UbuntuUpdates.org

Package "ibus"

Name: ibus

Description:

Intelligent Input Bus - core

Latest version: 1.5.11-1ubuntu2.4
Release: xenial (16.04)
Level: security
Repository: main
Homepage: https://github.com/ibus/ibus/releases

Links


Download "ibus"


Other versions of "ibus" in Xenial

Repository Area Version
base main 1.5.11-1ubuntu2
updates main 1.5.11-1ubuntu2.4

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.5.11-1ubuntu2.4 2020-03-24 12:07:00 UTC

  ibus (1.5.11-1ubuntu2.4) xenial-security; urgency=medium

  * SECURITY UPDATE: Lack of access control on DBus socket allows other
    local users to make arbitrary method calls
    - debian/patches/CVE-2019-14822.patch:
      Re-enable to implement GDBusAuthObserver callback in bus/server.c to
      add access control to the DBus server socket
    - CVE-2019-14822
  * Add breaks for older libglib2.0-0 releases which do not contain the
    GDBusServer fix for Qt applications

 -- Alex Murray <email address hidden> Mon, 04 Nov 2019 11:30:01 +1030

Source diff to previous version
CVE-2019-14822 missing authorization flaw

Version: 1.5.11-1ubuntu2.3 2019-09-23 15:06:54 UTC

  ibus (1.5.11-1ubuntu2.3) xenial-security; urgency=medium

  * SECURITY UPDATE: ibus regression in Qt applications (LP: #1844853)
    - debian/patches/CVE-2019-14822.patch: disabled pending further
      investigation.

 -- Marc Deslauriers <email address hidden> Mon, 23 Sep 2019 13:31:22 +0200

Source diff to previous version
1844853 IBus no longer works in Qt applications after upgrade
CVE-2019-14822 missing authorization flaw

Version: 1.5.11-1ubuntu2.2 2019-09-16 13:06:51 UTC

  ibus (1.5.11-1ubuntu2.2) xenial-security; urgency=medium

  * SECURITY UPDATE: Lack of access control on DBus socket allows other
    local users to make arbitrary method calls
    - debian/patches/CVE-2019-14822.patch: Implement GDBusAuthObserver
      callback in bus/server.c to add access control to the DBus server
      socket
    - CVE-2019-14822

 -- Alex Murray <email address hidden> Wed, 11 Sep 2019 12:32:56 +0930

CVE-2019-14822 missing authorization flaw



About   -   Send Feedback to @ubuntu_updates