Community Packages

Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#67514 - [security][firejail] CVE-2020-17367 / CVE-2020-17368

Attached to Project: Community Packages
Opened by T.J. Townsend (blakkheim) - Thursday, 06 August 2020, 20:34 GMT
Last edited by Sergej Pupykin (sergej) - Tuesday, 11 August 2020, 22:22 GMT
Task Type Bug Report
Category Packages
Status Closed
Assigned To Sergej Pupykin (sergej)
Levente Polyak (anthraxx)
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Description:
The firejail package is currently vulnerable to these two issues. Fixes for both are now public.

Additional info:
https://github.com/netblue30/firejail/commit/2c734d6350ad321fccbefc5ef0382199ac331b37

https://github.com/netblue30/firejail/commit/34193604fed04cad2b7b6b0f1a3a0428afd9ed5b

Patches should be added to the package in lieu of a new release, which has not been made as of the time this bug is being filed.
This task depends upon

Closed by  Sergej Pupykin (sergej)
Tuesday, 11 August 2020, 22:22 GMT
Reason for closing:  Fixed
Comment by T.J. Townsend (blakkheim) - Thursday, 06 August 2020, 21:15 GMT
PKGBUILD diff to add patches.
Comment by T.J. Townsend (blakkheim) - Tuesday, 11 August 2020, 12:38 GMT

Loading...