[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#703034: marked as done (apt unblock request)



Your message dated Thu, 14 Mar 2013 18:52:10 +0100
with message-id <20130314175210.GJ5840@radis.cristau.org>
and subject line Re: Bug#703034: apt unblock request
has caused the Debian Bug report #703034,
regarding apt unblock request
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
703034: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=703034
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: release.debian.org
Severity: important
User: release.debian.org@packages.debian.org
Usertags: unblock
X-Debbugs-Cc: deity@lists.debian.org


Hello Release Team,

unblock apt 0.9.7.8


Ansgar Burchardt found a flaw in the InRelease verification code
(CVE-2013-1051) effecting apt in testing and unstable.
[stable isn't effected as it has no support for it]

As a proper fix for this will be relatively big we propose to fix this
for testing by disabling InRelease support for now.


This can be revised of course if so desired after an experimental
upload which reintroduces a fixed InRelease handling we are working on
currently.


Thanks and sorry for the inconvenience,
 The APT team (David & Michael)

--- End Message ---
--- Begin Message ---
On Thu, Mar 14, 2013 at 14:59:35 +0100, Michael Vogt wrote:

> Package: release.debian.org
> Severity: important
> User: release.debian.org@packages.debian.org
> Usertags: unblock
> X-Debbugs-Cc: deity@lists.debian.org
> 
> 
> Hello Release Team,
> 
> unblock apt 0.9.7.8
> 
> 
> Ansgar Burchardt found a flaw in the InRelease verification code
> (CVE-2013-1051) effecting apt in testing and unstable.
> [stable isn't effected as it has no support for it]
> 
> As a proper fix for this will be relatively big we propose to fix this
> for testing by disabling InRelease support for now.
> 
:(

Unblocked.  Note that "criticial" is not a proper urgency setting.

Cheers,
Julien

Attachment: signature.asc
Description: Digital signature


--- End Message ---

Reply to: