https://bugzilla.redhat.com/show_bug.cgi?id=2042511
Bug ID: 2042511
Summary: CVE-2022-22815 python-pillow: improperly initializes
ImagePath.Path in path_getbbox() in path.c
Product: Security Response
Hardware: All
OS: Linux
Status: NEW
Component: vulnerability
Keywords: Security
Severity: medium
Priority: medium
Assignee: security-response-team(a)redhat.com
Reporter: gsuckevi(a)redhat.com
CC: bdettelb(a)redhat.com, cstratak(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
infra-sig(a)lists.fedoraproject.org,
manisandro(a)gmail.com, miminar(a)redhat.com,
orion(a)nwra.com, python-maint(a)redhat.com,
python-sig(a)lists.fedoraproject.org, torsava(a)redhat.com
Target Milestone: ---
Classification: Other
path_getbbox in path.c in Pillow before 9.0.0 improperly initializes
ImagePath.Path.
References:
https://github.com/python-pillow/Pillow/blob/c5d9223a8b5e9295d15b5a9b1ef1da…https://pillow.readthedocs.io/en/stable/releasenotes/9.0.0.html#fixed-image…
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2042511
https://bugzilla.redhat.com/show_bug.cgi?id=2176591
Bug ID: 2176591
Summary: msmtp package should provide /usr/bin/sendmail
Product: Fedora
Version: rawhide
Status: NEW
Component: msmtp
Assignee: lemenkov(a)gmail.com
Reporter: yann(a)droneaud.fr
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
gbcox(a)bzb.us, lemenkov(a)gmail.com, ndevos(a)redhat.com,
wart(a)kobold.org
Target Milestone: ---
Classification: Fedora
Description of problem:
msmtp package is not declared to provide /usr/sbin/sendmail. But installing
the package, makes msmtp the "mta" (see alternatives --display mta), and thus
provide /usr/bin/sendmail.
Some packages, see below, requires /usr/sbin/sendmail
BackupPC-0:4.4.0-9.fc38.x86_64
alpine-0:2.26-3.fc38.x86_64
arpwatch-14:3.3-14.fc39.x86_64
asterisk-voicemail-0:18.12.1-1.fc38.3.x86_64
certwatch-mod_ssl-0:1.2-12.fc38.x86_64
fail2ban-sendmail-0:1.0.2-2.fc38.noarch
fvwm-0:2.7.0-3.fc38.x86_64
hylafax+-client-0:7.0.7-1.fc39.i686
hylafax+-client-0:7.0.7-1.fc39.x86_64
mgetty-0:1.2.1-18.fc38.x86_64
quilt-0:0.67-4.fc39.noarch
redhat-lsb-core-0:4.1-60.fc38.i686
redhat-lsb-core-0:4.1-60.fc38.x86_64
spamass-milter-0:0.4.0-24.fc38.x86_64
uudeview-0:0.5.20-51.fc38.x86_64
websec-0:1.9.0-34.fc38.noarch
x509watch-0:0.6.1-14.fc38.noarch
Thus, when asking dnf to install one of the packages above, it will also
install another mta from the list below if none of them is already installed.
Likely esmtp in my experience (likely because it's the first alphabetically).
esmtp-0:1.2-21.fc38.x86_64
exim-0:4.96-8.fc38.x86_64
opensmtpd-0:6.8.0p2-11.fc38.x86_64
postfix-2:3.7.4-1.fc38.x86_64
sendmail-0:8.17.1-8.fc38.x86_64
ssmtp-0:2.64-32.fc38.x86_64
Having msmtp already installed should be enough to satisfy /usr/sbin/sendmail
requirement, and no other MTA should be installed as part of installing another
package.
Version-Release number of selected component (if applicable):
msmtp-1.8.23-1.fc38.x86_64
How reproducible:
When installing a package that requires /usr/bin/sendmail when no other MTA
is installed.
Steps to Reproduce:
1. dnf install msmtp
2. dnf install arpwatch
Actual results:
"dnf install arpwatch" installs arpwatch and esmtp
Expected results:
"dnf install arpwatch" would install only arpwatch
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2176591
https://bugzilla.redhat.com/show_bug.cgi?id=2208403
Bug ID: 2208403
Summary: busybox-1.36.1 is available
Product: Fedora
Version: rawhide
Status: NEW
Component: busybox
Keywords: FutureFeature, Triaged
Assignee: spotrh(a)gmail.com
Reporter: upstream-release-monitoring(a)fedoraproject.org
QA Contact: extras-qa(a)fedoraproject.org
CC: admiller(a)redhat.com, davide(a)cavalca.name,
dvlasenk(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
spotrh(a)gmail.com
Target Milestone: ---
Classification: Fedora
Releases retrieved: 1.36.1
Upstream release that is considered latest: 1.36.1
Current version/release in rawhide: 1.36.0-2.fc38
URL: https://www.busybox.net/
Please consult the package updates policy before you issue an update to a
stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/
More information about the service that created this bug can be found at:
https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_M…
Please keep in mind that with any upstream change, there may also be packaging
changes that need to be made. Specifically, please remember that it is your
responsibility to review the new version to ensure that the licensing is still
correct and that no non-free or legally problematic items have been added
upstream.
Based on the information from Anitya:
https://release-monitoring.org/project/230/
To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/busybox
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2208403
https://bugzilla.redhat.com/show_bug.cgi?id=2218820
Bug ID: 2218820
Summary: [abrt] meld: get_path_for_repo_file():
_null.py:48:get_path_for_repo_file:FileNotFoundError:
[Errno 2] No such file or directory:
'/static/markdown/owms/owms-4.0-waardelijsten-thema-in
deling-voor-officiele-publicaties.md'
Product: Fedora
Version: 38
Hardware: x86_64
Status: NEW
Whiteboard: abrt_hash:30c15e3cd74d238b6f38fd99d10f0fbb8b6527e7;VAR
IANT_ID=workstation;
Component: meld
Assignee: dmaphy(a)fedoraproject.org
Reporter: jan.public(a)famvlug.nl
QA Contact: extras-qa(a)fedoraproject.org
CC: dmaphy(a)fedoraproject.org,
epel-packagers-sig(a)lists.fedoraproject.org,
lkundrak(a)v3.sk, michel(a)michel-slm.name
Target Milestone: ---
Classification: Fedora
Version-Release number of selected component:
meld-3.22.0-2.fc38
Additional info:
reporter: libreport-2.17.10
kernel: 6.3.8-200.fc38.x86_64
cmdline: /usr/bin/python3 /usr/bin/meld
../../../../../../static/markdown/owms/owms-4.0-waardelijsten-thema-indeling-voor-officiele-publicaties.md
uid: 1000
reason: _null.py:48:get_path_for_repo_file:FileNotFoundError: [Errno 2]
No such file or directory:
'/static/markdown/owms/owms-4.0-waardelijsten-thema-indeling-voor-officiele-publicaties.md'
executable: /usr/bin/meld
type: Python3
package: meld-3.22.0-2.fc38
runlevel: N 5
exception_type: FileNotFoundError
crash_function: get_path_for_repo_file
interpreter: python3-3.11.3-2.fc38.x86_64
Truncated backtrace:
_null.py:48:get_path_for_repo_file:FileNotFoundError: [Errno 2] No such file or
directory:
'/static/markdown/owms/owms-4.0-waardelijsten-thema-indeling-voor-officiele-publicaties.md'
Traceback (most recent call last):
File "/usr/lib/python3.11/site-packages/meld/meldapp.py", line 86, in
do_command_line
tab = self.parse_args(command_line)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.11/site-packages/meld/meldapp.py", line 368, in
parse_args
tab = self.open_files(
^^^^^^^^^^^^^^^^
File "/usr/lib/python3.11/site-packages/meld/meldapp.py", line 166, in
open_files
return window.open_paths(gfiles, **kwargs)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.11/site-packages/meld/meldwindow.py", line 466, in
open_paths
self._single_file_open(a)
File "/usr/lib/python3.11/site-packages/meld/meldwindow.py", line 455, in
_single_file_open
doc.run_diff(path)
File "/usr/lib/python3.11/site-packages/meld/vcview.py", line 565, in
run_diff
comp_path = self.vc.get_path_for_repo_file(path)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.11/site-packages/meld/vc/_null.py", line 48, in
get_path_for_repo_file
with open(path, 'rb') as vc_file:
^^^^^^^^^^^^^^^^
FileNotFoundError: [Errno 2] No such file or directory:
'/static/markdown/owms/owms-4.0-waardelijsten-thema-indeling-voor-officiele-publicaties.md'
Local variables in innermost frame:
self: <meld.vc._null.Vc object at 0x7fc770ce91d0>
path:
'/static/markdown/owms/owms-4.0-waardelijsten-thema-indeling-voor-officiele-publicaties.md'
commit: None
suffix: '.md'
f: <tempfile._TemporaryFileWrapper object at 0x7fc771ac1090>
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2218820
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2216921
Bug ID: 2216921
Summary: [abrt] nemo: nemo_window_slot_get_window():
nemo-desktop killed by SIGABRT
Product: Fedora
Version: 38
Hardware: x86_64
Status: NEW
Whiteboard: abrt_hash:2f774e2f6c882f0f08b855988b10f1000f9832f3;VAR
IANT_ID=workstation;
Component: nemo
Assignee: leigh123linux(a)googlemail.com
Reporter: pbabinca(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
leigh123linux(a)googlemail.com, riehecky(a)fnal.gov
Target Milestone: ---
Classification: Fedora
Description of problem:
I disconnected thunderbolt4 docking station to which among other things
external monitor is connected.
Version-Release number of selected component:
nemo-5.6.4-1.fc38
Additional info:
reporter: libreport-2.17.10
type: CCpp
reason: nemo-desktop killed by SIGABRT
journald_cursor:
s=8dc583e8364c483faa53c7dcf2279e08;i=5c2c40;b=4a49785b8cc2421c8552b2883eb4aec9;m=14dc5511;t=5fec82e2d40eb;x=199436db1882e715
executable: /usr/bin/nemo-desktop
cmdline: nemo-desktop
cgroup: 0::/user.slice/user-18031.slice/session-2.scope
rootdir: /
uid: 18031
kernel: 6.3.8-200.fc38.x86_64
package: nemo-5.6.4-1.fc38
runlevel: N 5
backtrace_rating: 4
crash_function: nemo_window_slot_get_window
comment: I disconnected thunderbolt4 docking station to which among
other things external monitor is connected.
Truncated backtrace:
Thread no. 1 (7 frames)
#6 nemo_window_slot_get_window at ../src/nemo-window-slot.c:527
#8 got_file_info_for_view_selection_callback at
../src/nemo-window-manage-views.c:819
#9 desktop_callback_check_done at
../libnemo-private/nemo-desktop-directory-file.c:241
#10 call_ready_callbacks_at_idle at
../libnemo-private/nemo-directory-async.c:1846
#14 g_main_context_iterate.isra.0 at ../glib/gmain.c:4276
#15 g_main_context_iteration at ../glib/gmain.c:4343
#16 g_application_run at ../gio/gapplication.c:2573
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2216921
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2216843
Bug ID: 2216843
Summary: Cinnamon launches applications with a black background
making black letters unreadable
Product: Fedora
Version: 38
Hardware: x86_64
OS: Linux
Status: NEW
Component: cinnamon
Severity: medium
Assignee: leigh123linux(a)googlemail.com
Reporter: cvanewijk(a)xs4all.nl
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
leigh123linux(a)googlemail.com, miketwebster(a)gmail.com,
riehecky(a)fnal.gov
Target Milestone: ---
Classification: Fedora
Created attachment 1972146
--> https://bugzilla.redhat.com/attachment.cgi?id=1972146&action=edit
gedit with black background after launching with cinnamon
Description of problem:
Cinnamon launches applications with a black background which makes letters
unreadable.
When i login in again with Gnome then Gnome launches the applications with the
correct white background.
Version-Release number of selected component (if applicable):
[cewijk@localhost ~]$ sudo dnf install cinnamon
[sudo] password for cewijk:
Fedora 38 - x86_64 - Updates 83 kB/s | 17 kB 00:00
Fedora 38 - x86_64 - Updates 69 kB/s | 2.1 MB 00:31
Fedora Modular 38 - x86_64 - Updates 113 kB/s | 14 kB 00:00
Fedora Modular 38 - x86_64 - Updates 49 kB/s | 77 kB 00:01
Last metadata expiration check: 0:00:01 ago on Thu 22 Jun 2023 09:06:09 PM
CEST.
Package cinnamon-5.6.8-2.fc38.x86_64 is already installed.
Dependencies resolved.
Nothing to do.
Complete!
[cewijk@localhost ~]$ uname -a
Linux localhost.localdomain 6.3.8-200.fc38.x86_64 #1 SMP PREEMPT_DYNAMIC Thu
Jun 15 02:15:40 UTC 2023 x86_64 GNU/Linux
How reproducible:
Steps to Reproduce:
1.
2.
3.
Actual results:
Expected results:
Additional info:
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2216843
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2216452
Bug ID: 2216452
Summary: [abrt] gnome-calendar: gcal_event_widget_clone():
gnome-calendar killed by SIGSEGV
Product: Fedora
Version: 38
Hardware: x86_64
Status: NEW
Whiteboard: abrt_hash:269578cfefb56f8073d9ab3fee3f444a49d16cb8;VAR
IANT_ID=workstation;
Component: gnome-calendar
Assignee: gnome-sig(a)lists.fedoraproject.org
Reporter: q.cooremans(a)gmail.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
gnome-sig(a)lists.fedoraproject.org,
igor.raits(a)gmail.com, klember(a)redhat.com
Target Milestone: ---
Classification: Fedora
Description of problem:
ouverture du calendrier, clic sur le mois suivant dans le panneau en haut à
gauche
= crash (à 3 reprises puis ok la 4e en attendant une bonne minute après
l'ouverture de l'application avant de changer de mois)
Version-Release number of selected component:
gnome-calendar-44.1-1.fc38
Additional info:
reporter: libreport-2.17.10
type: CCpp
reason: gnome-calendar killed by SIGSEGV
journald_cursor:
s=e30469c8cf9d4d988b69d073a031733a;i=190f36;b=806f908085b649059c4b6aa3f0d14768;m=3cdbcde64;t=5fea20443346c;x=f05cfe5363e4c743
executable: /usr/bin/gnome-calendar
cmdline: /usr/bin/gnome-calendar --gapplication-service
cgroup:
0::/user.slice/user-1000.slice/user@1000.service/app.slice/dbus-:1.2-org.gnome.Calendar@1.service
rootdir: /
uid: 1000
kernel: 6.3.8-200.fc38.x86_64
package: gnome-calendar-44.1-1.fc38
runlevel: N 5
backtrace_rating: 4
crash_function: gcal_event_widget_clone
Truncated backtrace:
Thread no. 1 (10 frames)
#0 gcal_event_widget_clone at ../src/gui/gcal-event-widget.c:1002
#1 split_event_widget_at_column at ../src/gui/views/gcal-week-header.c:650
#2 apply_overflow_at_weekday at ../src/gui/views/gcal-week-header.c:766
#4 add_event_to_grid at ../src/gui/views/gcal-week-header.c:877
#5 gcal_week_header_add_event at ../src/gui/views/gcal-week-header.c:1639
#6 add_event_to_subscriber at ../src/core/gcal-timeline.c:205
#7 timeline_source_dispatch at ../src/core/gcal-timeline.c:682
#10 g_main_context_iterate.isra.0 at ../glib/gmain.c:4276
#11 g_main_context_iteration at ../glib/gmain.c:4343
#12 g_application_run at ../gio/gapplication.c:2573
Potential duplicate: bug 1476568
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2216452
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2215794
Bug ID: 2215794
Summary: [abrt] nemo: type_set_qdata_W(): nemo-desktop killed
by SIGSEGV
Product: Fedora
Version: 38
Hardware: x86_64
Status: NEW
Whiteboard: abrt_hash:892c41c4278ce7e3b123934012fe4e6f2b2225f8;VAR
IANT_ID=cinnamon;
Component: nemo
Assignee: leigh123linux(a)googlemail.com
Reporter: bryce.a.carson(a)gmail.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
leigh123linux(a)googlemail.com, riehecky(a)fnal.gov
Target Milestone: ---
Classification: Fedora
Description of problem:
I had two applications open: Firefox and Emacs.
I was browsing a website when I navigated to Non-GNU ELPA. As I scrolled the
page my graphical display was corrupted for a short period, then returned to
normal before I was notified of the crash in Nemo.
Version-Release number of selected component:
nemo-5.6.4-1.fc38
Additional info:
reporter: libreport-2.17.10
type: CCpp
reason: nemo-desktop killed by SIGSEGV
journald_cursor:
s=009484f7648a46cf892793af0e74a666;i=50ce;b=f307d6abd52a44958cf37ae911553c74;m=4974f0a37;t=5fe6c5d465435;x=a54a7929cea8db2b
executable: /usr/bin/nemo-desktop
cmdline: nemo-desktop
cgroup: 0::/user.slice/user-1000.slice/session-2.scope
rootdir: /
uid: 1000
kernel: 6.2.9-300.fc38.x86_64
package: nemo-5.6.4-1.fc38
runlevel: N 5
backtrace_rating: 4
crash_function: type_set_qdata_W
Truncated backtrace:
Thread no. 1 (8 frames)
#0 type_set_qdata_W at ../gobject/gtype.c:3857
#1 g_type_set_qdata at ../gobject/gtype.c:3886
#2 desktop_location_changed_callback at ../src/nemo-pathbar.c:223
#4 accumulate at ../gobject/gsignal.c:3299
#5 signal_emit_unlocked_R.isra.0 at ../gobject/gsignal.c:3888
#6 g_source_set_closure at ../gobject/gsourceclosure.c:250
#7 ??
#8 ??
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2215794
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…