4 ms·
In upstream-unsupported versions, which are bore than 2 years old? Sure it is responsibility of the distro. Even if it is unpatched upstream, it's perfectly fi
by throw_a_grenade 1y ago
In upstream-unsupported versions, which are bore than 2 years old? Sure it is responsibility of the distro.
Even if it is unpatched upstream, it's perfectly fine to push the fix to master branch only and let distros backport. That's also why the bugs should be filed downstream, and distro maintainers will forward the bug upstream but only if not already fixed (so upstream won't get N duplicate bugs, where N is the number of packages).
At in any case, distro maintainers tend to behave better in upstream bugtrackers.
- veeti 1y agoI don't see how any of that is relevant. Instead of addressing the fact that GNOME/evolution security issue number #2727 (https://gitlab.gnome.org/GNOME/evolution/-/issues/2727 https://gitlab.gnome.org/GNOME/evolution/-/issues/2727) about remote content leakage remains open and valid to this very moment, you are grasping onto straws about the author initially reporting the bug from an old version. However, the issue has been reproduced on newer versions, and no patch is available to fix it. It all really boils down to one thing: the Evolution mail client makes a promise of protecting your privacy, and then fails to uphold that promise. Whether the fault lies in the WebKit project, somewhere in the GTK bindings or the Evolution client's source code is utterly irrelevant. Instead of throwing their hands in the air and hoping that WebKit maybe fixes the issue one day someone needs to take responsibility and mitigate the issue. Of course these are probably unpaid volunteers just hacking on open source so I don't want to dunk on anyone in particular. But as a whole the GNOME project positions itself as a competitor to proprietary software, and this sort of myopic security attitude to the end product does not inspire confidence in their offering. It should not come as any surprise that people giving you full access to their inbox will warn others about the known insecurity of your product. I think I'll stick to Thunderbird, where security reports aren't met with such indifferent handwaving. But you can keep engaging in academic thought exercises whether the bug should have been reported by the blessed Debian maintainer or something.