Bug 1660223 Comment 49 Edit History

Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.

(In reply to Daniel Holbert [:dholbert] from comment #42)
> I've just reported this to the Gnome folks at https://security.gnome.org (just a web form; if a ticket results from it, I'll post a link to the ticket here).

The Gnome sec bug is https://gitlab.gnome.org/GNOME/gtk/-/issues/6265 . It's essentially a dupe of their public bug 4672 but they're keeping them separate for now since 4672 is already public.

I'm also adding a whiteboard note here to remind ourselves to keep this bug hidden until those bugs are fixed/openable (particularly when 6265 can be made public.)  Don't want to zero-day the gnome folks with the details discussed here.
(In reply to Daniel Holbert [:dholbert] from comment #42)
> I've just reported this to the Gnome folks at https://security.gnome.org (just a web form; if a ticket results from it, I'll post a link to the ticket here).

The Gnome sec bug is https://gitlab.gnome.org/GNOME/gtk/-/issues/6265 (which shows up as 404 since it's hidden). It's essentially a dupe of their public bug 4672 but they're keeping them separate for now since 4672 is already public.

I'm also adding a whiteboard note here to remind ourselves to keep this bug hidden until those bugs are fixed/openable (particularly when 6265 can be made public.)  Don't want to zero-day the gnome folks with the details discussed here.
(In reply to Daniel Holbert [:dholbert] from comment #42)
> I've just reported this to the Gnome folks at https://security.gnome.org (just a web form; if a ticket results from it, I'll post a link to the ticket here).

My report spawned a Gnome security-bug at https://gitlab.gnome.org/GNOME/gtk/-/issues/6265 (which shows up as 404 since it's hidden to the public). It's essentially a dupe of their public bug 4672 but they're keeping them separate for now since 4672 is already public.

I'm also adding a whiteboard note here to remind ourselves to keep this bug hidden until those bugs are fixed/openable (particularly when 6265 can be made public.)  Don't want to zero-day the gnome folks with the details discussed here.
(In reply to Daniel Holbert [:dholbert] from comment #42)
> I've just reported this to the Gnome folks at https://security.gnome.org (just a web form; if a ticket results from it, I'll post a link to the ticket here).

My report spawned a Gnome security-bug at https://gitlab.gnome.org/GNOME/gtk/-/issues/6265 (which shows up as 404 since it's hidden to the public). It's essentially a dupe of their [public bug](https://gitlab.gnome.org/GNOME/gtk/-/issues/4672), but they're keeping them separate for now since 4672 is already public.

I'm also adding a whiteboard note here to remind ourselves to keep this bug hidden until those bugs are fixed/openable (particularly when 6265 can be made public.)  Don't want to zero-day the gnome folks with the details discussed here.

Back to Bug 1660223 Comment 49