Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Bug#697751: pu: package gdm3/2.30.5-6squeeze5

1 view
Skip to first unread message

Josselin Mouette

unread,
Jan 9, 2013, 6:00:01 AM1/9/13
to
Package: release.debian.org
Severity: normal
User: release.d...@packages.debian.org
Usertags: pu

Hi,

as already discussed, I’d like to propose a stable upload for gdm3 in
order to avoid a security risk when doing upgrades.

Theoretically, with the greeter session of gdm 2.30 and the glib version
in wheezy, you could use default URI handlers, and launch things such as
a web browser. A bit of testing didn’t show any dialog from which this
could be triggered, but it’s better to be on the safe side.

Therefore this update would, when a newer glib is installed, disable all
URI handlers, as already done by gdm3 3.4 in wheezy.

Proposed diff attached.

Cheers,
--
.''`. Josselin Mouette
: :' :
`. `'
`-
gdm_squeeze.diff

Josselin Mouette

unread,
Jan 25, 2013, 8:00:03 AM1/25/13
to
Le mercredi 09 janvier 2013 à 11:53 +0100, Josselin Mouette a écrit :
> as already discussed, I’d like to propose a stable upload for gdm3 in
> order to avoid a security risk when doing upgrades.

Ping?

--
.''`. Josselin Mouette
: :' :
`. `'
`-


--
To UNSUBSCRIBE, email to debian-bugs-...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listm...@lists.debian.org

Josselin Mouette

unread,
Feb 14, 2013, 3:30:03 PM2/14/13
to

Adam D. Barratt

unread,
Feb 15, 2013, 7:20:01 AM2/15/13
to
Control: tags -1 + confirmed squeeze

On Wed, 2013-01-09 at 11:53 +0100, Josselin Mouette wrote:
> as already discussed, I’d like to propose a stable upload for gdm3 in
> order to avoid a security risk when doing upgrades.
>
> Theoretically, with the greeter session of gdm 2.30 and the glib version
> in wheezy, you could use default URI handlers, and launch things such as
> a web browser. A bit of testing didn’t show any dialog from which this
> could be triggered, but it’s better to be on the safe side.

Did anyone ever manage to find a practical way of triggering such
issues?

Please go ahead; thanks.

Regards,

Adam

Adam D. Barratt

unread,
May 11, 2013, 1:10:01 PM5/11/13
to
On Fri, 2013-02-15 at 12:07 +0000, Adam D. Barratt wrote:
> On Wed, 2013-01-09 at 11:53 +0100, Josselin Mouette wrote:
> > as already discussed, I’d like to propose a stable upload for gdm3 in
> > order to avoid a security risk when doing upgrades.
> >
> > Theoretically, with the greeter session of gdm 2.30 and the glib version
> > in wheezy, you could use default URI handlers, and launch things such as
> > a web browser. A bit of testing didn’t show any dialog from which this
> > could be triggered, but it’s better to be on the safe side.
>
> Did anyone ever manage to find a practical way of triggering such
> issues?
>
> Please go ahead; thanks.

Any news on that?

Josselin Mouette

unread,
May 24, 2013, 5:10:02 AM5/24/13
to
Le samedi 11 mai 2013 à 18:00 +0100, Adam D. Barratt a écrit :
> On Fri, 2013-02-15 at 12:07 +0000, Adam D. Barratt wrote:
> > On Wed, 2013-01-09 at 11:53 +0100, Josselin Mouette wrote:
> > > as already discussed, I’d like to propose a stable upload for gdm3 in
> > > order to avoid a security risk when doing upgrades.
> > >
> > > Theoretically, with the greeter session of gdm 2.30 and the glib version
> > > in wheezy, you could use default URI handlers, and launch things such as
> > > a web browser. A bit of testing didn’t show any dialog from which this
> > > could be triggered, but it’s better to be on the safe side.
> >
> > Did anyone ever manage to find a practical way of triggering such
> > issues?
> >
> > Please go ahead; thanks.
>
> Any news on that?

Sorry for the delay. I just uploaded it to oldstable.

Cheers,
--
.''`. Josselin Mouette
: :' :
`. `'
`-


Adam D. Barratt

unread,
May 25, 2013, 6:10:01 PM5/25/13
to
Control: tags -1 + pending

On Fri, 2013-05-24 at 11:06 +0200, Josselin Mouette wrote:
> Sorry for the delay. I just uploaded it to oldstable.

Thanks; flagged for acceptance.

Regards,

Adam
0 new messages