Your message dated Mon, 23 Jun 2025 14:25:29 +0200 with message-id <aFlHufrR3K4Vtjuk@vis> and subject line Re: Bug#1068798: bookworm-pu: package fdroidserver/2.2.1-1 has caused the Debian Bug report #1068798, regarding bookworm-pu: package fdroidserver/2.2.1-1 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact owner@bugs.debian.org immediately.) -- 1068798: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068798 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
--- Begin Message ---
- To: Debian Bug Tracking System <submit@bugs.debian.org>
- Subject: bookworm-pu: package fdroidserver/2.2.1-1
- From: Jochen Sprickerhof <jspricke@debian.org>
- Date: Thu, 11 Apr 2024 11:36:12 +0200
- Message-id: <171282817202.19608.79851754559500317.reportbug@fenchel>
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: fdroidserver@packages.debian.org, Hans-Christoph Steiner <hans@eds.org> Control: affects -1 + src:fdroidserver User: release.debian.org@packages.debian.org Usertags: pu [ Reason ] There was a security problem reported against fdroidserver: https://www.openwall.com/lists/oss-security/2024/04/08/8 [ Impact ] Stable users of fdroidserver running their own repo could be tricked into providing wrongly signed files. [ Tests ] Manual test on F-Droid internal datasets as well as automated tests inside fdroidserver. [ Risks ] Low, the relevant code is only used to extract and verify signatures. [ Checklist ] [X] *all* changes are documented in the d/changelog [X] I reviewed all changes and I approve them [X] attach debdiff against the package in (old)stable [ ] the issue is verified as fixed in unstable [ Changes ] The patch reorders the code as well as changes the code of the imported androguard library. [ Other info ] Upstream is still working on a long term fix that will be uploaded to unstable later. I agreed with upstream to use use the patch provided in the mail on oss-security already now.
--- End Message ---
--- Begin Message ---
- To: Jonathan Wiltshire <jmw@debian.org>
- Cc: 1068798-done@bugs.debian.org
- Subject: Re: Bug#1068798: bookworm-pu: package fdroidserver/2.2.1-1
- From: Jochen Sprickerhof <jspricke@debian.org>
- Date: Mon, 23 Jun 2025 14:25:29 +0200
- Message-id: <aFlHufrR3K4Vtjuk@vis>
- In-reply-to: <[🔎] aFgIG5UFca_j4Q0d@powdarrmonkey.net>
- References: <171282817202.19608.79851754559500317.reportbug@fenchel> <[🔎] aFgIG5UFca_j4Q0d@powdarrmonkey.net>
Hi Jonathan, * Jonathan Wiltshire <jmw@debian.org> [2025-06-22 14:41]:Hi, On Thu, Apr 11, 2024 at 11:36:12AM +0200, Jochen Sprickerhof wrote:[ Reason ] There was a security problem reported against fdroidserver: https://www.openwall.com/lists/oss-security/2024/04/08/8 [ Impact ] Stable users of fdroidserver running their own repo could be tricked into providing wrongly signed files.Is this issue fixed in unstable yet?Thanks for asking. I think this is partly fixed in unstable but I don't think there is a need to backport it to bookworm, thus closing.Cheers JochenAttachment: signature.asc
Description: PGP signature
--- End Message ---