[ubuntu/kinetic-proposed] accountsservice 22.07.5-2ubuntu2 (Accepted)
Gunnar Hjalmarsson
gunnarhj at ubuntu.com
Tue May 24 18:04:11 UTC 2022
accountsservice (22.07.5-2ubuntu2) kinetic; urgency=medium
[ Marc Deslauriers ]
* SECURITY UPDATE: accountsservice incorrect privilege dropping
(LP: #1974250)
- debian/patches/0009-language-tools.patch: updated to not reset
effective uid, and migrate root-owned .pam_environment file.
- This change was originally known as CVE-2020-16126 and got reverted
by mistake in 0.6.55-3ubuntu1.
- CVE-2022-1804
* Fix FTBFS with a newer python-dbusmock package:
- debian/patches/adduser_invocation.patch: fix invocation of AddUser in
tests/dbusmock/accounts_service.py.
- debian/patches/setlocked_signature.patch: fix the signature for the
SetLocked call in tests/dbusmock/accounts_service.py.
Date: Tue, 24 May 2022 19:53:07 +0200
Changed-By: Gunnar Hjalmarsson <gunnarhj at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/accountsservice/22.07.5-2ubuntu2
-------------- next part --------------
Format: 1.8
Date: Tue, 24 May 2022 19:53:07 +0200
Source: accountsservice
Built-For-Profiles: noudeb
Architecture: source
Version: 22.07.5-2ubuntu2
Distribution: kinetic
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Gunnar Hjalmarsson <gunnarhj at ubuntu.com>
Launchpad-Bugs-Fixed: 1974250
Changes:
accountsservice (22.07.5-2ubuntu2) kinetic; urgency=medium
.
[ Marc Deslauriers ]
* SECURITY UPDATE: accountsservice incorrect privilege dropping
(LP: #1974250)
- debian/patches/0009-language-tools.patch: updated to not reset
effective uid, and migrate root-owned .pam_environment file.
- This change was originally known as CVE-2020-16126 and got reverted
by mistake in 0.6.55-3ubuntu1.
- CVE-2022-1804
* Fix FTBFS with a newer python-dbusmock package:
- debian/patches/adduser_invocation.patch: fix invocation of AddUser in
tests/dbusmock/accounts_service.py.
- debian/patches/setlocked_signature.patch: fix the signature for the
SetLocked call in tests/dbusmock/accounts_service.py.
Checksums-Sha1:
083531aa1f3bdf33c5ad155db6ecd158d24451e3 2861 accountsservice_22.07.5-2ubuntu2.dsc
5bdeccb06623bdcf99e91ff52c1454920ae251e3 31188 accountsservice_22.07.5-2ubuntu2.debian.tar.xz
9ea1298886869002c09a397031e8e77e67840844 9845 accountsservice_22.07.5-2ubuntu2_source.buildinfo
Checksums-Sha256:
cccaca8b9ff029d10497e4945066cacba20e1eb02192d1e73626cc0ad95d270b 2861 accountsservice_22.07.5-2ubuntu2.dsc
954b080fbfa6d901cf12b9270c3ea20846fc1bfb896fa68a6a65a0c4f1d26cfb 31188 accountsservice_22.07.5-2ubuntu2.debian.tar.xz
3b2ba979c493bb11fe0e8ce1a8dd5bd24b8cccb71e705cbf38a4a8ff74f70905 9845 accountsservice_22.07.5-2ubuntu2_source.buildinfo
Files:
f279f5088e6b5f80341c8f88e7bf2f77 2861 admin optional accountsservice_22.07.5-2ubuntu2.dsc
5c48617f66bd66cf8e46ad3c7fe285ac 31188 admin optional accountsservice_22.07.5-2ubuntu2.debian.tar.xz
bc25ef4cedb94a058bb448527e38d44a 9845 admin optional accountsservice_22.07.5-2ubuntu2_source.buildinfo
Original-Maintainer: Debian freedesktop.org maintainers <pkg-freedesktop-maintainers at lists.alioth.debian.org>
More information about the kinetic-changes
mailing list