dpm: CVE-2011-4970

Related Vulnerabilities: CVE-2011-4970  

Debian Bug report logs - #702895
dpm: CVE-2011-4970

version graph

Package: dpm; Maintainer for dpm is Mattias Ellert <mattias.ellert@physics.uu.se>; Source for dpm is src:lcgdm (PTS, buildd, popcon).

Reported by: Moritz Muehlenhoff <jmm@inutil.org>

Date: Tue, 12 Mar 2013 16:15:01 UTC

Severity: important

Tags: security

Fixed in version lcgdm/1.8.6-1

Done: Mattias Ellert <mattias.ellert@fysast.uu.se>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Mattias Ellert <mattias.ellert@fysast.uu.se>:
Bug#702895; Package dpm. (Tue, 12 Mar 2013 16:15:04 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@inutil.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Mattias Ellert <mattias.ellert@fysast.uu.se>. (Tue, 12 Mar 2013 16:15:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@inutil.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: dpm: CVE-2011-4970
Date: Tue, 12 Mar 2013 17:11:07 +0100
Package: dpm
Severity: important
Tags: security

This has been assigned CVE-2011-4970:
https://wiki.egi.eu/wiki/SVG:Advisory-SVG-2012-2683

Cheers,
        Moritz



Reply sent to Mattias Ellert <mattias.ellert@fysast.uu.se>:
You have taken responsibility. (Sat, 20 Apr 2013 21:36:08 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@inutil.org>:
Bug acknowledged by developer. (Sat, 20 Apr 2013 21:36:08 GMT) (full text, mbox, link).


Message #10 received at 702895-close@bugs.debian.org (full text, mbox, reply):

From: Mattias Ellert <mattias.ellert@fysast.uu.se>
To: 702895-close@bugs.debian.org
Subject: Bug#702895: fixed in lcgdm 1.8.6-1
Date: Sat, 20 Apr 2013 21:33:08 +0000
Source: lcgdm
Source-Version: 1.8.6-1

We believe that the bug you reported is fixed in the latest version of
lcgdm, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 702895@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Mattias Ellert <mattias.ellert@fysast.uu.se> (supplier of updated lcgdm package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sat, 16 Mar 2013 07:31:43 +0100
Source: lcgdm
Binary: liblcgdm1 liblcgdm-dev liblfc1 liblfc-dev lfc liblfc-perl python-lfc lfc-server-mysql lfc-server-postgres lfc-dli libdpm1 libdpm-dev dpm libdpm-perl python-dpm dpm-server-mysql dpm-server-postgres dpm-name-server-mysql dpm-name-server-postgres dpm-copy-server-mysql dpm-copy-server-postgres dpm-srm-server-mysql dpm-srm-server-postgres dpm-rfio-server lcgdm-dbg
Architecture: source amd64
Version: 1.8.6-1
Distribution: unstable
Urgency: low
Maintainer: Mattias Ellert <mattias.ellert@fysast.uu.se>
Changed-By: Mattias Ellert <mattias.ellert@fysast.uu.se>
Description: 
 dpm        - Disk Pool Manager (DPM) client
 dpm-copy-server-mysql - DPM copy server with MySQL database backend
 dpm-copy-server-postgres - DPM copy server with postgres database backend
 dpm-name-server-mysql - DPM nameserver server with MySQL database backend
 dpm-name-server-postgres - DPM nameserver server with postgres database backend
 dpm-rfio-server - DPM RFIO server
 dpm-server-mysql - Disk Pool Manager (DPM) server with MySQL database backend
 dpm-server-postgres - Disk Pool Manager (DPM) server with postgres database backend
 dpm-srm-server-mysql - DPM SRM server with MySQL database backend
 dpm-srm-server-postgres - DPM SRM server with postgres database backend
 lcgdm-dbg  - LHC Computing Grid debuggng symbols
 lfc        - LCG File Catalog (LFC) client
 lfc-dli    - LCG File Catalog (LFC) data location interface (dli) server
 lfc-server-mysql - LCG File Catalog (LFC) server with MySQL database backend
 lfc-server-postgres - LCG File Catalog (LFC) server with postgres database backend
 libdpm-dev - DPM development libraries and header files
 libdpm-perl - Disk Pool Manager (DPM) perl bindings
 libdpm1    - Disk Pool Manager (DPM) libraries
 liblcgdm-dev - LCG Data Management common development files
 liblcgdm1  - LHC Computing Grid Data Management common libraries
 liblfc-dev - LFC development libraries and header files
 liblfc-perl - LCG File Catalog (LFC) perl bindings
 liblfc1    - LCG File Catalog (LFC) libraries
 python-dpm - Disk Pool Manager (DPM) python bindings
 python-lfc - LCG File Catalog (LFC) python bindings
Closes: 702895
Changes: 
 lcgdm (1.8.6-1) unstable; urgency=low
 .
   * Update to version 1.8.6 (Closes: #702895)
Checksums-Sha1: 
 423bb08b6ac15ae51337f6cbd40694691302d5ee 3410 lcgdm_1.8.6-1.dsc
 91e957e05150bc71c05545803b0c07759d14a223 2082220 lcgdm_1.8.6.orig.tar.gz
 098484f045e7d872d5f00ea8dd4cf31aff6aa826 28163 lcgdm_1.8.6-1.debian.tar.gz
 93afce631300fa2cc41723c0e7510331c312ee16 100530 liblcgdm1_1.8.6-1_amd64.deb
 124baa6428a1bb5c5b6a5bda8fdec271cc915d74 140144 liblcgdm-dev_1.8.6-1_amd64.deb
 208d7f30ac0315d62b9dc07bea6e476c57ee5701 41590 liblfc1_1.8.6-1_amd64.deb
 d7411f37563fb8cc2a628d68bfabc67426d8d6ac 176290 liblfc-dev_1.8.6-1_amd64.deb
 42fc5579f111a6dc6e684325b6dc848665e55fcd 75518 lfc_1.8.6-1_amd64.deb
 2faa445d0a5d4340458ecc86b83334030062f339 149314 liblfc-perl_1.8.6-1_amd64.deb
 87c59ad1d32d909939f0dc5a05ea12ae266fe46b 366474 python-lfc_1.8.6-1_amd64.deb
 e9b313d7f34526aa39f861f5aaf0a28a4dc31983 109804 lfc-server-mysql_1.8.6-1_amd64.deb
 0f345fb52df8c87b401f4ba3e906727c587abd5d 109564 lfc-server-postgres_1.8.6-1_amd64.deb
 b8d4457a4e8dcfb023fea0cc7b58c69e30c14578 27090 lfc-dli_1.8.6-1_amd64.deb
 b78824492c1d2f1480019365685cf600ad80b081 155892 libdpm1_1.8.6-1_amd64.deb
 5e6793a8234fb3bc667ee2d868d5c927807ccde3 417956 libdpm-dev_1.8.6-1_amd64.deb
 9683c7370428d39065f88862471dcb2b1b62eeec 146354 dpm_1.8.6-1_amd64.deb
 5b8c4a9a92224891b4356f47e16ce50e2eff3d87 205450 libdpm-perl_1.8.6-1_amd64.deb
 b1bc500c68ccdbd0833b081a318e92137e2751f3 262006 python-dpm_1.8.6-1_amd64.deb
 adb95bb0cd804af54faf6351496169a957a3d78c 109966 dpm-server-mysql_1.8.6-1_amd64.deb
 d325e4fd98fac4c1793f222432cf4c7d0e304136 108602 dpm-server-postgres_1.8.6-1_amd64.deb
 cff6f6c1b27014b5ba98f0b508aa2a20e54f5e35 109876 dpm-name-server-mysql_1.8.6-1_amd64.deb
 448351c55e66b1ae0301a7109c03e9adb16c3610 109694 dpm-name-server-postgres_1.8.6-1_amd64.deb
 bfe0cd7fe10af0631875a4a79ea44a7af60d6615 166790 dpm-copy-server-mysql_1.8.6-1_amd64.deb
 09ba3b3d0cda8d9eb22077fd5eccf887d3775a00 165686 dpm-copy-server-postgres_1.8.6-1_amd64.deb
 56b67230d39d432ec19ec413f96d43fb1068d819 410390 dpm-srm-server-mysql_1.8.6-1_amd64.deb
 8a4ae1d2ec09e131ecb1f4c3e39725cc92bb4440 406798 dpm-srm-server-postgres_1.8.6-1_amd64.deb
 e9e5b9f849d922ecc83c65f7a7a27af8780ff502 84774 dpm-rfio-server_1.8.6-1_amd64.deb
 0fdd60c42e6356a01a1fb20a8b05aeb7a217ae91 10328514 lcgdm-dbg_1.8.6-1_amd64.deb
Checksums-Sha256: 
 b054f2c4a74b335f4d1b21746db7f090f409eeea5e455d6559a7a02ff69042aa 3410 lcgdm_1.8.6-1.dsc
 ff1e0c14a803ef9accd9953639a3e47eb431850fe1f574d0802410d99515f349 2082220 lcgdm_1.8.6.orig.tar.gz
 e56a56411f91163150a2c7c4ed6e2aa335eb214969e26d89e575dae8d8257ddd 28163 lcgdm_1.8.6-1.debian.tar.gz
 8e547bbe3f308a6b66c7a993fa438b0aec75652427e64c3f4003d15f991e2ba0 100530 liblcgdm1_1.8.6-1_amd64.deb
 88ec894d26bdc6050b3017eabfe2ae21f19a572b00febdff787cf080d6ccc3ea 140144 liblcgdm-dev_1.8.6-1_amd64.deb
 2666c26d5636b7ad0b6838b2ec66abdd68f42c6ff6e4cc56080b909c084901c8 41590 liblfc1_1.8.6-1_amd64.deb
 5f0612bbe28fad940049226b12871546e9aaa3385c9af8f074b79cfc9cf24969 176290 liblfc-dev_1.8.6-1_amd64.deb
 c7f560b32e35ad61e43b0c24fde5e62dfc4f17b5107ba791532a9b248e3edf04 75518 lfc_1.8.6-1_amd64.deb
 134317b3059ebfbca1a934c72bb16327bbf397feb206e429582b3d81e1786940 149314 liblfc-perl_1.8.6-1_amd64.deb
 69ef54ceac86d4867e658159d8ed4fee321afe81ed0fe31283b5bde1775307db 366474 python-lfc_1.8.6-1_amd64.deb
 7345ecae1fe3693ed8272cda2b4b7e35573ed201efd51a758aac30c7a4eb13e0 109804 lfc-server-mysql_1.8.6-1_amd64.deb
 d7cc8cff098ba071c53a64c8e466ee2b0aafe6520c302c3f85d55f204da6f49a 109564 lfc-server-postgres_1.8.6-1_amd64.deb
 4d56398f14b4814b2e40eb37990cf7826e643ee36894aef347b4f40ec49c3c1f 27090 lfc-dli_1.8.6-1_amd64.deb
 3ca1a2a56b88c7c3212efd55f8337d7a4b4c005e2ac68ca4298fc17532a04ea0 155892 libdpm1_1.8.6-1_amd64.deb
 2a15355ad5d4b34063aed101bf3c2ebb7e13b8c297d0bdf0df36db1c44ffcdfc 417956 libdpm-dev_1.8.6-1_amd64.deb
 ecbef97d6336d42d54582a26c86606ba2d6cc01073daa357091ae4326c9fee88 146354 dpm_1.8.6-1_amd64.deb
 773a993e8180949b003a860196ba6af6518e8c6bea6688884f5e8f4437c72b95 205450 libdpm-perl_1.8.6-1_amd64.deb
 36ea388e082af7779f701ce01a78204529d8cd25f4b4f8dd78d2cdbe8e023476 262006 python-dpm_1.8.6-1_amd64.deb
 fe040c4a5bcf85634fa0054eeed59018bde32a3a6b666c5cf28d1cf80fccf539 109966 dpm-server-mysql_1.8.6-1_amd64.deb
 f697a695fbf8fe6d907bcfa8c19e74970be46e21d4cae2150879bc3c74dd5867 108602 dpm-server-postgres_1.8.6-1_amd64.deb
 f6047da851650c02010d9541d97acf1973862a2d7a9d907a1ec4ba5d28de940c 109876 dpm-name-server-mysql_1.8.6-1_amd64.deb
 00f2267263e1cf5a7e5355c6bb698ecdc243a990ececba0581662a193ccc902a 109694 dpm-name-server-postgres_1.8.6-1_amd64.deb
 92c62a7c3977a2731bb7c2d9dc73fb0cd97132c1707dfd81740050cc92445f4b 166790 dpm-copy-server-mysql_1.8.6-1_amd64.deb
 5079c8fc9aa9e795a775970ad22795a07cb88630f0d7127c409a0df7a3a25bed 165686 dpm-copy-server-postgres_1.8.6-1_amd64.deb
 00e81d32ea060f46b93d0fb40c85fd1272187640e8bd676b2c31fe77251c945f 410390 dpm-srm-server-mysql_1.8.6-1_amd64.deb
 2f385d93121fa617b17f692fcc65b4dcd315a826db1acde64c49681825db3e08 406798 dpm-srm-server-postgres_1.8.6-1_amd64.deb
 29d41410d7966e1cf0318373bda6954ff51dd7810713c3f5c7c66862ba3ae17a 84774 dpm-rfio-server_1.8.6-1_amd64.deb
 1185e1bfa72cc9e5ad850ff2c33c69df201ff864f1ce6a5736bb6f7343644145 10328514 lcgdm-dbg_1.8.6-1_amd64.deb
Files: 
 0fe81b263afe7432baac3ff62b42ff97 3410 net optional lcgdm_1.8.6-1.dsc
 a5e6d5693d1fd01aac5366bac6c6858c 2082220 net optional lcgdm_1.8.6.orig.tar.gz
 dbd1f815a8865aa9093ce4c1405549b4 28163 net optional lcgdm_1.8.6-1.debian.tar.gz
 7756e1f6f70af7fd10f812444e60310f 100530 libs optional liblcgdm1_1.8.6-1_amd64.deb
 54dc30ddf3540364a8ae5734b0483750 140144 libdevel optional liblcgdm-dev_1.8.6-1_amd64.deb
 b1ed72ee0f6e6a47bcbea41572e20e97 41590 libs optional liblfc1_1.8.6-1_amd64.deb
 75a83e1da439b7af3036948adb18b65c 176290 libdevel optional liblfc-dev_1.8.6-1_amd64.deb
 c86976331a73086e12146b17da798556 75518 net optional lfc_1.8.6-1_amd64.deb
 93d281e3a5c543c21ab41490f0478b3e 149314 perl optional liblfc-perl_1.8.6-1_amd64.deb
 1bf21d8828afe81f7d94f10f7bf75824 366474 python optional python-lfc_1.8.6-1_amd64.deb
 ab3f6024183e74d70ec59c8326eecadd 109804 net optional lfc-server-mysql_1.8.6-1_amd64.deb
 2ea6124968b8e0212da8c8588d7b8124 109564 net optional lfc-server-postgres_1.8.6-1_amd64.deb
 7d175726fada77615ea2c97628e35d78 27090 net optional lfc-dli_1.8.6-1_amd64.deb
 9e964a4fea221f7ec2a6fe9b442ae61a 155892 libs optional libdpm1_1.8.6-1_amd64.deb
 66a525e3ad3381b9b31318adc638a6e9 417956 libdevel optional libdpm-dev_1.8.6-1_amd64.deb
 b5a6a68610a7314ee35266a70c39e258 146354 net optional dpm_1.8.6-1_amd64.deb
 3c26c08f5918ce7107d4d11bca0ddcdd 205450 perl optional libdpm-perl_1.8.6-1_amd64.deb
 42310d8633d0692fadb1864f9ceca322 262006 python optional python-dpm_1.8.6-1_amd64.deb
 00c7cde9adbb1f0996065b91a1dd76ef 109966 net optional dpm-server-mysql_1.8.6-1_amd64.deb
 9d3e2cd71e19db674b8a04008417e282 108602 net optional dpm-server-postgres_1.8.6-1_amd64.deb
 901c5c999a7b75c40fc54ff848878608 109876 net optional dpm-name-server-mysql_1.8.6-1_amd64.deb
 2ecd07f00be8cbfe132a7bb58483c561 109694 net optional dpm-name-server-postgres_1.8.6-1_amd64.deb
 e3988da14bb34caf5ac51f0595ff44b6 166790 net optional dpm-copy-server-mysql_1.8.6-1_amd64.deb
 070a449de08478b3ea54a5ee9a3ad790 165686 net optional dpm-copy-server-postgres_1.8.6-1_amd64.deb
 94be4538ac7bed0cec10cc374076db00 410390 net optional dpm-srm-server-mysql_1.8.6-1_amd64.deb
 940ff4f91d4127e51cdf1d688e13498d 406798 net optional dpm-srm-server-postgres_1.8.6-1_amd64.deb
 79479e4c058ec1a46c69dccd47bcef82 84774 net optional dpm-rfio-server_1.8.6-1_amd64.deb
 d03c099eb40bde438ed0ad7b630abc81 10328514 debug extra lcgdm-dbg_1.8.6-1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBAgAGBQJRcwibAAoJEOiuwv874alLx9AP/36SZGE0a/kIJx02+bDaWpDP
ZaMH6bFvoW4y4312mN8ij9fXA5KPVvRazSc1k1aUlBWRZXw1fFtxlm7UErJCDxpR
y1knJchx5HlJoZ36FHm23Matrq2unTURWRFYF0GTVCq2QMoV06av2/Yq1Bz7LIB0
oo7UaZEopkgWntwV5ySWPEjB2GvZ15FOTTrZr+NqZZXVePym/NfXPqZoZTFnI01x
BaZzNtuAX5y/ghD/4y4IPOnRbIxgsAWqKfuC/axgj8Erpjlz0R2CCJScDKifkP6K
UKG6ZTOiDOljNiWp1dDFv8KyLVrM4h7rZCFIlgXgMh0pvPciO5LOSyAB/NQWz9s0
u3kzw7U0kZd1lJgyJWJkqkJmMSlXeO26xAgGFotgi4xgOLl34TqJD84PPCL5n1Lt
L8SwATmJ2ZiurDvQ0cB/iOF/nBZAhOdeLtpaLecSXcCMe0j/0yN3ZFuG2p0FY6XF
D0e6731dQn9qojYzc2OOzgFnYYZoGzJ4YS6jR3+6hykvGYBF/MOD54smNismMHyH
jJx0CBiGhl643F6m0HBAEv292aN7BVsK2aiopTE3ls9e7c6UHjZSs5du3/T+vysp
wM3ZnGjad2XjpC03OKD0MOqvnW9/lGLtAqA8XIYOfX6UoIWkN6tXB0bSfXd+59jq
i30S8+NR1l1bW980PrA4
=S0FM
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 19 May 2013 07:30:14 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 18:19:52 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.