~trebelnik-stefina/cinnamon-test/+git/xreader:3.2-maintenance

Last commit made on 2023-12-18
Get this branch:
git clone -b 3.2-maintenance https://git.launchpad.net/~trebelnik-stefina/cinnamon-test/+git/xreader

Branch merges

Branch information

Name:
3.2-maintenance
Repository:
lp:~trebelnik-stefina/cinnamon-test/+git/xreader

Recent commits

87ee944... by Clement Lefebvre <email address hidden>

3.2.3

269c0b8... by Michael Webster

comics: Use unarr for rar support when using libarchive 3.4.

ref (revert):
https://gitlab.gnome.org/GNOME/evince/-/commit/e25912b3a2fa91d8d05d0a683303a8d0a39541b5

4d3a196... by Michael Webster

comics: Use libarchive to unpack documents [CVE-2023-44452].

This commit eliminates the use of external commands for opening
comic documents, and uses libarchive instead.

Fixes:
CVE-2023-44452 - Linux Mint Xreader CBT File Parsing Argument
                 Injection Remote Code Execution Vulnerability.

Based on:
https://gitlab.gnome.org/GNOME/evince/-/commit/7b5ad18399b04cbfce02730d28baf30e9fc35b58

This vulnerability was discovered by:
Febin Mon Saji working with Trend Micro Zero Day Initiative

4f0c6ec... by Michael Webster

epub: Prevent path traversal when extracting files [CVE-2023-44451]

Test each file's resolved path against the temporary directory
before extracting.

Fixes:
CVE-2023-44451 - Linux Mint Xreader EPUB File Parsing Directory
Traversal Remote Code Execution Vulnerability.

This vulnerability was discovered by:
Febin Mon Saji working with Trend Micro Zero Day Initiative

c69cfb5... by Michael Webster

dvi: Don't manually escape the exported filename.

Use g_shell_escape on the filename, as manually escaping can
allow command injection attacks.

ref:
https://gitlab.gnome.org/GNOME/evince/-/commit/350404c76dc8601e2cdd2636490e2afc83d3090e

93d2696... by Clement Lefebvre <email address hidden>

3.2.2

2ca702a... by Clement Lefebvre <email address hidden>

l10n: Update translations

e8c9c5c... by Clement Lefebvre <email address hidden>

3.2.1

e58dfe5... by Clement Lefebvre <email address hidden>

Gsettings: Remove state schema reference

314341a... by Clement Lefebvre <email address hidden>

3.2.0