Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SRU] Thunar CVE-2021-32563 (focal, groovy, hirsute) #6

Open
1 task done
bluesabre opened this issue Jun 8, 2021 · 9 comments
Open
1 task done

[SRU] Thunar CVE-2021-32563 (focal, groovy, hirsute) #6

bluesabre opened this issue Jun 8, 2021 · 9 comments
Assignees

Comments

@bluesabre
Copy link
Member

Describe the bug(s) being fixed
CVE-2021-32563 affects Thunar versions found in supported releases. Related patches:

GitLab issues #121, #575

To Reproduce
Steps to reproduce the behavior:

  1. Execute thunar ~/Pictures/icon.png
  2. The default application loads the file.

Expected behavior
Thunar should instead open, selecting the file.

Desktop (please complete the following information):

  • Xubuntu Releases: focal, groovy, hirsute
  • Package: thunar
  • Versions: 1.8.14-0ubuntu1, 1.8.15-1, 4.16.6-0ubuntu1

Additional context
Scripts and applications depending on the previous functionality will be adversely affected. Since this functionality is specific to Thunar, this change should have minimal regression impact.

Verification

@bluesabre
Copy link
Member Author

@bluesabre
Copy link
Member Author

@bluesabre
Copy link
Member Author

@bluesabre
Copy link
Member Author

@philipzae I've got some early experimental builds for focal, groovy, and hirsute above (some are still building). Can you or the testers give them a quick test before I submit formal SRUs on Launchpad?

@bluesabre bluesabre self-assigned this Jun 8, 2021
@philipzae
Copy link

@bluesabre on it.

@JT252
Copy link

JT252 commented Jun 8, 2021

I was able to reproduce the issue with Xubuntu_21.04 with the experimental build.

@bluesabre
Copy link
Member Author

@JT252 Does that mean that the issue is not fixed? I'll have to take another look.

@JT252
Copy link

JT252 commented Jun 9, 2021 via email

@bluesabre
Copy link
Member Author

@JT252 Thanks for the confirmation.

I've created a public security bug on Launchpad for the CVE.
https://bugs.launchpad.net/ubuntu/+source/thunar/+bug/1931510

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: No status
Development

No branches or pull requests

3 participants