Your message dated Mon, 23 Jun 2025 14:25:29 +0200
with message-id <aFlHufrR3K4Vtjuk@vis>
and subject line Re: Bug#1068798: bookworm-pu: package fdroidserver/2.2.1-1
has caused the Debian Bug report #1068798,
regarding bookworm-pu: package fdroidserver/2.2.1-1
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
1068798: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068798
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: release.debian.org
Severity: normal
Tags: bookworm
X-Debbugs-Cc: fdroidser...@packages.debian.org, Hans-Christoph Steiner
<h...@eds.org>
Control: affects -1 + src:fdroidserver
User: release.debian....@packages.debian.org
Usertags: pu
[ Reason ]
There was a security problem reported against fdroidserver:
https://www.openwall.com/lists/oss-security/2024/04/08/8
[ Impact ]
Stable users of fdroidserver running their own repo could be tricked
into providing wrongly signed files.
[ Tests ]
Manual test on F-Droid internal datasets as well as automated tests
inside fdroidserver.
[ Risks ]
Low, the relevant code is only used to extract and verify signatures.
[ Checklist ]
[X] *all* changes are documented in the d/changelog
[X] I reviewed all changes and I approve them
[X] attach debdiff against the package in (old)stable
[ ] the issue is verified as fixed in unstable
[ Changes ]
The patch reorders the code as well as changes the code of the imported
androguard library.
[ Other info ]
Upstream is still working on a long term fix that will be uploaded to
unstable later. I agreed with upstream to use use the patch provided in
the mail on oss-security already now.
--- End Message ---
--- Begin Message ---
Hi Jonathan,
* Jonathan Wiltshire <j...@debian.org> [2025-06-22 14:41]:
Hi,
On Thu, Apr 11, 2024 at 11:36:12AM +0200, Jochen Sprickerhof wrote:
[ Reason ]
There was a security problem reported against fdroidserver:
https://www.openwall.com/lists/oss-security/2024/04/08/8
[ Impact ]
Stable users of fdroidserver running their own repo could be tricked
into providing wrongly signed files.
Is this issue fixed in unstable yet?
Thanks for asking. I think this is partly fixed in unstable but I don't
think there is a need to backport it to bookworm, thus closing.
Cheers Jochen
signature.asc
Description: PGP signature
--- End Message ---