Your message dated Sat, 15 Sep 2012 17:19:08 +0000
with message-id <e1tcw1m-0006hv...@franck.debian.org>
and subject line Bug#684619: fixed in nullmailer 1:1.11-2
has caused the Debian Bug report #684619,
regarding [nullmailer] Debconf prompts for info that might contain password,
saves to world-readable file
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
684619: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=684619
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: nullmailer
Version: 1:1.11-1
Severity: serious
Tags: security
X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org
--- Please enter the report below this line. ---
Durint installation, this package uses debconf to get information about how
mail should be delivered, giving examples that show how to specify a password
for an SMTP account. This information is then saved to
/etc/nullmailer/remotes which is readable by any account on the system.
--- System information. ---
Architecture: amd64
Kernel: Linux 3.2.0-3-amd64
Debian Release: wheezy/sid
500 unstable http.debian.net
--- Package information. ---
Depends (Version) | Installed
==============================-+-===============
libc6 (>= 2.4) | 2.13-35
libgnutls26 (>= 2.12.17-0) | 2.12.20-1
libstdc++6 (>= 4.1.1) | 4.7.1-6
debconf (>= 0.5) | 1.5.45
OR debconf-2.0 |
lsb-base | 4.1+Debian7
Recommends (Version) | Installed
================================-+-===========
rsyslog | 5.8.11-1+b1
OR system-log-daemon |
Package's Suggests field is empty.
--- End Message ---
--- Begin Message ---
Source: nullmailer
Source-Version: 1:1.11-2
We believe that the bug you reported is fixed in the latest version of
nullmailer, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 684...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Nick Leverton <n...@leverton.org> (supplier of updated nullmailer package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Tue, 21 Aug 2012 09:01:38 +0100
Source: nullmailer
Binary: nullmailer
Architecture: source amd64
Version: 1:1.11-2
Distribution: unstable
Urgency: low
Maintainer: Nick Leverton <n...@leverton.org>
Changed-By: Nick Leverton <n...@leverton.org>
Description:
nullmailer - simple relay-only mail transport agent
Closes: 684619
Changes:
nullmailer (1:1.11-2) unstable; urgency=low
.
* Make 'remotes' not world-readable (Closes: #684619)
Checksums-Sha1:
da8418627d9d1e299a2459419f8c6fab085f291f 1791 nullmailer_1.11-2.dsc
f51d2841bd9602a05f90d72d20238c2507886829 33198 nullmailer_1.11-2.debian.tar.gz
273e54e0ae7d46678a80f26e9a65f78c12b3b2d4 137124 nullmailer_1.11-2_amd64.deb
Checksums-Sha256:
92ea9daf7ecd4c8cdfca4b14901a30634111a8b6bb93a1ccec8eae919eb1241e 1791
nullmailer_1.11-2.dsc
c8dae45c2d5b2a9d8bf8dd6d19cbaf4d676ff1a11c9747a98e826170e705e830 33198
nullmailer_1.11-2.debian.tar.gz
49bc26710a2286413aa7c5af4031ce18a11d7720c9b9c947b607b79647770ff5 137124
nullmailer_1.11-2_amd64.deb
Files:
703d047ab35ba9d134934ae0a69b9225 1791 mail extra nullmailer_1.11-2.dsc
8801de5dfc534abe6383f1446118edca 33198 mail extra
nullmailer_1.11-2.debian.tar.gz
000e32cf0a84bd967cc53e1da397e67a 137124 mail extra nullmailer_1.11-2_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iQIVAwUBUFSxzwkauFYGmqocAQiH7Q//Z9Pkcdul+fEF0y3bZiRP7Z11+90cDdhE
IeOgBBBkRRpaPYfvfVjGy73l0c7JQJaYUJSUQKA0KwM1C9Lq2YUAbRYPcIYqsr5A
Tg9jGDtamW4OmJPhoJKSW+Vt1fpOanG0VxP88xcYuGDVHdvBUr0nUdo7qX74tyRC
zT5duRwNQvJbCU+EKF9XqFl/t5Xvl0h/kYX807kT5wQfpsGvYD/LHrZCdewjG5ii
v4n5dN6udjIM1WdK+WUK/0A9tdQgBXERfQfm5XOZhX3L6t2K+kVW2pZPsdGhe+Yy
LvxyrpRihkAXO80fgrUo7rfjuYt51SfiKCD1gonkIIt+/BwFfYsVKA7A8OUHIDzB
01Xoa8EMuuiFv4JbK/n7M/29KKtgIq8QTKSGeGPXLcyGiZypkdPk0VuIBJOXXa6X
KfYRLV1zfgtGTIZTk9Emjr7Tt+4h/ZlMD/fBr7fn+KyA/+sLKR8ItU31REHZKM6N
kyohVFEfgLYmafvgv+ZDhxEPpZToI9PEJIYVpVDqPCAmcsuEfKBQAx+N5l4nRQE/
tLfloL1k03QZD0ctKCeb2njvUeUmj+m4fYWsuxdF4zceb6wC3XhwSiBTYpWOfC95
SN4XGB2lzYp2Wt0vVLQ7KftIY9bRoiMlUJb/J1fd+Aitdx9QVgAT98kpZMLJT6y0
ZYgfpi6DjCA=
=yIqa
-----END PGP SIGNATURE-----
--- End Message ---