/srv/irclogs.ubuntu.com/2022/11/16/#ubuntu-security.txt

amurrayfwiw I just retried all those failed thunderbird 102 builds as requested by ricotz earlier02:01
ItzSwirlzHey security team, Nemo may also have CVE-2022-3729015:02
-ubottu:#ubuntu-security- GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive. <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37290>15:02
ItzSwirlzlook at the merge request for the nautilus and nemo's code - https://github.com/linuxmint/nemo/blob/0686ec5f75c0456c140c79169607cf6b5ef44175/libnemo-private/nemo-file-operations.c#L82915:02
ItzSwirlz(Nemo is built off of nautilus)15:02
ItzSwirlzI believe it is. I'm sending an email right now to the nemo devs15:03
mdeslaurItzSwirlz: thanks, I'll add it to our tracker15:04
ItzSwirlzthanks, I'll also check caja and thunar. The code is scarily similar15:04
ItzSwirlzfound it in caja - https://github.com/mate-desktop/caja/blob/14dd4822ddbcafecd3bfb283920b6a60507134bd/libcaja-private/caja-file-operations.c#L83115:09
ItzSwirlznot in thunar15:13
JanCwhile Nemo & Caja are Nautilus forks, Thunar is not AFAIK (but it's always possible they reused some code, of course)22:22

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!