Opened 2 years ago

Closed 2 years ago

#20430 closed enhancement (fixed)

xdg-desktop-portal-0.18.4

Reported by: Xi Ruoyao Owned by: Douglas R. Reno
Priority: high Milestone: 12.3
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New patch version, release in Apr.

Change History (4)

comment:1 by Douglas R. Reno, 2 years ago

Owner: changed from blfs-book to Douglas R. Reno
Priority: normal → high
Status: new → assigned

There is an 8.4/10 CVE fixed in this release. It allows for a sandbox escape via the RequestBackground portal, and several proof of concept exploits exist out in the wild that use GNOME and KDE applications.

comment:2 by Bruce Dubbs, 2 years ago

Summary: xdg-desktop-portal-0.18.4 (currency) → xdg-desktop-portal-0.18.4

Currency has been updated.

comment:3 by Douglas R. Reno, 2 years ago

Release notes:

This is a new minor release of xdg-desktop-portal 1.18 series. Users and distributions 
are strongly encouraged to update to this version. These are the changes included in 
this release:

    Don't allow commandline arrays when the first commandline item starts with 
whitespace or hyphen. (CVE-2024-32462)
    Do not store device access permission if it returned an error.
    Fix crash with config files without a default backend set.

comment:4 by Douglas R. Reno, 2 years ago

Resolution: → fixed
Status: assigned → closed

SA-12.2-019 issued.

Fixed at 99b309f8b1efde54284348ee094c8d1b0d96ef2c

Note: See TracTickets for help on using tickets.