Your message dated Thu, 05 Feb 2015 19:32:56 +0000
with message-id <e1yjsaa-00048u...@franck.debian.org>
and subject line Bug#775640: fixed in unzip 6.0-8+deb7u2
has caused the Debian Bug report #775640,
regarding libarchive-zip-perl: FTBFS: Test failure (unzip/CVE-2014-8139
regression?)
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
775640: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775640
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: libarchive-zip-perl
Version: 1.39-1
Severity: serious
Tags: jessie sid
User: debian...@lists.debian.org
Usertags: qa-ftbfs-20150117 qa-ftbfs
Justification: FTBFS in jessie on amd64
Hi,
During a rebuild of all packages in jessie (in a jessie chroot, not a
sid chroot), your package failed to build on amd64.
Relevant part (hopefully):
> # expected: '0'
> # Looks like you failed 1 test of 4.
> t/17_bug_73797.t ..............
> Dubious, test returned 1 (wstat 256, 0x100)
> Failed 1/4 subtests
>
> Test Summary Report
> -------------------
> t/17_bug_73797.t (Wstat: 256 Tests: 4 Failed: 1)
> Failed test: 4
> Non-zero exit status: 1
> Files=17, Tests=250, 3 wallclock secs ( 0.07 usr 0.09 sys + 2.04 cusr
> 0.75 csys = 2.95 CPU)
> Result: FAIL
> Failed 1/17 test programs. 1/250 subtests failed.
> make[2]: *** [test_dynamic] Error 1
> Makefile:910: recipe for target 'test_dynamic' failed
The full build log is available from:
http://aws-logs.debian.net/ftbfs-logs/2015/01/17/libarchive-zip-perl_1.39-1_jessie.log
A list of current common problems and possible solutions is available at
http://wiki.debian.org/qa.debian.org/FTBFS . You're welcome to contribute!
About the archive rebuild: The rebuild was done on EC2 VM instances from
Amazon Web Services, using a clean, minimal and up-to-date chroot. Every
failed build was retried once to eliminate random failures.
--- End Message ---
--- Begin Message ---
Source: unzip
Source-Version: 6.0-8+deb7u2
We believe that the bug you reported is fixed in the latest version of
unzip, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 775...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Santiago Vila <sanv...@debian.org> (supplier of updated unzip package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 01 Feb 2015 23:48:28 +0100
Source: unzip
Binary: unzip
Architecture: source amd64
Version: 6.0-8+deb7u2
Distribution: wheezy-security
Urgency: high
Maintainer: Santiago Vila <sanv...@debian.org>
Changed-By: Santiago Vila <sanv...@debian.org>
Description:
unzip - De-archiver for .zip files
Closes: 775640 776589
Changes:
unzip (6.0-8+deb7u2) wheezy-security; urgency=high
.
* Security upload.
* CVE-2014-9636: Fix heap overflow. Ensure that compressed
and uncompressed block sizes match when using STORED method
in extract.c. Closes: #776589.
* CVE-2014-8139: Update patch. The old one was not right
and had regressions with executable jar files. Closes: #775640
Checksums-Sha1:
8400b0fb5fad43ef83065d59a4330ee3a0d0b179 1676 unzip_6.0-8+deb7u2.dsc
f62b356bf40fcbf0e1143f99ed90860583c3ddbc 14193 unzip_6.0-8+deb7u2.debian.tar.gz
013a77751cd3d1e29adbd36978204631925ad5db 194898 unzip_6.0-8+deb7u2_amd64.deb
Checksums-Sha256:
b46313d05ee5cd7576390e8d21afe905f3b4eb08fa80ec97f1c2bf9197834123 1676
unzip_6.0-8+deb7u2.dsc
667c03e6b9ec219444f8a43c09532412d5e088f7c1803d673af899af34ebd6ab 14193
unzip_6.0-8+deb7u2.debian.tar.gz
aa7091a39b99cde48e1ed0ae930518b64ff215fbbf4a124b761bf386c3d38b8f 194898
unzip_6.0-8+deb7u2_amd64.deb
Files:
38b882234bc2a7b9350028f8ee09367c 1676 utils optional unzip_6.0-8+deb7u2.dsc
4fa58132df8930e551a5087f281149d4 14193 utils optional
unzip_6.0-8+deb7u2.debian.tar.gz
0fe74b198d91d63fefbb3094c43313a3 194898 utils optional
unzip_6.0-8+deb7u2_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJU0JetAAoJEAVMuPMTQ89ET+AP/36uVn5JvpaVAx7Ru9ZyT9V4
Vdwb1zubwU0wE9ldMeeuukS81+rXiwtNr0M77MjK2OULxSTf1Uw+BHy2+9p0AXm8
fCJsmmDckgkROaXDoIlRH5aPS9jaXSmYyBPM/P8X0iHxkDFsJvgl6J39ZYqBAXz9
w0ImGPiYuLivn/oSbDsqlMKU69CaA4uHXD8ETvFCBYE8v8uid2ZK+dzR+vA3/o6r
mW8MsjWd/dQbfo9+PF4qYOKQcegyRInk1TAZmUgIhxpNGKwPVe7U846pcYc6OlVu
W31pCTxNxiME1sSh+Vef5ZI4afWS3Qjq3hZqEaofOjjyDqETVhmku/hjmjUb6bPD
ec4qEUMswBGeuI3cmuS7vJCdHCvapNNEQkhQ3ZASs+xcOaqi5OkZETuvQvdowkZW
fxO7EIOivqn0S2IqB1H31QP366Z/x2DhMkz107wIMFdlkXNbWm9NGajgH+UUtPF0
tbW4LeGUhRQ/hgS6ZCtsqrmAxCPPK6FuAVPsZzqC3fJMrV+jnCktB374z8qx3MJ8
b1PxpBvbLN4YwD1JJlnTb3w+JmtH9gIbjFX59LBXf6YI5ELyWCxjBfYdW3Lays/J
iKym+98gY2AbNgiLJd6s6aevY5hqrp/2yFlzqIqcy9ooSujFj2cgimrad6sXwh1K
+Ce2HA0JHsi/+jnhwc2g
=dAGc
-----END PGP SIGNATURE-----
--- End Message ---