Update evince to 3.28.4

Bug #1790609 reported by Jeremy Bícha
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
evince (Ubuntu)
Fix Released
Medium
Unassigned
Bionic
Fix Released
Medium
Didier Roche-Tolomelli

Bug Description

[Impact]
New release in the stable 3.28 series.

https://gitlab.gnome.org/GNOME/evince/commits/gnome-3-28
https://gitlab.gnome.org/GNOME/evince/blob/gnome-3-28/NEWS

[Test Case]
1. Install new evince version
2. try opening multiple pdf and ps files, ensure no obvious regression is visible.

[Regression Potential]
The visible regression potential is the enable-ps (see comment below), otherwise, the new evince upstream release has been released a while ago with no post-release fixes: https://gitlab.gnome.org/GNOME/evince/commits/gnome-3-28

[Other Info]
Please add --enable-ps to the build options since this version disables viewing Postscript files as a workaround for security issues in Ghostscript. We should fix Ghostscript instead.

See https://gitlab.gnome.org/GNOME/evince/issues/967

Jeremy Bícha (jbicha)
Changed in evince (Ubuntu Bionic):
status: New → Triaged
importance: Undecided → Medium
Changed in evince (Ubuntu):
importance: Undecided → Medium
description: updated
Changed in evince (Ubuntu Bionic):
assignee: nobody → Didier Roche (didrocks)
Revision history for this message
Jeremy Bícha (jbicha) wrote :

3.28.4 was released today.

summary: - Update evince to 3.28.3
+ Update evince to 3.28.4
description: updated
Revision history for this message
Brian Murray (brian-murray) wrote :

I'm a bit confused here. As I understand it this upload uses the build option --enable-ps something that was disabled by upstream due to an unknown (the ghostscript bug is still private) security issue with postscript files. Is this security issue really fixed in Ubuntu 18.04? If so please provide some evidence. Thanks!

Changed in evince (Ubuntu Bionic):
status: Triaged → Incomplete
Changed in evince (Ubuntu Bionic):
status: Incomplete → New
Revision history for this message
Sebastien Bacher (seb128) wrote :

@Brian, you have some details on https://gitlab.gnome.org/GNOME/evince/issues/967

the interesting bit is "The fix will be in 9.24" (speaking of ghoscript), that version is in cosmic
https://launchpad.net/ubuntu/+source/ghostscript/9.24~dfsg+1-0ubuntu1

Note, that --enable-ps is the default in cosmic, upstream changed the default in the update to be on the safe side in case users don't have the fix ghostcript, do using the --enable-ps is not a change over what we have in cosmic already.

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

We did update ghostscript, but I suspect there will be many more issues discovered in the future.

Ideally, we'd keep postscript disabled, but I do understand postscript documents are still being used by our users and disabling postscript support would be viewed as a regression. As such, I think we can re-enable it for now but keep the option to turn it off if it becomes problematic again in the future.

Revision history for this message
Sebastien Bacher (seb128) wrote :

> Ideally, we'd keep postscript disabled

Just to be clear, it's currently enabled in cosmic (and all Ubuntu series), so if we speak about Ubuntu it would be rather "ideally we would disable postcript"

Revision history for this message
Brian Murray (brian-murray) wrote : Please test proposed package

Hello Jeremy, or anyone else affected,

Accepted evince into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/evince/3.28.4-0ubuntu1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-bionic to verification-done-bionic. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-bionic. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance for helping!

N.B. The updated package will be released to -updates after the bug(s) fixed by this package have been verified and the package has been in -proposed for a minimum of 7 days.

Changed in evince (Ubuntu Bionic):
status: New → Fix Committed
tags: added: verification-needed verification-needed-bionic
Revision history for this message
Jean-Baptiste Lallement (jibel) wrote :

I verified evince 3.28.4-0ubuntu1 from bionic-proposed with a broad range of PDF and PS documents, some very simple, some complex with thousands of pages and a variety of fonts and graphics and didn't find any issue.

Marking as verification-done.

tags: added: verification-done verification-done-bionic
removed: verification-needed verification-needed-bionic
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package evince - 3.28.4-0ubuntu1

---------------
evince (3.28.4-0ubuntu1) bionic; urgency=medium

  * New upstream release (LP: #1790609)
  * debian/rules:
    - add --enable-ps to keep ghostscript file visionning disabled upstream,
      (as in current bionic and cosmic)

 -- Didier Roche <email address hidden> Mon, 15 Oct 2018 11:42:54 +0200

Changed in evince (Ubuntu Bionic):
status: Fix Committed → Fix Released
Revision history for this message
Brian Murray (brian-murray) wrote : Update Released

The verification of the Stable Release Update for evince has completed successfully and the package has now been released to -updates. Subsequently, the Ubuntu Stable Release Updates Team is being unsubscribed and will not receive messages about this bug report. In the event that you encounter a regression using the package from -updates please report a new bug using ubuntu-bug and tag the bug report regression-update so we can easily find any regressions.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.