CVE-2016-3100

Related Vulnerabilities: CVE-2016-3100  

Debian Bug report logs - #827476
CVE-2016-3100

version graph

Reported by: Moritz Muehlenhoff <jmm@debian.org>

Date: Thu, 16 Jun 2016 17:54:02 UTC

Severity: grave

Tags: security

Found in version kinit/5.22.0-1

Fixed in version kinit/5.23.0-1

Done: Maximiliano Curia <maxy@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian/Kubuntu Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>:
Bug#827476; Package kinit. (Thu, 16 Jun 2016 17:54:06 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian/Kubuntu Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>. (Thu, 16 Jun 2016 17:54:06 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2016-3100
Date: Thu, 16 Jun 2016 19:49:50 +0200
Package: kinit
Version: 5.22.0-1
Severity: grave
Tags: security

Hi,
please see
https://bugs.kde.org/show_bug.cgi?id=358593
https://bugs.kde.org/show_bug.cgi?id=363140
https://quickgit.kde.org/?p=kinit.git&a=commitdiff&h=dece8fd89979cd1a86c03bcaceef6e9221e8d8cd
https://quickgit.kde.org/?p=kinit.git&a=commitdiff&h=72f3702dbe6cf15c06dc13da2c99c864e9022a58

Cheers,
        Moritz
                                



Reply sent to Maximiliano Curia <maxy@debian.org>:
You have taken responsibility. (Wed, 22 Jun 2016 16:45:04 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@debian.org>:
Bug acknowledged by developer. (Wed, 22 Jun 2016 16:45:05 GMT) (full text, mbox, link).


Message #10 received at 827476-close@bugs.debian.org (full text, mbox, reply):

From: Maximiliano Curia <maxy@debian.org>
To: 827476-close@bugs.debian.org
Subject: Bug#827476: fixed in kinit 5.23.0-1
Date: Wed, 22 Jun 2016 16:41:55 +0000
Source: kinit
Source-Version: 5.23.0-1

We believe that the bug you reported is fixed in the latest version of
kinit, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 827476@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Maximiliano Curia <maxy@debian.org> (supplier of updated kinit package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 22 Jun 2016 17:49:13 +0200
Source: kinit
Binary: kinit-dev kinit
Architecture: source
Version: 5.23.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian/Kubuntu Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>
Changed-By: Maximiliano Curia <maxy@debian.org>
Description:
 kinit      - process launcher to speed up launching KDE applications
 kinit-dev  - process launcher to speed up launching KDE applications
Closes: 827476
Changes:
 kinit (5.23.0-1) unstable; urgency=medium
 .
   [ Automatic packaging ]
   * Update build-deps and deps with the info from cmake
   * New upstream release. (Closes: 827476) Thanks to Moritz Muehlenhoff for
     reporting.
Checksums-Sha1:
 382fece0e269c81498beab553fcda839d7b1960a 2317 kinit_5.23.0-1.dsc
 23f6634b8bd96c2324cd51d7ca3923c2107011a4 117812 kinit_5.23.0.orig.tar.xz
 4266025b5f20d02b0d42f67e2f05840b936fcefd 5224 kinit_5.23.0-1.debian.tar.xz
Checksums-Sha256:
 71ded61fbda38c7f72c4119b53f66943f061e4f796dd994e349bffbd67cd51e1 2317 kinit_5.23.0-1.dsc
 c3d2e5fc2fa71e6d1d2cca2e5654f90cbe4d4dd5607898365e062d4471a48f7d 117812 kinit_5.23.0.orig.tar.xz
 4d2929b716d958d05d3f5015052c12f3da92f771d932e9419eaf53115c510edc 5224 kinit_5.23.0-1.debian.tar.xz
Files:
 1933db961715dfda75886b4d0c8e5e7a 2317 libs optional kinit_5.23.0-1.dsc
 4072959e05d8a561fca95919fc8fad18 117812 libs optional kinit_5.23.0.orig.tar.xz
 950619879073d6025ca0aad65a4334b3 5224 libs optional kinit_5.23.0-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJXarRgAAoJEMcZdpmymyMqXtAP/RgoEr9RiApBCjwVibvdNbaH
SIIny00MLdshwWyIQ0D0pgmsT1vcTn9J1BQOVoMcTFcBe+v68FTtDevnrnjPCIns
PYsxHDyzDrqRpFLme8rbHR/HZ0nruOGBGxXiGHcXeWsZky39d9zuhPBHpQdvamPv
2IMjV7xodOq+Sx+VbiZ7p4RkLUOt0jXJqxb5NPz8fs+EDCp0bJLcAVc+C1vbtJPA
n2QfRWG7rNpluT8jnfW8mNQ0+NHqTtDuDkpGRHObHqDJ7M5FXHAwQaguQuMOQah4
Rd3pxu3NwUs7VnpormBgoZduP+kayt1YmpfZgMFOY76pO64TWZ5NMoB7CN0WQHMJ
6IjvS8tGbvEE4jQR5tDVn2mCDiXywGHjQhCukcU+CaZK6u7/1rwpRJAtFdiBbOPX
1BIxLf+AmSxZxfAlloGdsakAmyJHJZTUPh7oA754Jfz5YoD/hr2KMz9hP1CqdUfR
q4PjbOmjX6IY1yVfE9qWLAxlwgPVGJfgwAMqj89shz6P0OswkSZWIOVs9pWRbbgv
gt61QxcAeAnMtYXyC99R5W95RRDbx/DOEIOr9bkKLdLIj1Y9NSLMMC+b6OSrCj+i
CFhAfEhKOVYVSPIDA3sojDcRY6ffL2HtzbzyLCWW1WghYWTp3FC4ZVag06NslBdu
8VOwGb8+scnrlYpOgijE
=Oenz
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 05 Dec 2016 10:54:21 GMT) (full text, mbox, link).


Bug unarchived. Request was from Don Armstrong <don@debian.org> to control@bugs.debian.org. (Wed, 07 Dec 2016 01:49:26 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 14 Aug 2017 07:27:31 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 15:59:16 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.