Comment 18 for bug 1897287

Revision history for this message
Emilia Torino (emitorino) wrote : Re: [Bug 1897287] Re: Local privilege escalation in blueman

On 23/10/20 16:29, cschramm wrote:
> 23.10.20 20:39 Emilia Torino:
> > On 23/10/20 10:38, cschramm wrote:
> >> It seems like there actually are Ubuntu updates waiting to get released.
> >
> > That's correct
>
> > Tuesday 27th sounds perfect for the Ubuntu security team. Can you please
> > also define a time (UTC) so we make sure we release the updates
> > appropriately?
>
> I'll pick... 09:00 UTC. 🤷
If possible, can we make it 12:00 UTC? It better accommodates with our
time zones.

>
> I'm going to publish upstream
> - a GitHub security advisory
> - version 2.1.4 with the fix and a reference to the security advisory
> - the same fix in master
> around that time or a little later.
>
> (Most) other distributions than Debian and Ubuntu (and derivatives) are
> not at risk as they use Policykit authorization and rules that allow the
> actions only to users that have the desired privileges anyway.
>
> Cheers
>

Thanks!