CVE-2024-32462 - Need to update to the last secure patch

Bug #2062956 reported by Ange des Ténèbres
270
This bug affects 4 people
Affects Status Importance Assigned to Milestone
flatpak (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

Hello,

There is a security issue in flatpack package, see: https://www.cve.org/CVERecord?id=CVE-2024-32462
To fix that, according to Ubuntu version we have to update the package to one of these versions: 1.10.9, 1.12.9, 1.14.6, and 1.15.8,

Here is the current statut:

Noble = OK
Mantic = update required
Jammy = update required
Focal = update required

Could you please check that and provide the patched version?

Thanks in advance.

CVE References

description: updated
information type: Public → Public Security
information type: Public Security → Private Security
information type: Private Security → Public Security
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in flatpak (Ubuntu):
status: New → Confirmed
Revision history for this message
John Kizer (johnandmegh) wrote :

FWIW, looks like a Debian patch must already exist for this:

https://security-tracker.debian.org/tracker/CVE-2024-32462

Revision history for this message
Simon McVittie (smcv) wrote (last edit ):

This is the same vulnerability as LP: #2062406.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.