser (package konqueror) that depends on a good number of KDE packages. When I looked at the Applications menu, there were lots of new KDE-rel

[Bug 321460] Re: alacarte crashed with SIGSEGV in g_closure_invoke()

2009-01-26 Thread Alexander Konovalenko
** Attachment added: "CoreDump.gz" http://launchpadlibrarian.net/21645113/CoreDump.gz ** Attachment added: "Dependencies.txt" http://launchpadlibrarian.net/21645115/Dependencies.txt ** Attachment added: "Disassembly.txt" http://launchpadlibrarian.net/21645116/Disassembly.txt ** Attachm

[Bug 319880] Re: transmission crashed while quitting with SIGSEGV in g_closure_invoke()

2009-02-28 Thread Alexander Konovalenko
I do not know. I cannot reproduce the problem. -- transmission crashed while quitting with SIGSEGV in g_closure_invoke() https://bugs.launchpad.net/bugs/319880 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list

[Bug 133310] Re: Duplicate Cdrom entries in Software Sources

2009-02-28 Thread Alexander Konovalenko
Unfortunately I cannot install Jaunty to test that. I am not a tester and I use only LTS releases. -- Duplicate Cdrom entries in Software Sources https://bugs.launchpad.net/bugs/133310 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. --

[Bug 319880] Re: transmission crashed while quitting with SIGSEGV in g_closure_invoke()

2009-02-28 Thread Alexander Konovalenko
Hew, I don't understand your decision. We've got an unreproducible crash here that has debug information attached. Is it Ubuntu policy to ignore such bugs? Is that policy documented? Can the debug information help? I imagine someone knowledgeable enough could use the backtrace to find the specific

[Bug 319880] Re: transmission crashed while quitting with SIGSEGV in g_closure_invoke()

2009-02-28 Thread Alexander Konovalenko
Thanks for reopening this bug. The explanation makes sense to me. Could you please clarify what kind of testing do you expect to be performed on Jaunty? I know of no way to trigger this crash again even on my Hardy. Let's assume that I have installed Jaunty and the new version of Transmission does

[Bug 329716] Re: file-roller crashed with SIGSEGV in g_main_context_dispatch()

2009-02-15 Thread Alexander Konovalenko
** Attachment added: "CoreDump.gz" http://launchpadlibrarian.net/22648583/CoreDump.gz ** Attachment added: "Dependencies.txt" http://launchpadlibrarian.net/22648584/Dependencies.txt ** Attachment added: "Disassembly.txt" http://launchpadlibrarian.net/22648585/Disassembly.txt ** Attachm

[Bug 239124] [NEW] [CVE-2008-2230] Arbitrary code execution by preparing module files in os.curdir

2008-06-11 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: reportbug CVE-2008-2230 description: "Untrusted search path vulnerability in (1) reportbug 3.8 and 3.31, and (2) reportbug-ng before 0.2008.06.04, allows local users to execute arbitrary code via a m

[Bug 239129] [NEW] [CVE-2008-0960] Multiple SNMP implementations HMAC authentication spoofing

2008-06-11 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: CVE-2008-0960 description: "Some SNMP implementations include incomplete HMAC authentication code that allows spoofing of authenticated SNMPv3 packets. The authentication code reads the length to be checked from sender i

[Bug 239129] Re: [CVE-2008-0960] Multiple SNMP implementations HMAC authentication spoofing

2008-06-11 Thread Alexander Konovalenko
** Also affects: ucd-snmp (Ubuntu) Importance: Undecided Status: New -- [CVE-2008-0960] Multiple SNMP implementations HMAC authentication spoofing https://bugs.launchpad.net/bugs/239129 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ub

Re: [Bug 237690] Re: [New Upstream] Firefox 3 RC2 is available

2008-06-12 Thread Alexander Konovalenko
On Thu, Jun 12, 2008 at 04:40, LumpyCustard wrote: > As far as I know, there is no change of the code between rc2 and rc3 for > Windows and Linux. They had to do a rc3 for Mac. Are there any detailed changelogs between Firefox release candidates? I tried to find them on their web sites but failed.

[Bug 235915] Re: [CVE-2008-2426] imlib2 PNM and XPM buffer overflows

2008-06-12 Thread Alexander Konovalenko
Debian advisory: http://www.debian.org/security/2008/dsa-1594 (not yet available on the web site) In the mean time, see http://lists.debian.org/debian-security-announce/2008/msg00175.html -- [CVE-2008-2426] imlib2 PNM and XPM buffer overflows https://bugs.launchpad.net/bugs/235915 You received t

[Bug 239129] Re: [CVE-2008-0960] Multiple SNMP implementations HMAC authentication spoofing

2008-06-12 Thread Alexander Konovalenko
A tool to exploit this vulnerability has been published on Bugtraq: http://www.securityfocus.com/archive/1/493304/30/0/threaded -- [CVE-2008-0960] Multiple SNMP implementations HMAC authentication spoofing https://bugs.launchpad.net/bugs/239129 You received this bug notification because you are a

[Bug 240015] [NEW] [CVE-2008-1926] Log injection vulnerability in login

2008-06-14 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: util-linux CVE-2008-1926 description: "Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by mod

[Bug 128932] Re: Google Suggest drop-down list too narrow in Firefox

2007-09-24 Thread Alexander Konovalenko
** Changed in: firefox Bugwatch: Mozilla Bugzilla #397350 => Mozilla Bugzilla #339363 -- Google Suggest drop-down list too narrow in Firefox https://bugs.launchpad.net/bugs/128932 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu.

[Bug 218640] [NEW] Multiple vulnerabilities in OpenOffice.org (CVE-2007-574{5-7}, CVE-2008-0320)

2008-04-17 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: openoffice.org >From the Debian security advisory DSA 1547-1: "CVE-2007-5745, CVE-2007-5747 Several bugs have been discovered in the way OpenOffice.org parses Quattro Pro files that may lead t

[Bug 218652] [NEW] CVE-2008-1686: Multiple speex implementations insufficient boundary checks

2008-04-17 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Description Uncontrolled array index in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, allows remote attackers to execute arb

[Bug 205547] Re: resume produces blank screen when NVIDIA enabled on T61p

2008-04-17 Thread Alexander Konovalenko
This is a report of a genuine problem and should not be dismissed as Invalid without any investigation. Marking it as New again. ** Changed in: ubuntu Status: Invalid => New -- resume produces blank screen when NVIDIA enabled on T61p https://bugs.launchpad.net/bugs/205547 You received thi

[Bug 205547] Re: resume produces blank screen when NVIDIA enabled on T61p

2008-04-17 Thread Alexander Konovalenko
This issue is not related to yelp. Actually, it was reported in yelp by mistake, according to the reporter's blog. Marking as Invalid in yelp. ** Changed in: yelp (Ubuntu) Status: New => Invalid -- resume produces blank screen when NVIDIA enabled on T61p https://bugs.launchpad.net/bugs/20

[Bug 219491] [NEW] [CVE-2008-1722] CUPS integer overflows in PNG image handling (in files filter/image-{png, zoom}.c)

2008-04-19 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: cupsys >From the CVE description: "Multiple integer overflows in (1) filter/image-png.c and (2) filter /image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memor

[Bug 220339] [NEW] Firefox 3b5 remote DoS using JavaScript

2008-04-21 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: firefox-3.0 >From http://own-the.net/news_Firefox-3b5-on-Ubuntu-(DoS)_15.html (via Full Disclosure), reported by K-Gen: "I'll be honest, I was very surprised by this find. Very surprised. As a matter

[Bug 214818] Re: apport-gtk crashed with IOError in mark_report_seen()

2008-04-09 Thread Alexander Konovalenko
*** This bug is a duplicate of bug 129146 *** https://bugs.launchpad.net/bugs/129146 Why is this bug marked as a security vulnerability? -- apport-gtk crashed with IOError in mark_report_seen() https://bugs.launchpad.net/bugs/214818 You received this bug notification because you are a member

Re: [Bug 191791] Re: Firefox-3.0 zoomed images and webpages

2008-04-30 Thread Alexander Konovalenko
Alexander, on March 10, 2008 you marked this bug as a duplicate of bug #175904. Why? I can't see how this bug is related to bug 175904. -- Firefox-3.0 zoomed images and webpages https://bugs.launchpad.net/bugs/191791 You received this bug notification because you are a member of Ubuntu Bugs, whic

[Bug 205547] Re: resume produces blank screen when NVIDIA enabled on T61p

2008-04-30 Thread Alexander Konovalenko
See also http://intertwingly.net/blog/2008/04/28/Sleep-Quirks-Debugged and bug #202413 which might be a similar problem. -- resume produces blank screen when NVIDIA enabled on T61p https://bugs.launchpad.net/bugs/205547 You received this bug notification because you are a member of Ubuntu Bugs, w

[Bug 161173] Re: [CVE-2007-4476] cpio is affected by this CVE as tar.

2008-05-02 Thread Alexander Konovalenko
Has there been any progress on this bug? -- [CVE-2007-4476] cpio is affected by this CVE as tar. https://bugs.launchpad.net/bugs/161173 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu

[Bug 180299] Re: [tar] [CVE-2007-4476] Buffer overflow

2008-05-02 Thread Alexander Konovalenko
It is very sad that CVE-2007-4476 hasn't received any attention from the security team for several months. After reading some high-level descriptions and changelogs, it looks like Feisty and Dapper are vulnerable and that this bug might lead to arbitrary code execution when unpacking a malicious fi

[Bug 225948] [NEW] [CVE-2008-1375] Race condition in dnotify.c leads to local DoS and possible privelege escalation

2008-05-02 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Description from the National Vulnerability Database: "Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a deni

[Bug 136813] Re: (Gutsy) help button does not work in gnome-appearance-properties

2008-05-05 Thread Alexander Konovalenko
This bug still occurs in Ubuntu 8.04 Hardy release when run from the live DVD. -- (Gutsy) help button does not work in gnome-appearance-properties https://bugs.launchpad.net/bugs/136813 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. --

[Bug 197792] Re: less crashed with SIGSEGV

2008-05-05 Thread Alexander Konovalenko
This bug no longer occurs with less version 418-1 from Ubuntu 8.04 Hardy. -- less crashed with SIGSEGV https://bugs.launchpad.net/bugs/197792 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.

[Bug 222592] Re: [CVE-2008-1102] Blender imb_loadhdr() buffer overflow

2008-05-05 Thread Alexander Konovalenko
This has been fixed in Debian, see http://www.debian.org/security/2008/dsa-1567 -- [CVE-2008-1102] Blender imb_loadhdr() buffer overflow https://bugs.launchpad.net/bugs/222592 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bu

[Bug 226998] [NEW] Disabled service is restarted on package upgrade

2008-05-05 Thread Alexander Konovalenko
Public bug reported: When a service is disabled in System -> Administration -> Services and the corresponding package is upgraded, the service is started nevertheless. How to reproduce on Ubuntu 7.10 Gutsy: 1. Open the System -> Administration -> Services dialog. 2. Uncheck the checkbox near "Pr

[Bug 227345] [NEW] [CVE-2008-1103] Multiple temporary files vulnerabilities

2008-05-06 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: blender CVE-2008-1103 description: 'Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues." ' http://nvd.nist.gov/nvd.cfm?cvename=

[Bug 222592] Re: [CVE-2008-1102] Blender imb_loadhdr() buffer overflow

2008-05-06 Thread Alexander Konovalenko
CVE-2008-1103 is a separate set of problems and is best tracked in another bug report. I asked in the comments whether bug #6671 was the same problem as CVE-2008-1103 but received no reply. I have just filed bug #227345 to track CVE-2008-1103. ** CVE removed: http://www.cve.mitre.org/cgi- bin/cven

[Bug 227826] [NEW] [CVE-2008-1675] Linux kernel tehuti network driver BDX_OP_WRITE memory corruption

2008-05-07 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: CVE-2008-1675 description from the Nationval Vulnerability Database: "The bdx_ioctl_priv function in the tehuti driver (tehuti.c) in Linux kernel 2.6.x before 2.6.25 does not properly check certain information related to

[Bug 221541] [NEW] [CVE-2008-1927] Perl 5.8.8 vulnerability via UTF-8 regular expression

2008-04-24 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: perl >From the National Vulnerability Database, CVE-2008-1927: "Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to cause a denial of service (memory corruption and crash) v

[Bug 6671] Re: insecure file access (breezy, dapper, edgy, gutsy, hardy)

2008-04-26 Thread Alexander Konovalenko
Is this the same issue as CVE-2008-1103, an unspecified insecure temporary file creation vulnerability reported in a recent SUSE advisory ? ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2008-1103 -- insecure file access (breezy, dapper, edgy, g

[Bug 222592] [NEW] [CVE-2008-1102] Blender imb_loadhdr() buffer overflow

2008-04-26 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: blender CVE-2008-1102 description: "Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that cont

[Bug 221541] Re: [CVE-2008-1927] Perl 5.8.8 vulnerability via UTF-8 regular expression

2008-04-26 Thread Alexander Konovalenko
** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2008-1927 -- [CVE-2008-1927] Perl 5.8.8 vulnerability via UTF-8 regular expression https://bugs.launchpad.net/bugs/221541 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. --

[Bug 6671] Re: insecure file access (breezy, dapper, edgy, gutsy, hardy)

2008-04-26 Thread Alexander Konovalenko
It seems that Launchpad has automatically added a CVE reference to this bug without asking me for a confirmation. I'll remove the reference now to prevent possible confusion. If you know that this problem and CVE-2008-1103 are in fact the same issue, please add the CVE reference again. ** CVE remo

[Bug 222649] [NEW] Another Firefox 3 beta 5 remote DoS using JavaScript

2008-04-26 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: firefox-3.0 Juan Pablo Lopez Yacubian reported at Bugtraq that the following HTML code causes Firefox 3 beta 5 to crash: function crash() { while(1) document.write("

[Bug 223196] [NEW] [CVE-2008-1679, CVE-2008-1721] Python 2.5 vulnerabilities

2008-04-27 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: python2.5 I see in the changelog that CVE-2008-1679 and CVE-2008-1721 have been fixed in Hardy. But no updates for previous releases were issued. It looks like Gutsy, Feisty and Edgy are vulnerable an

[Bug 223196] Re: [CVE-2008-1679, CVE-2008-1721] Python 2.5 vulnerabilities

2008-04-27 Thread Alexander Konovalenko
Oh, Edgy is no longer supported. So let it be Gutsy and Feisty. -- [CVE-2008-1679, CVE-2008-1721] Python 2.5 vulnerabilities https://bugs.launchpad.net/bugs/223196 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing l

[Bug 205547] Re: resume produces blank screen when NVIDIA enabled on T61p

2008-04-12 Thread Alexander Konovalenko
Christophe, could you please explain why this is not a bug report? I see a real problem here that needs to be fixed. Resume should not result in a blank screen. -- resume produces blank screen when NVIDIA enabled on T61p https://bugs.launchpad.net/bugs/205547 You received this bug notification be

[Bug 217128] [NEW] CVE-2008-1382: libpng zero-length chunks incorrect handling

2008-04-14 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: >From the oCERT advisory: "Applications using libpng that install unknown chunk handlers, or copy unknown chunks, may be vulnerable to a security issue which may result in incorrect output, information leaks, crashes, or

[Bug 228193] [NEW] rdesktop 1.5.0 multiple remote vulnerabilities [CVE-2008-1801, -1802, -1803]

2008-05-08 Thread Alexander Konovalenko
*** This bug is a security vulnerability *** Public security bug reported: Binary package hint: rdesktop * CVE-2008-1801: iso_recv_msg() integer underflow Description by iDefense: "Remote exploitation of an integer underflow vulnerability in rdesktop [...] allows attackers to execute arbitrary

[Bug 205547] Re: resume produces blank screen when NVIDIA enabled on T61p

2008-05-12 Thread Alexander Konovalenko
Sorry, Max, I don't know much about these bug reports and don't have any of the relevant hardware to test things either. You can use the Launchpad search feature to look for similar bugs that have already been reported. I guess you should file another bug report if the workarounds described here an

[Bug 127940] logrotate script for acpid may send USR1 to innocent processes

2007-07-24 Thread Alexander Konovalenko
Public bug reported: Binary package hint: acpid The script /etc/logrotate.d/acpid in version 1.0.4-5ubuntu6 of package acpid (which appears in 7.04 Feisty) issues the following command to restart the acpid process: pkill -SIGUSR1 acpid > /dev/null If a user for some reason runs her own executab

[Bug 127940] Re: logrotate script for acpid may send USR1 to innocent processes

2007-07-24 Thread Alexander Konovalenko
Correction: The pkill command is issued not to *restart* acpid, but to make it reload its configuration or something. Everything else still holds. -- logrotate script for acpid may send USR1 to innocent processes https://bugs.launchpad.net/bugs/127940 You received this bug notification because y

[Bug 127960] Unresponsive script dialog usability problems

2007-07-24 Thread Alexander Konovalenko
Public bug reported: Binary package hint: firefox First, see attached screenshot. Here is a textual description of it. The "Warning: Unresponsive script" dialog has two buttons: "Continue" and "Stop script". The Continue button's icon is a red X. The "Stop script" button's icon is a green Enter-

[Bug 127960] Screenshot

2007-07-24 Thread Alexander Konovalenko
** Attachment added: "The dialog in question" http://launchpadlibrarian.net/8559601/Warning%3A%20Unresponsive%20script.png -- Unresponsive script dialog usability problems https://bugs.launchpad.net/bugs/127960 You received this bug notification because you are a member of Ubuntu Bugs, which

[Bug 30522] Re: MASTER - Firefox goes to windowed state, not maximized when leaving full screen mode

2007-07-24 Thread Alexander Konovalenko
I can reproduce this in firefox 2.0.0.5+1-0ubuntu1 from 7.04 Feisty. -- MASTER - Firefox goes to windowed state, not maximized when leaving full screen mode https://bugs.launchpad.net/bugs/30522 You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscri

[Bug 127960] Re: Unresponsive script dialog usability problems

2007-07-24 Thread Alexander Konovalenko
Alexander, could you please elaborate on what exactly is tricky? I'm not sure I get what you mean. -- Unresponsive script dialog usability problems https://bugs.launchpad.net/bugs/127960 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubunt

[Bug 128159] Re: Jabber: Client and OS version visible to authorized buddies

2007-07-25 Thread Alexander Konovalenko
** Visibility changed to: Public -- Jabber: Client and OS version visible to authorized buddies https://bugs.launchpad.net/bugs/128159 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.u

[Bug 128159] Re: Jabber: Client and OS version visible to authorized buddies

2007-07-25 Thread Alexander Konovalenko
** This bug is no longer flagged as a security issue ** This bug has been flagged as a security issue -- Jabber: Client and OS version visible to authorized buddies https://bugs.launchpad.net/bugs/128159 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug

[Bug 127960] Re: Unresponsive script dialog usability problems

2007-07-25 Thread Alexander Konovalenko
> There are two purposes: > > * The initial purpose was to abort scripts that are looping as they > are primary considered malicious. > > * The second pupose is to continue scripts because your system is too > slow for the javascript application. > >For initial case, the idea is to guide the user t

[Bug 127960] Test case to reproduce Firefox's "Unresponsive script" dialog

2007-07-26 Thread Alexander Konovalenko
Attached is an HTML file that enters an infinite loop in JavaScript when loaded. Opening that file is an easy way to have Firefox show the "Warning: Unresponsive script" dialog and play with it. Please DON'T OPEN THE ATTACHED FILE IF YOUR BROWSER CAN'T HANDLE RUN- AWAY JAVASCRIPT. ** Attachment a

[Bug 127960] Re: Unresponsive script dialog usability problems

2007-07-26 Thread Alexander Konovalenko
sponsive script" dialog from a vanilla Firefox for Linux build from mozilla.com, I would be grateful. You can use the file from my previous message to produce that dialog. -- Alexander Konovalenko -- Unresponsive script dialog usability problems https://bugs.launchpad.net/bugs/127960 Y

[Bug 128159] Re: Jabber: Client and OS version visible to authorized buddies

2007-07-26 Thread Alexander Konovalenko
This issue has been assigned CVE number CVE-2007-4002. ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2007-4002 -- Jabber: Client and OS version visible to authorized buddies https://bugs.launchpad.net/bugs/128159 You received this bug notification because you are a member of U

[Bug 127960] Re: Unresponsive script dialog usability problems

2007-07-26 Thread Alexander Konovalenko
John Vivirito wrote: > Using the link in > https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/127960/comments/10 > I dont have icons with default human theme at all. Screenshot is attached. John, I'm running Ubuntu 7.04 Feisty Fawn with latest security and recommend updates. Do you have the s

[Bug 128159] Re: Jabber: Client and OS version visible to authorized buddies

2007-07-27 Thread Alexander Konovalenko
** Bug watch added: Pidgin bug tracker #2264 http://developer.pidgin.im/ticket/2264 ** Also affects: gaim (upstream) via http://developer.pidgin.im/ticket/2264 Importance: Unknown Status: Unknown -- Jabber: Client and OS version visible to authorized buddies https://bugs.launchpa

[Bug 128932] Google Suggest drop-down list too narrow in Firefox

2007-07-28 Thread Alexander Konovalenko
Public bug reported: Binary package hint: firefox The Google Suggest drop-down list is too narrow by default in Firefox 2.0 (I'm using Firefox 2.0.0.5+1-0ubuntu1 from 7.04 Feisty). See the screenshot attached. I'm using the default theme and fonts at the resolution of 1024x768. The mouse pointer

[Bug 128932] Re: Google Suggest drop-down list too narrow in Firefox

2007-07-28 Thread Alexander Konovalenko
** Attachment added: "Dependencies.txt" http://launchpadlibrarian.net/8591160/Dependencies.txt -- Google Suggest drop-down list too narrow in Firefox https://bugs.launchpad.net/bugs/128932 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for

[Bug 128932] Re: Google Suggest drop-down list too narrow in Firefox

2007-07-28 Thread Alexander Konovalenko
** Attachment added: "Screenshot that demonstrates the problem" http://launchpadlibrarian.net/8591162/Google_Suggest_usability_problem_in_Firefox.png -- Google Suggest drop-down list too narrow in Firefox https://bugs.launchpad.net/bugs/128932 You received this bug notification because you a

[Bug 128939] Re: Lock icon in Firefox disappears when pointed by the mouse

2007-07-28 Thread Alexander Konovalenko
** Attachment added: "Dependencies.txt" http://launchpadlibrarian.net/8591797/Dependencies.txt -- Lock icon in Firefox disappears when pointed by the mouse https://bugs.launchpad.net/bugs/128939 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug conta

[Bug 128939] Lock icon in Firefox disappears when pointed by the mouse

2007-07-28 Thread Alexander Konovalenko
Public bug reported: Binary package hint: firefox Steps to reproduce: 1. Open any https page in Firefox. For example, https://launchpad.net/ 2. A yellow lock icon appears to the right of the address bar. Point your mouse over that icon. Don't click, just move the pointer. 3. Whenever the mouse

[Bug 128941] Sound events configuration usability problem in Gaim

2007-07-28 Thread Alexander Konovalenko
Public bug reported: Binary package hint: gaim Steps to reproduce: 1. Open the main window of Gaim (the Buddy List). 2. Select Tools -> Preferences in the menu. 3. In the Preferences window that appears, select the Sounds tab. 4. Look at the "Sound events" list. It shows about one row and a h

[Bug 128941] Re: Sound events configuration usability problem in Gaim

2007-07-28 Thread Alexander Konovalenko
** Attachment added: "Dependencies.txt" http://launchpadlibrarian.net/8591879/Dependencies.txt ** Attachment added: "ProcMaps.txt" http://launchpadlibrarian.net/8591880/ProcMaps.txt ** Attachment added: "ProcStatus.txt" http://launchpadlibrarian.net/8591881/ProcStatus.txt -- Sound eve

[Bug 128941] Re: Sound events configuration usability problem in Gaim

2007-07-28 Thread Alexander Konovalenko
** Attachment added: "Screenshot: Gaim Preferences -> Sounds" http://launchpadlibrarian.net/8591886/Gaim_Preferences_Sounds.png -- Sound events configuration usability problem in Gaim https://bugs.launchpad.net/bugs/128941 You received this bug notification because you are a member of Ubuntu

[Bug 128939] Re: Lock icon in Firefox disappears when pointed by the mouse

2007-08-01 Thread Alexander Konovalenko
> Do you have the same problem with the default firefox > theme (Tools -> Add-ons)? No. When using the default Firefox theme, the lock icon doesn't disappear when pointed at. It just gets highlighted (a yellow border around it appears). Just to articulate it, I was using the Firefox Human theme

[Bug 132788] Re: gedit doesn't notice that a file has been renamed

2007-08-15 Thread Alexander Konovalenko
** Attachment added: "Dependencies.txt" http://launchpadlibrarian.net/8844707/Dependencies.txt ** Attachment added: "ProcMaps.txt" http://launchpadlibrarian.net/8844708/ProcMaps.txt ** Attachment added: "ProcStatus.txt" http://launchpadlibrarian.net/8844709/ProcStatus.txt -- gedit doe

[Bug 132788] gedit doesn't notice that a file has been renamed

2007-08-15 Thread Alexander Konovalenko
Public bug reported: Binary package hint: gedit When you edit a file in gedit and the file is renamed, gedit doesn't notice that the file on disk has disappeared. Instead, when trying to save a file that has been renamed, a warning should appear, similar to the yellow warning bar that appears whe

[Bug 132788] Re: gedit doesn't notice that a file has been renamed

2007-08-15 Thread Alexander Konovalenko
** Description changed: Binary package hint: gedit When you edit a file in gedit and the file is renamed, gedit doesn't notice that the file on disk has disappeared. Instead, when trying to save a file that has been renamed, a warning should appear, similar to the yellow warning bar t

[Bug 132800] Re: Command line automatically included in bug report, violating user's privacy

2007-08-15 Thread Alexander Konovalenko
** Attachment added: "Dependencies.txt" http://launchpadlibrarian.net/8845029/Dependencies.txt -- Command line automatically included in bug report, violating user's privacy https://bugs.launchpad.net/bugs/132800 You received this bug notification because you are a member of Ubuntu Bugs, whic

[Bug 132800] Command line automatically included in bug report, violating user's privacy

2007-08-15 Thread Alexander Konovalenko
Public bug reported: Binary package hint: apport I used the "Help -> Report a problem" menu item in gedit to report bug #132788. The command line of my gedit process was automatically included in the bug report. The command line contained the pathname of a file that I clicked to open that particu

[Bug 132812] When moving, renaming, deleting files, their backup copies are not modified

2007-08-15 Thread Alexander Konovalenko
Public bug reported: Binary package hint: nautilus When moving, renaming, and deleting files that have backup copies (those have the same filename with a tilde in the end, like 'filename~'), the backup copy is not affected by any such change to the main file. Since the backup copies are usually i

[Bug 132812] Re: When moving, renaming, deleting files, their backup copies are not modified

2007-08-15 Thread Alexander Konovalenko
** Attachment added: "Dependencies.txt" http://launchpadlibrarian.net/8845363/Dependencies.txt -- When moving, renaming, deleting files, their backup copies are not modified https://bugs.launchpad.net/bugs/132812 You received this bug notification because you are a member of Ubuntu Bugs, whic

[Bug 46632] Re: no warning about running synaptic session

2007-08-15 Thread Alexander Konovalenko
I encountered this as well, losing a long list of carefully selected changes. Why is the importance set to "wishlist"? This is a real bug that causes user data loss. I was using Feisty Fawn 7.04 with the following package versions: gnome-app-install 0.3.31 synaptic 0.57.11.1ubuntu14 If anyone nee

[Bug 132824] gnome-games leaves .pyc files in site-packages when removed

2007-08-15 Thread Alexander Konovalenko
Public bug reported: Binary package hint: gnome-games Removing gnome-games 1:2.18.1-0ubuntu1 (from 7.04 Feisty) leaves some directories and .pyc files in the following directories: /usr/lib/python2.5/site-packages/gnome_sudoku/ /usr/lib/python2.5/site-packages/glchess/ dpkg then complains that

[Bug 132828] Caps Lock indication invalid when it is used to switch keyboard layouts

2007-08-15 Thread Alexander Konovalenko
Public bug reported: Binary package hint: gnome-screensaver I use Caps Lock to switch keyboard layouts from one language to another. (It was recommended by the text mode installer of 7.04 Feisty Fawn, and it turned out to be very convenient indeed). The actual Caps Lock effect is achieved by pres

[Bug 132828] Re: Caps Lock indication invalid when it is used to switch keyboard layouts

2007-08-15 Thread Alexander Konovalenko
** Attachment added: "Dependencies.txt" http://launchpadlibrarian.net/8845828/Dependencies.txt -- Caps Lock indication invalid when it is used to switch keyboard layouts https://bugs.launchpad.net/bugs/132828 You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 132832] Configuring encrypted volumes in 7.04 debian-installer?

2007-08-15 Thread Alexander Konovalenko
Public bug reported: Binary package hint: debian-installer The Installation Guide for 7.04 Feisty describes how to configure encrypted disk volumes during the text-mode installation . However, I was unable

[Bug 132835] Firefox uses a different user dictionary for spell checking than gedit

2007-08-15 Thread Alexander Konovalenko
Public bug reported: Firefox and gedit use two different spell checking dictionaries to which the user can add words manually. The user has to add some new words twice, separately in each application. Firefox and gedit should use a single user dictionary instead. ProblemType: Bug Architecture: i

[Bug 46632] Re: no warning about running synaptic session

2007-08-18 Thread Alexander Konovalenko
The libgtk bug watched from here has nothing to do with this gnome-app- install issue. It was probably referenced by mistake. ** Changed in: libgtk (upstream) Importance: Undecided => Unknown Bugwatch: None => GNOME Bug Tracker #342952 Status: New => Unknown ** Changed in: libgtk (

[Bug 133310] Duplicate Cdrom entries in Software Sources

2007-08-18 Thread Alexander Konovalenko
Public bug reported: After installing 7.04 Feisty Fawn from the DVD using the text-mode installer, there are two identical CD-ROM entries in Software Sources. To reproduce: 1. Install Ubuntu 7.04 from the live/installation DVD using the text- mode installer. 2. Log in to the administrative acco

[Bug 133310] Re: Duplicate Cdrom entries in Software Sources

2007-08-18 Thread Alexander Konovalenko
** Attachment added: "Dependencies.txt" http://launchpadlibrarian.net/8885059/Dependencies.txt -- Duplicate Cdrom entries in Software Sources https://bugs.launchpad.net/bugs/133310 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu.

[Bug 89219] Re: Switching back to an user account needs no password

2007-08-18 Thread Alexander Konovalenko
** This bug has been flagged as a security issue -- Switching back to an user account needs no password https://bugs.launchpad.net/bugs/89219 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contact for Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@

[Bug 133310] Re: Duplicate Cdrom entries in Software Sources

2007-08-18 Thread Alexander Konovalenko
Here it is. ** Attachment added: "/etc/apt/sources.list" http://launchpadlibrarian.net/8887378/sources.list -- Duplicate Cdrom entries in Software Sources https://bugs.launchpad.net/bugs/133310 You received this bug notification because you are a member of Ubuntu Bugs, which is the bug contac

[Bug 133310] Re: Duplicate Cdrom entries in Software Sources

2007-08-21 Thread Alexander Konovalenko
If anyone needs more information, please feel free to mark this bug as Incomplete again. ** Changed in: software-properties (Ubuntu) Status: Incomplete => New -- Duplicate Cdrom entries in Software Sources https://bugs.launchpad.net/bugs/133310 You received this bug notification because y

Re: [Bug 128159] Re: Jabber: Client and OS version visible to authorized buddies

2007-08-24 Thread Alexander Konovalenko
On 24/08/07, Sebastien Bacher <[EMAIL PROTECTED]> wrote: > doesn't seem to be a security issue Sebastien, To summarize my analysis above, revealing the versions of software and the hardware architecture can aid attackers to conceal their attacks and to perform them with a greater rate of success.

[Bug 112484] Re: audio skips under IO load

2007-08-25 Thread Alexander Konovalenko
I observe plenty of skipping on Pentium III 666 MHz with 256 MB of RAM, 1 GB of swap, and a Seagate ST340016A hard disk, running Rhythmbox on Ubuntu 7.04 Feisty Fawn. Anyone has any idea what part of software is responsible for (1) the skipping per se; (2) not resuming in the same place where it l

[Bug 128159] Re: Jabber: Client and OS version visible to authorized buddies

2007-08-26 Thread Alexander Konovalenko
On 24/08/07, Sebastien Bacher wrote: > that's nothin really exploitable and there is other way to determine > what OS is running What is that other way to determine the exact kernel version of an Ubuntu machine remotely? Assume that the attacker can communicate with the victim's Pidgin client by s

[Bug 132812] Re: When moving, renaming, deleting files, their backup copies are not modified

2007-08-27 Thread Alexander Konovalenko
** Bug watch added: GNOME Bug Tracker #46883 http://bugzilla.gnome.org/show_bug.cgi?id=46883 ** Also affects: nautilus via http://bugzilla.gnome.org/show_bug.cgi?id=46883 Importance: Unknown Status: Unknown -- When moving, renaming, deleting files, their backup copies are not mod

<    1   2   3   4   >