Your message dated Fri, 08 Feb 2013 21:04:07 +0000
with message-id <e1u3v79-0005po...@franck.debian.org>
and subject line Bug#698545: fixed in haskell-tls-extra 0.6.1-1
has caused the Debian Bug report #698545,
regarding Basic constraints vulnerability
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
698545: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=698545
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: haskell-tls-extra
Severity: grave
Tags: security upstream
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
someone reported a security problem against tls-extra:
https://github.com/vincenthz/hs-tls/issues/29
The author is contacted to see if he can backport the fix to 0.4.6:
http://www.haskell.org/pipermail/haskell-cafe/2013-January/105844.html
Greetings,
Joachim
- -- System Information:
Debian Release: 7.0
APT prefers unstable
APT policy: (500, 'unstable'), (101, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 3.5-trunk-amd64 (SMP w/4 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iEYEARECAAYFAlD7wQ4ACgkQ9ijrk0dDIGwLugCfSoF8gvqqea3km2mWK2FdWTy7
eB4An3Rs75tpgdG64yKnNq2S49vh3RCn
=DIgk
-----END PGP SIGNATURE-----
--- End Message ---
--- Begin Message ---
Source: haskell-tls-extra
Source-Version: 0.6.1-1
We believe that the bug you reported is fixed in the latest version of
haskell-tls-extra, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 698...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Joachim Breitner <nome...@debian.org> (supplier of updated haskell-tls-extra
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Fri, 08 Feb 2013 21:06:41 +0100
Source: haskell-tls-extra
Binary: libghc-tls-extra-dev libghc-tls-extra-prof libghc-tls-extra-doc
Architecture: source all amd64
Version: 0.6.1-1
Distribution: experimental
Urgency: low
Maintainer: Debian Haskell Group
<pkg-haskell-maintain...@lists.alioth.debian.org>
Changed-By: Joachim Breitner <nome...@debian.org>
Description:
libghc-tls-extra-dev - TLS extra default values and helpers
libghc-tls-extra-doc - TLS extra default values and helpers; documentation
libghc-tls-extra-prof - TLS extra default values and helpers; profiling
libraries
Closes: 698545
Changes:
haskell-tls-extra (0.6.1-1) experimental; urgency=low
.
* New upstream release
Closes: #698545, a certificate validation security flaw.
Checksums-Sha1:
075a23ba85c51c09cdec933cc2a9395f16c019e1 2574 haskell-tls-extra_0.6.1-1.dsc
05184c091a685e957d2ec84ee1cb61a7fe127b79 8091
haskell-tls-extra_0.6.1.orig.tar.gz
735369045cd7dcc5545d68f2a3f901a95336b2db 2879
haskell-tls-extra_0.6.1-1.debian.tar.gz
101e4781dc63357c77deccf66d30b2099e3a5445 49052
libghc-tls-extra-doc_0.6.1-1_all.deb
e47f6b62f84f7f9630d7090a5cbf101834ac0e68 56566
libghc-tls-extra-dev_0.6.1-1_amd64.deb
3d218f1f9cb6acf9f1d9a50216bee6b6901afcd9 51912
libghc-tls-extra-prof_0.6.1-1_amd64.deb
Checksums-Sha256:
961353577d538a965fd2e5b2ae6bb3aa2452266f7aa805e7bb5783b7415775d5 2574
haskell-tls-extra_0.6.1-1.dsc
56391245bf5f9a6cbf3c8d80fa921606f6c98837252a2ab09912a1a0c76f833d 8091
haskell-tls-extra_0.6.1.orig.tar.gz
19e0070991383c20409fa7cfe9f7500493b2d438d4599416a5838995c58a80e3 2879
haskell-tls-extra_0.6.1-1.debian.tar.gz
273b93fd5e873ba8cb7e4e34f2206419ae32995f882af932ba0fbe714d0ce1d2 49052
libghc-tls-extra-doc_0.6.1-1_all.deb
6defe081f20893e66ec3c3220d6c3aad2e51d652fa44f14ab5a4fb7e17aabfe1 56566
libghc-tls-extra-dev_0.6.1-1_amd64.deb
997613bb67ab5ef2ca78bfd2c740afc9f0d4b4b2b0249f7b1a43e9c4c9b6a5e4 51912
libghc-tls-extra-prof_0.6.1-1_amd64.deb
Files:
15fc1d554c9faa04639a2d57cbb9c1ed 2574 haskell extra
haskell-tls-extra_0.6.1-1.dsc
f84aea0247bf969aae8b9d41abf1730b 8091 haskell extra
haskell-tls-extra_0.6.1.orig.tar.gz
225ac66d04e0b53d9676dc058f30779f 2879 haskell extra
haskell-tls-extra_0.6.1-1.debian.tar.gz
6cf78de1288a628251f150364a7fbd57 49052 doc extra
libghc-tls-extra-doc_0.6.1-1_all.deb
88eee00b3a46d1b43776656b5ac880f0 56566 haskell extra
libghc-tls-extra-dev_0.6.1-1_amd64.deb
e12ad87ecc11e5f4a4853012e1ca35dc 51912 haskell extra
libghc-tls-extra-prof_0.6.1-1_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iEYEARECAAYFAlEVXXgACgkQ9ijrk0dDIGzt8QCfW5HrvubE/IDn0kgh29DcehHZ
em8AmwXxOjiTzrt/lJVSp9WXOGW5X+f7
=3kDJ
-----END PGP SIGNATURE-----
--- End Message ---