GNU bug report logs - #70539
Flatpak is vulnerable to CVE-2024-32462

Previous Next

Package: guix;

Reported by: DonaldSanders1968 <DonaldSanders1968 <at> protonmail.ch>

Date: Tue, 23 Apr 2024 17:47:06 UTC

Severity: normal

Done: Z572 <zhengjunjie <at> iscas.ac.cn>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: help-debbugs <at> gnu.org (GNU bug Tracking System)
To: DonaldSanders1968 <DonaldSanders1968 <at> protonmail.ch>
Subject: bug#70539: closed (bug#70539: Flatpak is vulnerable to
 CVE-2024-32462)
Date: Wed, 24 Apr 2024 02:47:10 +0000
[Message part 1 (text/plain, inline)]
Your bug report

#70539: Flatpak is vulnerable to CVE-2024-32462

which was filed against the guix package, has been closed.

The explanation is attached below, along with your original report.
If you require more details, please reply to 70539 <at> debbugs.gnu.org.

-- 
70539: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=70539
GNU Bug Tracking System
Contact help-debbugs <at> gnu.org with problems
[Message part 2 (message/rfc822, inline)]
From: Z572 <zhengjunjie <at> iscas.ac.cn>
To: DonaldSanders1968 <at> protonmail.ch
Cc: 70539-done <at> debbugs.gnu.org
Subject: bug#70539: Flatpak is vulnerable to CVE-2024-32462
Date: Wed, 24 Apr 2024 10:46:16 +0800
[Message part 3 (text/plain, inline)]
Thanks, fix in https://git.savannah.gnu.org/cgit/guix.git/commit/?id=d115af1bcc48f07a40dafd94d1d00926d446d068
[signature.asc (application/pgp-signature, inline)]
[Message part 5 (message/rfc822, inline)]
From: DonaldSanders1968 <DonaldSanders1968 <at> protonmail.ch>
To: "bug-guix <at> gnu.org" <bug-guix <at> gnu.org>
Subject: Flatpak is vulnerable to CVE-2024-32462
Date: Tue, 23 Apr 2024 16:59:22 +0000
[Message part 6 (text/plain, inline)]
Hi Guix,

Flatpak before versions 1.10.9, 1.12.9, 1.14.6, and 1.15.8 is vulnerable to [CVE-2024-32462](https://nvd.nist.gov/vuln/detail/CVE-2024-32462). Currently what we have is in version 1.14.4.

Kind regards,

Donald
[Message part 7 (text/html, inline)]

This bug report was last modified 1 year and 78 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.