[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#235477: marked as done (Two security vulnerabilities in anubis 3.6.2)



Your message dated Sun, 21 Mar 2004 18:04:17 -0800
with message-id <20040322020417.GG8592@triplehelix.org>
and subject line package orphaned
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 29 Feb 2004 17:15:43 +0000
>From jurijus@wooyd.org Sun Feb 29 09:15:43 2004
Return-path: <jurijus@wooyd.org>
Received: from d141-161-189.home.cgocable.net (bobcat) [24.141.161.189] 
	by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 1AxUXX-0005AD-00; Sun, 29 Feb 2004 09:15:43 -0800
Received: by bobcat (Postfix, from userid 1000)
	id 24ED96B48A; Sun, 29 Feb 2004 12:16:44 -0500 (EST)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Jurij Smakov <jurij@wooyd.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: Two security vulnerabilities in anubis 3.6.2
X-Mailer: reportbug 2.48
Date: Sun, 29 Feb 2004 12:16:44 -0500
Message-Id: <20040229171644.24ED96B48A@bobcat>
Delivered-To: submit@bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_02_27 
	(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-5.0 required=4.0 tests=HAS_PACKAGE autolearn=no 
	version=2.60-bugs.debian.org_2004_02_27
X-Spam-Level: 

Package: anubis
Version: 3.6.2-2.1
Severity: grave
Tags: security
Justification: user security hole

Hi, 

According to the anubis home page [0], two security vulnerabilities have
been discovered in anubis, including version 3.6.2, which is currently in
testing and unstable. The users are strongly advised to download and install
the available fixes [1].

Best regards,

Jurij Smakov                                       jurij@wooyd.org
http://www.wooyd.org/pgpkey                        KeyID: C99E03CC

[0] http://www.gnu.org/software/anubis
[1] http://savannah.gnu.org/patch/?func=detailitem&item_id=2699

-- System Information:
Debian Release: testing/unstable
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.4.20
Locale: LANG=C, LC_CTYPE=C

Versions of packages anubis depends on:
ii  debconf                     1.4.11       Debian configuration management sy
ii  debianutils                 2.7.1        Miscellaneous utilities specific t
ii  libc6                       2.3.2.ds1-11 GNU C Library: Shared libraries an
ii  libgcrypt1                  1.1.12-4     LGPL Crypto library - runtime libr
ii  libgnutls5                  0.8.8-2      GNU TLS library - runtime library
ii  libgpgme6                   0.3.15-1     GPGME - GnuPG Made Easy
ii  libpam0g                    0.76-15      Pluggable Authentication Modules l
ii  libpcre3                    4.3-4        Philip Hazel's Perl 5 Compatible R
ii  libwrap0                    7.6-ipv6.1-3 Wietse Venema's TCP wrappers libra
ii  openssl                     0.9.7c-5     Secure Socket Layer (SSL) binary a

-- debconf information excluded


---------------------------------------
Received: (at 235477-done) by bugs.debian.org; 22 Mar 2004 02:04:34 +0000
>From joshk@triplehelix.org Sun Mar 21 18:04:34 2004
Return-path: <joshk@triplehelix.org>
Received: from smtp812.mail.sc5.yahoo.com [66.163.170.82] 
	by spohr.debian.org with smtp (Exim 3.35 1 (Debian))
	id 1B5Enq-0000e2-00; Sun, 21 Mar 2004 18:04:34 -0800
Received: from unknown (HELO triplehelix.org) (edkwan@sbcglobal.net@68.126.186.145 with login)
  by smtp812.mail.sc5.yahoo.com with SMTP; 22 Mar 2004 02:04:18 -0000
Received: by triplehelix.org (Postfix, from userid 1000)
	id 7C8252DD93; Sun, 21 Mar 2004 18:04:17 -0800 (PST)
Date: Sun, 21 Mar 2004 18:04:17 -0800
To: 217148-done@bugs.debian.org, 235477-done@bugs.debian.org,
	192910-done@bugs.debian.org, 193835-done@bugs.debian.org,
	197486-done@bugs.debian.org, 197539-done@bugs.debian.org,
	208268-done@bugs.debian.org
Subject: package orphaned
Message-ID: <20040322020417.GG8592@triplehelix.org>
Mime-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="bGR76rFJjkSxVeRa"
Content-Disposition: inline
User-Agent: Mutt/1.5.5.1+cvs20040105i
From: joshk@triplehelix.org (Joshua Kwan)
Delivered-To: 235477-done@bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_03_12 
	(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-2.0 required=4.0 tests=BAYES_00 autolearn=no 
	version=2.60-bugs.debian.org_2004_03_12
X-Spam-Level: 


--bGR76rFJjkSxVeRa
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Because this package was recently orphaned, tracking these bugs as being
NMU'd and not acknowledged by a maintainer upload is no longer
necessary, so I'm closing these bugs.

--=20
Joshua Kwan

--bGR76rFJjkSxVeRa
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iQIVAwUBQF5JoKOILr94RG8mAQLYCw/8D7AAuza7rW1tmquOewgFpTXbrVngAVzl
3MtavZtL5U7K40N1v0ZJ4VdhSp+26KQapaUnw5P7+igHBq87ZhOpeHnysg6bmrAY
o8vUyR936wDrlzekwZrZpgGAhtp7iljwe+nmmBStvljdOpGHcrCUezWaoIE4qgjx
IuXdzwZd8ZPqtmQ3UfhmocRilv9isaoS0ok/4BDHY3Kxf4Y0DEad91CDwbkSPa90
w2CkbMOiQYMD0RcpiTpwYU7IQlwDFyclfowxHT9H4rhQuwRLagAe1MyjmInSe+QH
1LYjFgubtYphwBWyzsZA1hNaHcrGEBkyPyJ9D59hyfB8XP9OuTYxhU5vcTE+VCGB
8TTp1d/Dg31cUhDIJ5mbT61zRcsBgTC65x8tiqn5kigcspLOoWjZfQz+dlhcbHXK
Wx/2Y7rzc5dNM+GYWs4Fv1DFio2gtE8DlzW0MClnUT+W+64X9/Je+VZc0o2PRSVy
RreOhOp7fXnFBOnkgEgybFd19XaCV+R6S947GCB2KvN9lDPMA7F6V93mZZ9fwDMM
IoilDKFDqweqZcQZV9t8YeaX8l3HkWF6yOZmWT2PyyeEbk+Vi1BJzktQials+MYx
PDJSAogXf54G1ilJ4Kq2WuoSLbgMCDaWoK8NHr3ppMhGMJlBmCB5jSpLDDYeIeS8
mPo+Tn5TJyg=
=CsJR
-----END PGP SIGNATURE-----

--bGR76rFJjkSxVeRa--



Reply to: