Update xdg-desktop-portal to 1.18.4

Bug #2062394 reported by Jeremy Bícha
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
xdg-desktop-portal (Ubuntu)
Fix Committed
High
Unassigned
Noble
In Progress
High
Unassigned

Bug Description

Impact
------
This is a new release in the stable 1.18.x series. It includes part of a CVE security fix; the more important part of the CVE is in flatpak but there is some hardening on the xdg-desktop-portal side.

https://github.com/flatpak/xdg-desktop-portal/releases/tag/1.18.4

https://github.com/flatpak/xdg-desktop-portal/compare/1.18.3...1.18.4

Test Plan
---------
Run the tests from https://wiki.ubuntu.com/DesktopTeam/TestPlans/XdgDesktopPortalGnome

What Could Go Wrong
------------------
xdg-desktop-portal is critical functionality for Snaps and Flatpaks including providing the file chooser dialogs for both of the only security supported web browsers in Ubuntu: firefox and chromium (both as snaps)

xdg-desktop-portal is included in every official Ubuntu desktop flavor as it has become essential functionality for modern desktops. When used by desktops, there is a separate backend package to provide the UI. For Ubuntu Desktop, this is xdg-desktop-portal-gnome. Several other desktops use xdg-desktop-portal-gtk (even Ubuntu Desktop uses it as a dependency of -gnome) but there are other backends that follow the standard naming convention xdg-desktop-portal-*

xdg-desktop-portal also is used in some apps that are distributed as .deb packages, for instance it is used for the Set as Background feature in the Nautilus file browser.

Other Info
----------
(none)

CVE References

Jeremy Bícha (jbicha)
description: updated
information type: Public → Public Security
Changed in xdg-desktop-portal (Ubuntu):
status: Triaged → In Progress
Jeremy Bícha (jbicha)
Changed in xdg-desktop-portal (Ubuntu):
status: In Progress → Fix Committed
status: Fix Committed → In Progress
Revision history for this message
Steve Langasek (vorlon) wrote : Proposed package upload rejected

An upload of xdg-desktop-portal to noble-proposed has been rejected from the upload queue for the following reason: "merge changelog includes references to long-fixed bugs, needs cleanup".

Jeremy Bícha (jbicha)
description: updated
description: updated
Changed in xdg-desktop-portal (Ubuntu Noble):
importance: Undecided → High
status: New → In Progress
Changed in xdg-desktop-portal (Ubuntu):
status: In Progress → Fix Committed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.