Your message dated Tue, 24 Aug 2010 15:03:18 +0000
with message-id <e1onv1y-00052f...@franck.debian.org>
and subject line Bug#592716: fixed in drupal6 6.18-1
has caused the Debian Bug report #592716,
regarding drupal6: SA-CORE-2010-002 - Drupal core - Multiple vulnerabilities
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
592716: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=592716
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: drupal6
Version: 6.16-1~bpo50+1
Severity: grave
Tags: security
Justification: user security hole


DRUPAL-SA-CORE-2010-002 from 2010-08-12 includes several vulnerabilities, some
of them allowing malicious site identifying as existing users and gaining
administrative access.

The problems got fixed in 6.18, so it looks like all versions currently in
Debian are affected.

Thanks,

-- System Information:
Debian Release: 5.0.5
  APT prefers stable
  APT policy: (990, 'stable'), (190, 'testing')
Architecture: i386 (i686)

Kernel: Linux 2.6.18.8-linode22 (SMP w/4 CPU cores)
Locale: LANG=ca_ES.UTF-8, LC_CTYPE=ca_ES.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages drupal6 depends on:
ii  curl               7.18.2-8lenny4        Get a file from an HTTP, HTTPS or 
ii  dbconfig-common    1.8.39                common framework for packaging dat
ii  debconf [debconf-2 1.5.24                Debian configuration management sy
ii  mysql-client       5.0.51a-24+lenny4     MySQL database client (metapackage
ii  mysql-client-5.0 [ 5.0.51a-24+lenny4     MySQL database client binaries
ii  nginx [httpd]      0.7.67-3              small, but very powerful and effic
ii  php5               5.2.6.dfsg.1-1+lenny9 server-side, HTML-embedded scripti
ii  php5-gd            5.2.6.dfsg.1-1+lenny9 GD module for php5
ii  php5-mysql         5.2.6.dfsg.1-1+lenny9 MySQL module for php5
ii  postfix [mail-tran 2.5.5-1.1             High-performance mail transport ag
ii  wwwconfig-common   0.1.2                 Debian web auto configuration

Versions of packages drupal6 recommends:
ii  mysql-server           5.0.51a-24+lenny4 MySQL database server (metapackage
ii  mysql-server-5.0 [mysq 5.0.51a-24+lenny4 MySQL database server binaries

drupal6 suggests no packages.

-- debconf information excluded



--- End Message ---
--- Begin Message ---
Source: drupal6
Source-Version: 6.18-1

We believe that the bug you reported is fixed in the latest version of
drupal6, which is due to be installed in the Debian FTP archive:

drupal6_6.18-1.diff.gz
  to main/d/drupal6/drupal6_6.18-1.diff.gz
drupal6_6.18-1.dsc
  to main/d/drupal6/drupal6_6.18-1.dsc
drupal6_6.18-1_all.deb
  to main/d/drupal6/drupal6_6.18-1_all.deb
drupal6_6.18.orig.tar.gz
  to main/d/drupal6/drupal6_6.18.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 592...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Luigi Gangitano <lu...@debian.org> (supplier of updated drupal6 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Tue, 24 Aug 2010 16:17:22 +0200
Source: drupal6
Binary: drupal6
Architecture: source all
Version: 6.18-1
Distribution: unstable
Urgency: high
Maintainer: Luigi Gangitano <lu...@debian.org>
Changed-By: Luigi Gangitano <lu...@debian.org>
Description: 
 drupal6    - a fully-featured content management framework
Closes: 592716
Changes: 
 drupal6 (6.18-1) unstable; urgency=high
 .
   [ Luigi Gangitano ]
   * Urgency high due to security fixes
 .
   * New upstream release
     - Fixes multiple remote vulnerabilities (Closes: #592716)
       (Ref: SA-CORE-2010-002, CVE-TBA)
 .
   * debian/control
     - Bumped Standard-Version to 3.9.1.0, no change needed
Checksums-Sha1: 
 a25cec6208deff6ba4e19cf8f64ffcdbbf0b76fd 1115 drupal6_6.18-1.dsc
 9706ef1c0e1e3ab8606d86da54ec73bae69397b9 1094576 drupal6_6.18.orig.tar.gz
 e4ab8ba3a369f1d204aadf872853618c16799f74 18706 drupal6_6.18-1.diff.gz
 27da0a6b1c0171ec1ca15dab136fc1e23a8053b1 1126170 drupal6_6.18-1_all.deb
Checksums-Sha256: 
 5661516c99539242407f01879152d819cfe227c8c6a0becc720d1dae6f13a08e 1115 
drupal6_6.18-1.dsc
 b07815d2922a48ba6630d44345fc53f6e9b1a3cd8a58a510e566854610573c98 1094576 
drupal6_6.18.orig.tar.gz
 515e15d69ee26f399d6db2c20437e9e1c3d9e53e32fb71a4bcebb15e19953543 18706 
drupal6_6.18-1.diff.gz
 5a0ddd4f2b232d8235f0dca94373fe11143ab1feca345bba0be9e39e3cabc93f 1126170 
drupal6_6.18-1_all.deb
Files: 
 8e4b7698ec72a38ac4e898301ca4c9d1 1115 web extra drupal6_6.18-1.dsc
 313b0f1d8a08b74ee6269cee250bd45d 1094576 web extra drupal6_6.18.orig.tar.gz
 ebe7882abc54a7ce54413cbf22aa503e 18706 web extra drupal6_6.18-1.diff.gz
 34a7662ba2c29987d94665243aa79fb7 1126170 web extra drupal6_6.18-1_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (Darwin)

iEYEARECAAYFAkxz3UQACgkQ8ZumGJJMDCYraQCfVzSqczc7w7nuX+igZe/+v5WU
OcEAoIND+0bDemvyUbnc3AjsB8IrIw15
=rSXi
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to