[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#751750: pu: package ldns/1.6.13-1+deb7u1



Control: tags -1 + pending

On Thu, 2014-06-19 at 13:09 +0100, Adam D. Barratt wrote:
> On 2014-06-16 10:45, Ondřej Surý wrote:
> > I have prepared security, but non-dsa, update to ldns that creates
> > private DNSSEC keys with default umask (CVE-2014-3209).
> > 
> > The patch is very simple and it has been prepared by
> > upstream.
> [...]
> >  ldns (1.6.13-1+deb7u1) stable-security; urgency=medium
> >  .
> >    * [CVE-2014-3209]: fix ldns-keygen writing private DNSKEYs with 
> > default
> >      umask (Closes: #746758)
> > [...]
> > 
> > It's not a critical issue (hence non-DSA), but it would be nice to
> > have this fixed in stable.
> 
> Please s/stable-security/wheezy/ in the changelog and go ahead; thanks.

For the record, this was uploaded and I've just flagged it for
acceptance; thanks.

Regards,

Adam


Reply to: