Your message dated Fri, 14 Apr 2006 15:32:29 -0700
with message-id <[EMAIL PROTECTED]>
and subject line Bug#340105: fixed in vpnc 0.3.3+SVN20051028-3
has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere. Please contact me immediately.)
Debian bug tracking system administrator
(administrator, Debian Bugs database)
--- Begin Message ---
Package: vpnc
Version: 0.3.2+SVN20050326-2
Severity: serious
Tags: security
Justification: security
Hi Zomb,
the provided /etc/vpnc/example.conf is 0644 per default. It should be
0600 as lazy users might not add their own file but just edit
/etc/vpnc/example.conf. This file contains at least the IPsec secret.
This file should be 0600 per default.
This bug seems to be valid for all suites.
Greetings
Martin
-- System Information:
Debian Release: testing/unstable
APT prefers unstable
APT policy: (500, 'unstable'), (500, 'testing')
Architecture: i386 (i686)
Shell: /bin/sh linked to /bin/bash
Kernel: Linux 2.6.14-2-686
Locale: LANG=en_US, LC_CTYPE=en_US (charmap=ISO-8859-1)
Versions of packages vpnc depends on:
ii iproute 20041019-4 Professional tools to control the
ii libc6 2.3.5-8 GNU C Library: Shared libraries an
ii libgcrypt11 1.2.2-1 LGPL Crypto library - runtime libr
ii libgpg-error0 1.1-4 library for common error values an
vpnc recommends no packages.
-- no debconf information
--- End Message ---
--- Begin Message ---
Source: vpnc
Source-Version: 0.3.3+SVN20051028-3
We believe that the bug you reported is fixed in the latest version of
vpnc, which is due to be installed in the Debian FTP archive:
vpnc_0.3.3+SVN20051028-3.diff.gz
to pool/main/v/vpnc/vpnc_0.3.3+SVN20051028-3.diff.gz
vpnc_0.3.3+SVN20051028-3.dsc
to pool/main/v/vpnc/vpnc_0.3.3+SVN20051028-3.dsc
vpnc_0.3.3+SVN20051028-3_i386.deb
to pool/main/v/vpnc/vpnc_0.3.3+SVN20051028-3_i386.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Eduard Bloch <[EMAIL PROTECTED]> (supplier of updated vpnc package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Fri, 14 Apr 2006 23:30:36 +0200
Source: vpnc
Binary: vpnc
Architecture: source i386
Version: 0.3.3+SVN20051028-3
Distribution: unstable
Urgency: low
Maintainer: Eduard Bloch <[EMAIL PROTECTED]>
Changed-By: Eduard Bloch <[EMAIL PROTECTED]>
Description:
vpnc - Cisco-compatible VPN client
Closes: 340105 360704
Changes:
vpnc (0.3.3+SVN20051028-3) unstable; urgency=low
.
* 08_keepalive_and_rekeying.dpatch: patch for basic rekeying and keepalive
support from Tomas Mraz <[EMAIL PROTECTED]>
* stronger permissions of /etc/vpnc/ and /etc/vpnc/example.conf to protect
careless users from making their login data world-readable
(closes: #340105)
* documented connect/disconnect hooks in README.Debian, thanks to Elmar
Hoffmann (closes: #360704)
Files:
ab93e2df8f20c4374817ddc21b0beaf7 610 net extra vpnc_0.3.3+SVN20051028-3.dsc
3bdadcb7771365ffb9f39b9fde6a188a 15907 net extra
vpnc_0.3.3+SVN20051028-3.diff.gz
02e131071909893697de5bef2d0c85e6 55516 net extra
vpnc_0.3.3+SVN20051028-3_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)
iD8DBQFEQB904QZIHu3wCMURAv92AJ49RRMdqCq6lzngG3Atv86+p0vh8QCfenus
2Fl8jm4XdSr83Tx8NleVZfU=
=Ptak
-----END PGP SIGNATURE-----
--- End Message ---