gvfs 1.41.91-1ubuntu1 source package in Ubuntu

Changelog

gvfs (1.41.91-1ubuntu1) eoan; urgency=medium

  * Revert upstream changes to port to fuse 3. This is in universe in Ubuntu
    and we'll need to work out how to move over.

gvfs (1.41.91-1) experimental; urgency=medium

  [ Simon McVittie ]
  * Add bug number and CVE ID to previous changelog entry

  [ Iain Lane ]
  * debian/watch: Find unstable versions
  * New upstream release
    + admin: Add query_info_on_read/write functionality (CVE-2019-12448)
    + admin: Allow changing file owner (CVE-2019-12447)
    + admin: Ensure correct ownership when moving to file:// uri
      (CVE-2019-12449)
    + admin: Prevent core dumps when daemon is manually started
    + admin: Use fsuid to ensure correct file ownership (CVE-2019-12447)
    + afc: Remove assumptions about length of device UUID to support new
      devices
    + afp: Fix afp backend crash when no username supplied
    + build: Add dependency on gsettings-desktop-schemas
    + build: Bump required meson version to 0.50.0
    + build: Define gvfs_rpath for libgvfsdaemon.so
    + build: Several meson improvements
    + daemon: Check that the connecting client is the same user
      (CVE-2019-12795)
    + daemon: Only accept EXTERNAL authentication (CVE-2019-12795)
    + daemon/udisks2: Handle lockdown option to disable writing
    + daemon: Unify some translatable strings
    + fuse: Adapt gvfsd-fuse to use fuse 3.x
    + fuse: Define RENAME_* macros when they are not defined
    + fuse: Remove max_write limit
    + gmountsource: Fix deadlocks in synchronous API
    + google: Check ownership in is_owner() without additional HTTP request
    + google: Disable deletion of non-empty directories
    + google: Do not enumerate volatile entries if title matches id
    + google: Fix crashes when deleting if the file isn't found
    + google: Fix issue with stale entries remaining after rename operation
    + google: Support deleting shared Google Drive files
    + proxy: Don't leak a GVfsDBusDaemon
    + udisks2: Change display name for crypto_unknown devices
  * debian/patches: Drop backported patches. We're further ahead now.

gvfs (1.40.1-3) experimental; urgency=medium

  * Team upload
  * d/p/gvfsdaemon-Check-that-the-connecting-client-is-the-same-u.patch:
    Add missing authentication, preventing a local attacker from connecting
    to an abstract socket address learned from netstat(8) and issuing
    arbitrary D-Bus method calls
    (Closes: #930376, CVE-2019-12795)
  * d/p/gvfsdaemon-Only-accept-EXTERNAL-authentication.patch:
    Harden private D-Bus connection by rejecting the more complicated
    DBUS_COOKIE_SHA1 authentication mechanism and only accepting EXTERNAL

gvfs (1.40.1-2) experimental; urgency=medium

  * Team upload
  * Update from upstream gnome-3-32 branch, commit 1.40.1-9-gec939a01,
    to fix the admin backend
    (Closes: #929755)
    - Implement query_info_on_read/write to fix some race conditions
      (CVE-2019-12448)
    - Ensure that created files get the correct ownership (CVE-2019-12247)
    - Ensure that copied files get the correct ownership (CVE-2019-12449)
    - Fix deadlocks in synchronous API
    - Various fixes for afc backend
    - Update translation: zh_CN
  * Remove obsolete version number from fuse dependency.
    gvfs needs fuse (>= 2.8.4), but that version is older than oldstable,
    so we can safely simplify to "Depends: fuse".
    The versioned dependency is not satisfied by fuse3's unversioned
    "Provides: fuse", but the unversioned dependency is. (Closes: #927221)

 -- Iain Lane <email address hidden>  Wed, 21 Aug 2019 12:33:35 +0100

Upload details

Uploaded by:
Iain Lane
Uploaded to:
Eoan
Original maintainer:
Debian GNOME Maintainers
Architectures:
any all
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
gvfs_1.41.91.orig.tar.xz 1.2 MiB a0e255640715f11f782e59a36a208962bbc84406cf3cfdea52e0651c0e26447f
gvfs_1.41.91-1ubuntu1.debian.tar.xz 25.7 KiB a09dfd983d989ff473270936ad65b47d60e59e72d0841d009574944f9f1c1dfc
gvfs_1.41.91-1ubuntu1.dsc 3.5 KiB 0ce72b6a83fbad1fa3167b6dd0072e3dc634c667d314cb7bbe3e77ef464a9572

Available diffs

View changes file

Binary packages built by this source

gvfs: No summary available for gvfs in ubuntu eoan.

No description available for gvfs in ubuntu eoan.

gvfs-backends: No summary available for gvfs-backends in ubuntu eoan.

No description available for gvfs-backends in ubuntu eoan.

gvfs-backends-dbgsym: No summary available for gvfs-backends-dbgsym in ubuntu eoan.

No description available for gvfs-backends-dbgsym in ubuntu eoan.

gvfs-bin: No summary available for gvfs-bin in ubuntu eoan.

No description available for gvfs-bin in ubuntu eoan.

gvfs-common: No summary available for gvfs-common in ubuntu eoan.

No description available for gvfs-common in ubuntu eoan.

gvfs-daemons: No summary available for gvfs-daemons in ubuntu eoan.

No description available for gvfs-daemons in ubuntu eoan.

gvfs-daemons-dbgsym: No summary available for gvfs-daemons-dbgsym in ubuntu eoan.

No description available for gvfs-daemons-dbgsym in ubuntu eoan.

gvfs-dbgsym: No summary available for gvfs-dbgsym in ubuntu eoan.

No description available for gvfs-dbgsym in ubuntu eoan.

gvfs-fuse: No summary available for gvfs-fuse in ubuntu eoan.

No description available for gvfs-fuse in ubuntu eoan.

gvfs-fuse-dbgsym: No summary available for gvfs-fuse-dbgsym in ubuntu eoan.

No description available for gvfs-fuse-dbgsym in ubuntu eoan.

gvfs-libs: No summary available for gvfs-libs in ubuntu eoan.

No description available for gvfs-libs in ubuntu eoan.

gvfs-libs-dbgsym: No summary available for gvfs-libs-dbgsym in ubuntu eoan.

No description available for gvfs-libs-dbgsym in ubuntu eoan.