jasper: CVE-2014-8157 CVE-2014-8158

Related Vulnerabilities: CVE-2014-8157   CVE-2014-8158  

Debian Bug report logs - #775970
jasper: CVE-2014-8157 CVE-2014-8158

version graph

Reported by: "Karl O. Pinc" <kop@meme.com>

Date: Thu, 22 Jan 2015 03:21:02 UTC

Severity: grave

Tags: patch, security, upstream

Found in version jasper/1.900.1-7

Fixed in versions jasper/1.900.1-13+deb7u3, jasper/1.900.1-debian1-2.4, jasper/1.900.1-7+squeeze4

Done: Thorsten Alteholz <debian@alteholz.de>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Roland Stigge <stigge@antcom.de>:
Bug#775970; Package libjasper1. (Thu, 22 Jan 2015 03:21:07 GMT) (full text, mbox, link).


Acknowledgement sent to "Karl O. Pinc" <kop@meme.com>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Roland Stigge <stigge@antcom.de>. (Thu, 22 Jan 2015 03:21:07 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: "Karl O. Pinc" <kop@meme.com>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: libjasper1: CVE-2014-8157 CVE-2014-8158
Date: Wed, 21 Jan 2015 21:09:57 -0600
Package: libjasper1
Version: 1.900.1-13+deb7u2
Severity: grave
Tags: security upstream
Justification: user security hole

From: http://www.ocert.org/advisories/ocert-2015-001.html

The library is affected by an off-by-one error in a buffer boundary
check in jpc_dec_process_sot(), leading to a heap based buffer
overflow, as well as multiple unrestricted stack memory use issues in
jpc_qmfb.c, leading to stack overflow.

A specially crafted jp2 file can be used to trigger the
vulnerabilities.

-- System Information:
Debian Release: 7.8
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.2.0-4-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages libjasper1 depends on:
ii  libc6              2.13-38+deb7u6
ii  libjpeg8           8d-1+deb7u1
ii  multiarch-support  2.13-38+deb7u6

libjasper1 recommends no packages.

Versions of packages libjasper1 suggests:
pn  libjasper-runtime  <none>

-- no debconf information



Changed Bug title to 'jasper: CVE-2014-8157 CVE-2014-8158' from 'libjasper1: CVE-2014-8157 CVE-2014-8158' Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 22 Jan 2015 04:18:04 GMT) (full text, mbox, link).


Marked as found in versions jasper/1.900.1-7. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 22 Jan 2015 04:18:05 GMT) (full text, mbox, link).


Bug reassigned from package 'libjasper1' to 'src:jasper'. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 22 Jan 2015 04:18:09 GMT) (full text, mbox, link).


No longer marked as found in versions jasper/1.900.1-7 and jasper/1.900.1-13+deb7u2. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 22 Jan 2015 04:18:10 GMT) (full text, mbox, link).


Marked as found in versions jasper/1.900.1-7. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 22 Jan 2015 05:27:04 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Roland Stigge <stigge@antcom.de>:
Bug#775970; Package src:jasper. (Thu, 22 Jan 2015 16:21:09 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Roland Stigge <stigge@antcom.de>. (Thu, 22 Jan 2015 16:21:09 GMT) (full text, mbox, link).


Message #20 received at 775970@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: 775970@bugs.debian.org
Subject: Re: Bug#775970: jasper: Debdiffs for CVE-2014-8157 CVE-2014-8158
Date: Thu, 22 Jan 2015 17:17:19 +0100
[Message part 1 (text/plain, inline)]
Control: tags -1 + patch

Hi Roland

Attached are the two debdiffs, one for wheezy-security and the one for
the unstable upload.

Regards,
Salvatore
[jasper_1.900.1-13+deb7u3.debdiff (text/plain, attachment)]
[jasper_1.900.1-debian1-2.4.debdiff (text/plain, attachment)]

Added tag(s) patch. Request was from Salvatore Bonaccorso <carnil@debian.org> to 775970-submit@bugs.debian.org. (Thu, 22 Jan 2015 16:21:09 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Roland Stigge <stigge@antcom.de>:
Bug#775970; Package src:jasper. (Thu, 22 Jan 2015 18:03:13 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Roland Stigge <stigge@antcom.de>. (Thu, 22 Jan 2015 18:03:13 GMT) (full text, mbox, link).


Message #27 received at 775970@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: 775970@bugs.debian.org
Subject: jasper: diff for NMU version 1.900.1-debian1-2.4
Date: Thu, 22 Jan 2015 19:01:39 +0100
[Message part 1 (text/plain, inline)]
Control: tags 775970 + pending

Hi Roland,

I've prepared an NMU for jasper (versioned as 1.900.1-debian1-2.4) and
uploaded it to DELAYED/5. Please feel free to tell me if I
should delay it longer.

Regards,
Salvatore
[jasper-1.900.1-debian1-2.4-nmu.diff (text/x-diff, attachment)]

Added tag(s) pending. Request was from Salvatore Bonaccorso <carnil@debian.org> to 775970-submit@bugs.debian.org. (Thu, 22 Jan 2015 18:03:13 GMT) (full text, mbox, link).


Reply sent to Salvatore Bonaccorso <carnil@debian.org>:
You have taken responsibility. (Sun, 25 Jan 2015 15:21:20 GMT) (full text, mbox, link).


Notification sent to "Karl O. Pinc" <kop@meme.com>:
Bug acknowledged by developer. (Sun, 25 Jan 2015 15:21:20 GMT) (full text, mbox, link).


Message #34 received at 775970-close@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: 775970-close@bugs.debian.org
Subject: Bug#775970: fixed in jasper 1.900.1-13+deb7u3
Date: Sun, 25 Jan 2015 15:17:07 +0000
Source: jasper
Source-Version: 1.900.1-13+deb7u3

We believe that the bug you reported is fixed in the latest version of
jasper, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 775970@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated jasper package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 22 Jan 2015 16:39:58 +0100
Source: jasper
Binary: libjasper1 libjasper-dev libjasper-runtime
Architecture: source amd64
Version: 1.900.1-13+deb7u3
Distribution: wheezy-security
Urgency: high
Maintainer: Roland Stigge <stigge@antcom.de>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Description: 
 libjasper-dev - Development files for the JasPer JPEG-2000 library
 libjasper-runtime - Programs for manipulating JPEG-2000 files
 libjasper1 - JasPer JPEG-2000 runtime library
Closes: 775970
Changes: 
 jasper (1.900.1-13+deb7u3) wheezy-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * Add 07-CVE-2014-8157.patch patch.
     CVE-2014-8157: dec->numtiles off-by-one check in jpc_dec_process_sot().
     (Closes: #775970)
   * Add 08-CVE-2014-8158.patch patch.
     CVE-2014-8158: unrestricted stack memory use in jpc_qmfb.c (Closes: #775970)
Checksums-Sha1: 
 d1690d295c1c1dfe3dba7bb88ef5cc2483ba0aa9 1878 jasper_1.900.1-13+deb7u3.dsc
 c2dd86e61c07a04609773fb840ff0796c436fe30 33864 jasper_1.900.1-13+deb7u3.debian.tar.gz
 a53462f64291a92821885b624e92b302115785b1 160120 libjasper1_1.900.1-13+deb7u3_amd64.deb
 ec0e6e78c999e26726621363b3993ab595fd1bf6 569224 libjasper-dev_1.900.1-13+deb7u3_amd64.deb
 f0c2c136fcf7c14a9e33ee74ceb2f6d38beb9678 27274 libjasper-runtime_1.900.1-13+deb7u3_amd64.deb
Checksums-Sha256: 
 6be5b2a5d45bf4de081e218fb01f12cf20e8436a602a8b289f273c1683038148 1878 jasper_1.900.1-13+deb7u3.dsc
 4440e323793fe8fb9de352a4460b28a7a58b78cd269c8e778ea5cc026e5b6b9e 33864 jasper_1.900.1-13+deb7u3.debian.tar.gz
 656500ae418c6a6a00c70916571c3455dee5745cc4f166862d40eee44e273a13 160120 libjasper1_1.900.1-13+deb7u3_amd64.deb
 2cfe9bf82564958f5d20acdba9eb87c9ff9e9cc104baefca1a5d576079125c7c 569224 libjasper-dev_1.900.1-13+deb7u3_amd64.deb
 45ffc604726b7fe5496e4cf87658cb7c8d525002d6b679287e51703709674c74 27274 libjasper-runtime_1.900.1-13+deb7u3_amd64.deb
Files: 
 925fc6931d68b53e2ec1f4afcd35e04f 1878 graphics optional jasper_1.900.1-13+deb7u3.dsc
 9765c9bd45d2d6f0ac5d73c4a1c42c79 33864 graphics optional jasper_1.900.1-13+deb7u3.debian.tar.gz
 a210810924e691c6ca2452629bc617b5 160120 libs optional libjasper1_1.900.1-13+deb7u3_amd64.deb
 5e99aebc6c62cde98edcc7e80837da6c 569224 libdevel optional libjasper-dev_1.900.1-13+deb7u3_amd64.deb
 df449eb8ce10177b0a2b242b609f3b38 27274 graphics optional libjasper-runtime_1.900.1-13+deb7u3_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJUwRrCAAoJEAVMuPMTQ89Ei2MQAIub9nsV6DaFfWmfTdFAAFti
8zF6vWmRthNLJO6SBxhGEG/HrNq7R4Xhg8+1hWFHDNnsWwqkXja44g24vMJVxG/5
3PYMv+npp3aoxZhQG8Of1B7rqEgh5jWd780ikKjGEJMet4QmbgYOCrtx8B2LYXGU
W6xUEEBuhIRmNA/psNDE1T3PPBaqThchnbVWyLoeeULCc1xqza+PoGPKKcvToomj
n3vjbq3L9HUqmMZvA/wba33keyBlkt19jnF/12uGwKJcf38RWyrcl46enBP2hfZ8
5+ZmZN1JM8R5QFnjrJ85rs2GFbKLtl12k27bksKPPZSucjNBmCDccANMsgQPV2VX
nIkQGxPOL9AIhCfL4L60YtI28IAjPShPyo+P1eQs6VcfiemalSL2DV+4Aeq99IT9
54CWo3C8oW+Cj5wPUOSqyYtkaEbRFZpZvYt9ib1tpVSGJbTD+rDax1dSjKfrMDSY
aKoeXOl4oqM0YN9jxfEOdD/NJCS/sS9RX8w20TQ/CT9uqIJoJYKUJf2KnJE73vq2
rBIGtH/DKgsJaQpUStT9UKVG8It1DzpkaEMQhvGiedOAW+0AOWqWo3reamtw5zvu
QHC34r97Xt1E6TAQaEOK0EZx6fZJnexXFVdmCisU5B6JvaeFV0vfZzP8ABFBvFDz
nhxxpz7kDyZnJC8Dh8l4
=U4+p
-----END PGP SIGNATURE-----




Reply sent to Salvatore Bonaccorso <carnil@debian.org>:
You have taken responsibility. (Tue, 27 Jan 2015 18:21:05 GMT) (full text, mbox, link).


Notification sent to "Karl O. Pinc" <kop@meme.com>:
Bug acknowledged by developer. (Tue, 27 Jan 2015 18:21:05 GMT) (full text, mbox, link).


Message #39 received at 775970-close@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: 775970-close@bugs.debian.org
Subject: Bug#775970: fixed in jasper 1.900.1-debian1-2.4
Date: Tue, 27 Jan 2015 18:18:44 +0000
Source: jasper
Source-Version: 1.900.1-debian1-2.4

We believe that the bug you reported is fixed in the latest version of
jasper, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 775970@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated jasper package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 22 Jan 2015 17:09:24 +0100
Source: jasper
Binary: libjasper1 libjasper-dev libjasper-runtime
Architecture: source amd64
Version: 1.900.1-debian1-2.4
Distribution: unstable
Urgency: high
Maintainer: Roland Stigge <stigge@antcom.de>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Description:
 libjasper-dev - Development files for the JasPer JPEG-2000 library
 libjasper-runtime - Programs for manipulating JPEG-2000 files
 libjasper1 - JasPer JPEG-2000 runtime library
Closes: 775970
Changes:
 jasper (1.900.1-debian1-2.4) unstable; urgency=high
 .
   * Non-maintainer upload.
   * Add 07-CVE-2014-8157.patch patch.
     CVE-2014-8157: dec->numtiles off-by-one check in jpc_dec_process_sot().
     (Closes: #775970)
   * Add 08-CVE-2014-8158.patch patch.
     CVE-2014-8158: unrestricted stack memory use in jpc_qmfb.c (Closes: #775970)
Checksums-Sha1:
 671278302ddba443c2bf1a4239d7cdedb235d78b 1927 jasper_1.900.1-debian1-2.4.dsc
 8edf28dab43a88903de4ca70c2753a6e45273a79 29504 jasper_1.900.1-debian1-2.4.debian.tar.xz
Checksums-Sha256:
 8d5f2e8de142c57220df75e965ea07628a2c70e20d87c3d25c82a10bafa9326e 1927 jasper_1.900.1-debian1-2.4.dsc
 64781a9307c5aee8c69c7ab78b699f67310172ec4a42202f50555c2a514f3249 29504 jasper_1.900.1-debian1-2.4.debian.tar.xz
Files:
 75490a9daf5859a8084e204dac1777e7 1927 graphics optional jasper_1.900.1-debian1-2.4.dsc
 5005a6124ed2d705e1beb7ea0e385c9e 29504 graphics optional jasper_1.900.1-debian1-2.4.debian.tar.xz

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJUwTYeAAoJEAVMuPMTQ89ENagP/214vYQw1pR+3aIHpuemWss+
zDAJwIUDowHg7wMHpbA99YBjjbu2B7q7TGIJMP9+9ZIfA/ma+vHGPXaEbl8wUi16
BURBhxkYTZOId/B4pfpDcfIuFs2VluWMBmzQ9Eyuxxqs03rNAil1eh7Xzw9exZPU
EEFZvM0slBkjVYGP9vh0hOO7U3xM5nLUp4LrjbZ5YoTj0CUW8najIRRLmWC+jf30
HvqNQqV6AvqXXEwPtkO3GzJevZ3bgrmiASf1930UPeobLgZlSsaWACbZrbMoJrim
jJtzZ5Km8u/LcOseMYVMmLMA6526uizx1IpJ82LnYOLllLLeB+LxwGPPfBwtmDfn
ECOUBJfMnt9L+SE+DG5rlt7JACl3Gicc5yPbzXN0SqUdXwNjGay6BsZl28cq3Yxt
sT3asePa/f+q/wkJ5eYuE8mnsAgGMcZ9DTA705dIESDAqZ2NGhxYj4TMDes/pb6H
6AWUcVofVTLm60N07KDvphN/fqPpC2zSYyv8kOVO5YhjBYjTGBZJ056yotcN7y7q
m3ijV2ApfkPiGd67+tYVbERSD17gYYglSeHApMkUuwlQrcdrdU31UFRVxpP/2nCq
vujyiXeLkck5CxaArc2K0l5Tdf4JHe9zsZpyZIxDqNQ27dxV+PML1OPLvUHIg021
Pu3gJZE+w1W2EIyNB1+t
=irp9
-----END PGP SIGNATURE-----




Reply sent to Thorsten Alteholz <debian@alteholz.de>:
You have taken responsibility. (Tue, 27 Jan 2015 22:24:06 GMT) (full text, mbox, link).


Notification sent to "Karl O. Pinc" <kop@meme.com>:
Bug acknowledged by developer. (Tue, 27 Jan 2015 22:24:06 GMT) (full text, mbox, link).


Message #44 received at 775970-close@bugs.debian.org (full text, mbox, reply):

From: Thorsten Alteholz <debian@alteholz.de>
To: 775970-close@bugs.debian.org
Subject: Bug#775970: fixed in jasper 1.900.1-7+squeeze4
Date: Tue, 27 Jan 2015 22:21:17 +0000
Source: jasper
Source-Version: 1.900.1-7+squeeze4

We believe that the bug you reported is fixed in the latest version of
jasper, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 775970@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thorsten Alteholz <debian@alteholz.de> (supplier of updated jasper package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 27 Jan 2015 20:20:04 +0100
Source: jasper
Binary: libjasper1 libjasper-dev libjasper-runtime
Architecture: source i386
Version: 1.900.1-7+squeeze4
Distribution: squeeze-lts
Urgency: high
Maintainer: Roland Stigge <stigge@antcom.de>
Changed-By: Thorsten Alteholz <debian@alteholz.de>
Description: 
 libjasper-dev - Development files for the JasPer JPEG-2000 library
 libjasper-runtime - Programs for manipulating JPEG-2000 files
 libjasper1 - The JasPer JPEG-2000 runtime library
Closes: 775970
Changes: 
 jasper (1.900.1-7+squeeze4) squeeze-lts; urgency=high
 .
   * Non-maintainer upload by the Squeeze LTS Team.
   * Add 07-CVE-2014-8157.patch patch.
     CVE-2014-8157: dec->numtiles off-by-one check in jpc_dec_process_sot().
     (Closes: #775970)
   * Add 08-CVE-2014-8158.patch patch.
     CVE-2014-8158: unrestricted stack memory use in jpc_qmfb.c (Closes: #775970)
Checksums-Sha1: 
 7cd93b0068da7d2a7d293ebeaa7b17ef70bb75ce 1844 jasper_1.900.1-7+squeeze4.dsc
 a20dc389f5962661b7ab81777c8316f8faee3a99 1143400 jasper_1.900.1.orig.tar.gz
 b3f592bf84e9ba221f3cbe7e81a3d38e5d394071 54228 jasper_1.900.1-7+squeeze4.diff.gz
 72e169e5908ddea8375580fbd38bb8fa2e89317a 145940 libjasper1_1.900.1-7+squeeze4_i386.deb
 85ce0dfbd3df7415961a03b8f27f3543e3ecc84b 551340 libjasper-dev_1.900.1-7+squeeze4_i386.deb
 03609b3e519ed38cf1c9a28dfcaea888a5c68568 24162 libjasper-runtime_1.900.1-7+squeeze4_i386.deb
Checksums-Sha256: 
 d080a0ffd1cccb2323bed63fcf78cd5d262235e07f15eeff1e6b01c36f39cd55 1844 jasper_1.900.1-7+squeeze4.dsc
 6cf104e2811f6088ca1dc76d87dd27c55178d3ccced20db8858d28ae22911a94 1143400 jasper_1.900.1.orig.tar.gz
 9dd7b1bb053c718db3dda72f52afaf639e6c183b3953e515104f3413d88ab3e3 54228 jasper_1.900.1-7+squeeze4.diff.gz
 168e7a467e0ff035a81bd9c573a4d76088d9460da9f4e75a9789b3fea37864d6 145940 libjasper1_1.900.1-7+squeeze4_i386.deb
 578f96892bc2b85fb06030fbadf68c762c603bd7753f7cf3c35ffb40e6741412 551340 libjasper-dev_1.900.1-7+squeeze4_i386.deb
 2fef285147853a988650e7bf9e2c6f364a405f9279198c57eeac95d701478962 24162 libjasper-runtime_1.900.1-7+squeeze4_i386.deb
Files: 
 723dcee390db604c6c4ad3a7f1294ed8 1844 graphics optional jasper_1.900.1-7+squeeze4.dsc
 4ae3dd938fd15f22f30577db5c9f27e9 1143400 graphics optional jasper_1.900.1.orig.tar.gz
 e3338284fe5af40355e0234d24a0ec9d 54228 graphics optional jasper_1.900.1-7+squeeze4.diff.gz
 1df57f8b03bb6260d6f95bff9b25d524 145940 libs optional libjasper1_1.900.1-7+squeeze4_i386.deb
 ed414f0b072b17e52d23c4c5a70fa9bc 551340 libdevel optional libjasper-dev_1.900.1-7+squeeze4_i386.deb
 8b8fea6e008d61b15c63febc38ee7427 24162 graphics optional libjasper-runtime_1.900.1-7+squeeze4_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQJ8BAEBCgBmBQJUyAfMXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQ2MjAxRkJGRkRCQkRFMDc4MjJFQUJCOTY5
NkZDQUMwRDM4N0I1ODQ3AAoJEJb8rA04e1hHt4EP/303ypvFGQ3R7qDes4aVdfyn
O9kV8yC+cHiZzsxQWO9TOg1IqBExdjwD1uaWYgS3InOSqOfbptbomD+bxV25YQ+b
BNFPmNSjEVmvH//KcdiRL1ai1M1/GfLEBOgMpftMksy+787RYDJZfGqnESbCbTfS
fYLm8x1ESt82pB4f6jbnNQW4mdbwKBLxFSOaS4Cen/VvnuCGsbfWaCZklPG4hUIQ
RcRuZJHyjZ2kXepPEQUkWbhdbm8wTuN97FyGV39u7HV3pDoCz3n0tAdktF8AeHud
dQqDNBsDN/SlV36IUfqQeeOxBg3SDGHNhK7pn4gJ4GW7jbpoR32qZy0n/ozBAYmn
BQiiFQnYLHkynJOpApGkTXnQ/SEtuvNKCZK3G4dpMNO3PYxbJbGDfZ4AgOtX83YL
n7PFNFSbBwOJLXykfzKVJWRa/H02w35H0aG9veglGk7KGtQjTzxioKpox5ox65zj
cOK2y2bTE2W91pil7g46G9c05NucqOWVWicwWrsHM/hA3RZAcsdzYImEMhBDKpQE
P1L73VkEn4tPX+EWdFJu2GueZOArJqQly7dd89pQDRkbuZGTAhBg/lP/ZBdEN7Dd
B5seIt/hoNhcK7/PfKneHiWoHdTufHZVxM9Ey8ZIH4r0pmLlPSFhpHAXn0HtaGCJ
xpCPBCcj93TU+JNgOOM1
=l8sW
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 24 May 2015 07:59:13 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 15:35:36 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.