[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#833595: marked as done (jessie-pu: package nullmailer/1.13-1+deb8u1)



Your message dated Sat, 17 Sep 2016 13:08:06 +0100
with message-id <1474114086.2011.126.camel@adam-barratt.org.uk>
and subject line Closing p-u bugs for updates in 8.6
has caused the Debian Bug report #833595,
regarding jessie-pu: package nullmailer/1.13-1+deb8u1
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
833595: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=833595
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: release.debian.org
Severity: normal
Tags: jessie
User: release.debian.org@packages.debian.org
Usertags: pu

Dear Release Team,

#831813 is an rc-bug in nullmailer, which, for some configurations,
keeps username/passwords in the debconf db. I've fixed this in
unstable as an NMU; Security has suggested doing the same for jessie
in a point release.

Debdiff attached.

Cheers,
-- 
 ,''`.  Christian Hofstaedtler <zeha@debian.org>
: :' :  Debian Developer
`. `'   7D1A CFFA D9E0 806C 9C4C  D392 5C13 D6DB 9305 2E03
  `-

diff -Nru nullmailer-1.13/debian/changelog nullmailer-1.13/debian/changelog
--- nullmailer-1.13/debian/changelog	2014-08-08 00:19:32.000000000 +0000
+++ nullmailer-1.13/debian/changelog	2016-08-06 17:38:32.000000000 +0000
@@ -1,3 +1,12 @@
+nullmailer (1:1.13-1+deb8u1) jessie; urgency=medium
+
+  * Non-maintainer upload.
+  * Do not keep relayhost data in debconf database longer than
+    strictly needed. (Closes: #831813)
+    Backport of 1:1.13-1.2 from unstable.
+
+ -- Christian Hofstaedtler <zeha@debian.org>  Sat, 06 Aug 2016 17:36:35 +0000
+
 nullmailer (1:1.13-1) unstable; urgency=low
 
   * Ack NMU, thankyou for your help with this package.
diff -Nru nullmailer-1.13/debian/postinst nullmailer-1.13/debian/postinst
--- nullmailer-1.13/debian/postinst	2012-08-21 08:07:21.000000000 +0000
+++ nullmailer-1.13/debian/postinst	2016-08-06 17:35:13.000000000 +0000
@@ -37,6 +37,8 @@
 				     -e 's/[[:space:]]*:[[:space:]]*/\n/g' \
 				     -e ':b s/(\[[^]=]*)=/\1:/; tb' \
 				     -e 's/[][]//g' > /etc/nullmailer/remotes
+		# zap debconf entry, as this key may contain sensitive data.
+		db_set nullmailer/relayhost ""
 
 		db_get nullmailer/adminaddr
 		if [ "$RET" ]; then

Attachment: signature.asc
Description: PGP signature


--- End Message ---
--- Begin Message ---
Version: 8.6

The updates referred to in each of these bugs were included in today's
stable point release.

Regards,

Adam

--- End Message ---

Reply to: