GNU bug report logs - #73059
Flatpak is vulnerable to CVE-2024-42472

Previous Next

Package: guix;

Reported by: DonaldSanders1968 <DonaldSanders1968 <at> protonmail.ch>

Date: Thu, 5 Sep 2024 20:13:02 UTC

Severity: normal

Done: Zheng Junjie <zhengjunjie <at> iscas.ac.cn>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: help-debbugs <at> gnu.org (GNU bug Tracking System)
To: DonaldSanders1968 <DonaldSanders1968 <at> protonmail.ch>
Subject: bug#73059: closed (Re: bug#73059: Flatpak is vulnerable to
 CVE-2024-42472)
Date: Fri, 06 Sep 2024 14:49:02 +0000
[Message part 1 (text/plain, inline)]
Your bug report

#73059: Flatpak is vulnerable to CVE-2024-42472

which was filed against the guix package, has been closed.

The explanation is attached below, along with your original report.
If you require more details, please reply to 73059 <at> debbugs.gnu.org.

-- 
73059: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=73059
GNU Bug Tracking System
Contact help-debbugs <at> gnu.org with problems
[Message part 2 (message/rfc822, inline)]
From: Zheng Junjie <zhengjunjie <at> iscas.ac.cn>
To: DonaldSanders1968 via Bug reports for GNU Guix <bug-guix <at> gnu.org>
Cc: 73059-done <at> debbugs.gnu.org,
 DonaldSanders1968 <DonaldSanders1968 <at> protonmail.ch>
Subject: Re: bug#73059: Flatpak is vulnerable to CVE-2024-42472
Date: Fri, 06 Sep 2024 22:48:38 +0800
[Message part 3 (text/plain, inline)]
DonaldSanders1968 via Bug reports for GNU Guix <bug-guix <at> gnu.org> writes:

> Hi Guix,
>
> Current flatpak version in Guix channel is affected by CVE-2024-42472. 
>
> Kind regards,
>
> Donald

Thanks, update bubblewrap and it.
[signature.asc (application/pgp-signature, inline)]
[Message part 5 (message/rfc822, inline)]
From: DonaldSanders1968 <DonaldSanders1968 <at> protonmail.ch>
To: "bug-guix <at> gnu.org" <bug-guix <at> gnu.org>
Subject: Flatpak is vulnerable to CVE-2024-42472
Date: Thu, 05 Sep 2024 17:36:12 +0000
[Message part 6 (text/plain, inline)]
Hi Guix,

Current flatpak version in Guix channel is affected by [CVE-2024-42472](https://github.com/flatpak/flatpak/security/advisories/GHSA-7hgv-f2j8-xw87).

Kind regards,
Donald
[Message part 7 (text/html, inline)]

This bug report was last modified 318 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.