freerdp2: Update to 2.8.1

Related Vulnerabilities: CVE-2022-39282   CVE-2022-39283  

Debian Bug report logs - #1021659
freerdp2: Update to 2.8.1

version graph

Reported by: Jeremy Bicha <jeremy.bicha@canonical.com>

Date: Wed, 12 Oct 2022 13:45:02 UTC

Severity: normal

Tags: patch

Found in version freerdp2/2.8.0+dfsg1-1

Fixed in version freerdp2/2.8.1+dfsg1-1

Done: Mike Gabriel <sunweaver@debian.org>

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian Remote Maintainers <debian-remote@lists.debian.org>:
Bug#1021659; Package src:freerdp2. (Wed, 12 Oct 2022 13:45:04 GMT) (full text, mbox, link).


Acknowledgement sent to Jeremy Bicha <jeremy.bicha@canonical.com>:
New Bug report received and forwarded. Copy sent to Debian Remote Maintainers <debian-remote@lists.debian.org>. (Wed, 12 Oct 2022 13:45:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Jeremy Bicha <jeremy.bicha@canonical.com>
To: submit@bugs.debian.org
Subject: freerdp2: Update to 2.8.1
Date: Wed, 12 Oct 2022 09:40:55 -0400
Source: freerdp2
Version: 2.8.0+dfsg1-1

Please update freerdp2 to the new version. Because I needed to work on
the update today for Ubuntu 22.10 deadlines, I am submitting merge
proposals for you.

https://github.com/FreeRDP/FreeRDP/releases/tag/2.8.1
https://github.com/FreeRDP/FreeRDP/compare/2.8.0...2.8.1

The changes say that it fixes 2 CVEs, CVE-2022-39282 and CVE-2022-39283

Thank you,
Jeremy Bicha



Added tag(s) patch. Request was from Jeremy Bicha <jeremy.bicha@canonical.com> to control@bugs.debian.org. (Wed, 12 Oct 2022 13:57:03 GMT) (full text, mbox, link).


Reply sent to Mike Gabriel <sunweaver@debian.org>:
You have taken responsibility. (Wed, 12 Oct 2022 22:12:03 GMT) (full text, mbox, link).


Notification sent to Jeremy Bicha <jeremy.bicha@canonical.com>:
Bug acknowledged by developer. (Wed, 12 Oct 2022 22:12:03 GMT) (full text, mbox, link).


Message #12 received at 1021659-close@bugs.debian.org (full text, mbox, reply):

From: Debian FTP Masters <ftpmaster@ftp-master.debian.org>
To: 1021659-close@bugs.debian.org
Subject: Bug#1021659: fixed in freerdp2 2.8.1+dfsg1-1
Date: Wed, 12 Oct 2022 22:08:33 +0000
Source: freerdp2
Source-Version: 2.8.1+dfsg1-1
Done: Mike Gabriel <sunweaver@debian.org>

We believe that the bug you reported is fixed in the latest version of
freerdp2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1021659@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Mike Gabriel <sunweaver@debian.org> (supplier of updated freerdp2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 12 Oct 2022 23:26:31 +0200
Source: freerdp2
Architecture: source
Version: 2.8.1+dfsg1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Remote Maintainers <debian-remote@lists.debian.org>
Changed-By: Mike Gabriel <sunweaver@debian.org>
Closes: 1021659
Changes:
 freerdp2 (2.8.1+dfsg1-1) unstable; urgency=medium
 .
   * New upstream release. (Closes: #1021659).
     - Fixes CVE-2022-39282, CVE-2022-39283.
   * debian/patches:
     + Drop 1001_amend-DumpThreadHandles-inclusion.patch. Resolved upstream.
Checksums-Sha1:
 7591f9a1d151d45b8dbb5d3c4623b2e2503abc92 3498 freerdp2_2.8.1+dfsg1-1.dsc
 a3e2f8036eab044acee2ab9d7017928d99131f91 2257248 freerdp2_2.8.1+dfsg1.orig.tar.xz
 1927d11cfa9cfe56e6fe3e5f0d9f86a7682ebae7 42932 freerdp2_2.8.1+dfsg1-1.debian.tar.xz
 ea89c4bf527312c5776fef62913cccda1e6b64bc 14053 freerdp2_2.8.1+dfsg1-1_source.buildinfo
Checksums-Sha256:
 f31cb1ea9ac2e61fa51adf374727b5eed0c0c08031eac29406de429a8ce6f5c3 3498 freerdp2_2.8.1+dfsg1-1.dsc
 5e45b906c63c4b8ad81dfe83f60dce4e722728ea1aba4137eb0938c446b4b8a8 2257248 freerdp2_2.8.1+dfsg1.orig.tar.xz
 03b419cd7cd50ee0926308119b674533a5c17a49a0aafb163a479a07317f0631 42932 freerdp2_2.8.1+dfsg1-1.debian.tar.xz
 8e0fbb35c182707edab4a82ad5628e6b8d542e2b209f53c9b1ea5ac929fd56a1 14053 freerdp2_2.8.1+dfsg1-1_source.buildinfo
Files:
 cb908f156014530ee37568688b8b71f5 3498 x11 optional freerdp2_2.8.1+dfsg1-1.dsc
 c51488e63d4b6b261efd7d35cf9c1267 2257248 x11 optional freerdp2_2.8.1+dfsg1.orig.tar.xz
 fe8408333b8da92ed017b5864038d69c 42932 x11 optional freerdp2_2.8.1+dfsg1-1.debian.tar.xz
 b066e2e6775fcb24606bfa486201b13c 14053 x11 optional freerdp2_2.8.1+dfsg1-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJJBAEBCAAzFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAmNHMs0VHHN1bndlYXZl
ckBkZWJpYW4ub3JnAAoJEJr0azAldxsxNUoP/10GWEuPcVjrgjOqpP3yjY+1ZQOq
S1+t3oRgQ0iSvqWzf0d05TqaAT3goGWSbrKhZHLqt4aeR21YDsPlprQ61M3PZpnc
F8RHOWpUMK993KU2qMa2gRZkfDPQVzGcwSWK/nxeljVeom48MAGUT8Aj056du2RP
m98lAkP8482FUNLKVGdiEymhUh9hGlmhObTGn1fZ7GObUjh4IZycgMVIlw2BVlES
DM6mloBC1bc5SJ4eRHNahyx+TU35u6o70kOJzTyBkfHbyKLCM4Piy7eQrjQ7qrZT
3Bv4JwAxwCY91el6iDqtyIBY+ZfGiey9Zb6sZOtWANbLliHaK5fGXKT7fvEXUYwn
0FIpxTSm7LxzYQiXW2emxOfgCtQURDh86QFRqDddA6MthJIlxmIFv/R/W1YJZnxs
1SXi9iu/iya7tnD6px91pNbAJ+wFor1czqhTdIiujKefg44yiPO3VSyu5O/aj1IG
bptjsb65r7Ar0+36knERVdVFo9zBmN3OEyGfuk5piudCdRcqnSX4CadKmLQACLVM
I4g14DHHhgzbrk/9UuNSZu6gAp8ikYyd+zJKElGl3v1A8o1iC9w4nMeZrWHH4l7C
MNkfZbB+9dUp6KFJyscvJNLiyBXVD17hbWv4p1MVxGM0METTtiuMkHWgGgc9GAwY
vu+Osk6vob2jnZfi
=tx5i
-----END PGP SIGNATURE-----




Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Thu Oct 13 13:22:22 2022; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.