mumble: Mumble database is world-readable

Related Vulnerabilities: CVE-2012-0863  

Debian Bug report logs - #659039
mumble: Mumble database is world-readable

version graph

Reported by: Marc Deslauriers <marc.deslauriers@ubuntu.com>

Date: Tue, 7 Feb 2012 16:21:01 UTC

Severity: normal

Tags: patch, security

Found in version mumble/1.2.3-2

Fixed in versions mumble/1.2.3-277-g98f4ac1-1, mumble/1.2.3-3, mumble/1.2.2-6+squeeze1

Done: Patrick Matthäi <pmatthaei@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian VoIP Team <pkg-voip-maintainers@lists.alioth.debian.org>:
Bug#659039; Package mumble. (Tue, 07 Feb 2012 16:21:05 GMT) (full text, mbox, link).


Acknowledgement sent to Marc Deslauriers <marc.deslauriers@ubuntu.com>:
New Bug report received and forwarded. Copy sent to Debian VoIP Team <pkg-voip-maintainers@lists.alioth.debian.org>. (Tue, 07 Feb 2012 16:21:05 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Marc Deslauriers <marc.deslauriers@ubuntu.com>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: mumble: Mumble database is world-readable
Date: Tue, 07 Feb 2012 11:20:00 -0500
[Message part 1 (text/plain, inline)]
Package: mumble
Version: 1.2.3-2
Severity: normal
Tags: patch
User: ubuntu-devel@lists.ubuntu.com
Usertags: origin-ubuntu precise ubuntu-patch



*** /tmp/tmpbbtG6M/bug_body
By default, Mumble creates it's config file and database with
world-readable permissions. The database may contain passwords.

In Ubuntu, the attached patch was applied to achieve the following:

  * debian/patches/0004-set-file-permissions.patch: Set restrictive
    permissions on data files. (LP: #783405)


Thanks for considering the patch.


-- System Information:
Debian Release: wheezy/sid
  APT prefers precise-updates
  APT policy: (500, 'precise-updates'), (500, 'precise-security'), (500, 'precise-proposed'), (500, 'precise')
Architecture: amd64 (x86_64)

Kernel: Linux 3.2.0-12-generic (SMP w/4 CPU cores)
Locale: LANG=en_CA.UTF-8, LC_CTYPE=en_CA.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
[mumble_1.2.3-2ubuntu3.debdiff (text/x-diff, attachment)]

Added tag(s) pending. Request was from Patrick Matthäi <pmatthaei@debian.org> to control@bugs.debian.org. (Sun, 12 Feb 2012 11:27:13 GMT) (full text, mbox, link).


Reply sent to Patrick Matthäi <pmatthaei@debian.org>:
You have taken responsibility. (Sun, 12 Feb 2012 16:51:14 GMT) (full text, mbox, link).


Notification sent to Marc Deslauriers <marc.deslauriers@ubuntu.com>:
Bug acknowledged by developer. (Sun, 12 Feb 2012 16:51:14 GMT) (full text, mbox, link).


Message #12 received at 659039-close@bugs.debian.org (full text, mbox, reply):

From: Patrick Matthäi <pmatthaei@debian.org>
To: 659039-close@bugs.debian.org
Subject: Bug#659039: fixed in mumble 1.2.3-277-g98f4ac1-1
Date: Sun, 12 Feb 2012 16:50:26 +0000
Source: mumble
Source-Version: 1.2.3-277-g98f4ac1-1

We believe that the bug you reported is fixed in the latest version of
mumble, which is due to be installed in the Debian FTP archive:

mumble-dbg_1.2.3-277-g98f4ac1-1_amd64.deb
  to main/m/mumble/mumble-dbg_1.2.3-277-g98f4ac1-1_amd64.deb
mumble-server-web_1.2.3-277-g98f4ac1-1_all.deb
  to main/m/mumble/mumble-server-web_1.2.3-277-g98f4ac1-1_all.deb
mumble-server_1.2.3-277-g98f4ac1-1_amd64.deb
  to main/m/mumble/mumble-server_1.2.3-277-g98f4ac1-1_amd64.deb
mumble_1.2.3-277-g98f4ac1-1.debian.tar.gz
  to main/m/mumble/mumble_1.2.3-277-g98f4ac1-1.debian.tar.gz
mumble_1.2.3-277-g98f4ac1-1.dsc
  to main/m/mumble/mumble_1.2.3-277-g98f4ac1-1.dsc
mumble_1.2.3-277-g98f4ac1-1_amd64.deb
  to main/m/mumble/mumble_1.2.3-277-g98f4ac1-1_amd64.deb
mumble_1.2.3-277-g98f4ac1.orig.tar.gz
  to main/m/mumble/mumble_1.2.3-277-g98f4ac1.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 659039@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Patrick Matthäi <pmatthaei@debian.org> (supplier of updated mumble package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sun, 12 Feb 2012 16:43:52 +0100
Source: mumble
Binary: mumble mumble-server mumble-dbg mumble-server-web
Architecture: source all amd64
Version: 1.2.3-277-g98f4ac1-1
Distribution: experimental
Urgency: low
Maintainer: Debian VoIP Team <pkg-voip-maintainers@lists.alioth.debian.org>
Changed-By: Patrick Matthäi <pmatthaei@debian.org>
Description: 
 mumble     - Low latency VoIP client
 mumble-dbg - Low latency VoIP client (debugging symbols)
 mumble-server - Low latency VoIP server
 mumble-server-web - Web scripts for mumble-server
Closes: 627139 657632 659035 659039
Changes: 
 mumble (1.2.3-277-g98f4ac1-1) experimental; urgency=low
 .
   * New upstream snapshot from 12.02.2012.
     - Refresh patch 01-fix-spelling-error.
     - Word readable file permissions on mumble database are fixed in this
       snapshot.
       Closes: #659039
   * Add Dutch debconf translation.
     Closes: #657632
   * Add patch 02-reject-with-ip-in-log to show up the IP address of a rejected
     connection in the mumble-server log.
     Closes: #627139
   * Add patch 03-fix-cert-validation from Marc Deslauriers, which fixes the
     certificate validation with Qt 4.8.
     Closes: #659035
   * Add patch 05-lsb-description which fixes the lintian warning
     init.d-script-missing-lsb-description.
Checksums-Sha1: 
 6dbe618ee66fc66ef10c56b819f4b986f470a403 2896 mumble_1.2.3-277-g98f4ac1-1.dsc
 ac4649d2c0d606c110f9b548f62aa055fca47a95 3287593 mumble_1.2.3-277-g98f4ac1.orig.tar.gz
 a0728fa77222dd816c4fbfb500a13b89ab3f9a9c 31024 mumble_1.2.3-277-g98f4ac1-1.debian.tar.gz
 1738aa95094408ff81e2a91e35a5ba85531735e7 122242 mumble-server-web_1.2.3-277-g98f4ac1-1_all.deb
 7ad74183faad2cf60e15f65107fcf4a6d1873ffb 2846448 mumble_1.2.3-277-g98f4ac1-1_amd64.deb
 d8670726d7c11146d39d961163e8e2ee8a69378e 956276 mumble-server_1.2.3-277-g98f4ac1-1_amd64.deb
 7f9d3ea3e70e420ca729c55fcec2e8ae2c35de13 28297966 mumble-dbg_1.2.3-277-g98f4ac1-1_amd64.deb
Checksums-Sha256: 
 b74b8ae6201c88b870e38d98c979d605084fa447350f4d4e1796aabcaa4110f9 2896 mumble_1.2.3-277-g98f4ac1-1.dsc
 905bf0ed5dbe593c90e806fe8cb6d6071da0f92cbaaaa12617f73c7394b96e8e 3287593 mumble_1.2.3-277-g98f4ac1.orig.tar.gz
 8cd8d0ec84d03665575a0af7d8c0e279d1741338fedc6c3af97052a2b8b8f1a8 31024 mumble_1.2.3-277-g98f4ac1-1.debian.tar.gz
 5dcbcbb8ad193d800d17357d321f3af840c666f0b6bc0f6fac5b73b0eb502274 122242 mumble-server-web_1.2.3-277-g98f4ac1-1_all.deb
 13ecf2038626fabfd4f03d7cd21f2908a24fc66244535744103b9670b8fd809c 2846448 mumble_1.2.3-277-g98f4ac1-1_amd64.deb
 009bf42177c84ba2350642e306da802c00cc04053d34d1ea03da8e8f097a7695 956276 mumble-server_1.2.3-277-g98f4ac1-1_amd64.deb
 5ee4db587b507436ec03b5fb9a42bece7e0ba6a9fbe98478921f368785d1d889 28297966 mumble-dbg_1.2.3-277-g98f4ac1-1_amd64.deb
Files: 
 b565309f257b385d586c2f53dceec60f 2896 sound optional mumble_1.2.3-277-g98f4ac1-1.dsc
 bf7579ee5dc02e0df17d598547859b72 3287593 sound optional mumble_1.2.3-277-g98f4ac1.orig.tar.gz
 38867b991562225164bcf9ccf7b15314 31024 sound optional mumble_1.2.3-277-g98f4ac1-1.debian.tar.gz
 d28c52029ae15213effd69e74a559578 122242 sound optional mumble-server-web_1.2.3-277-g98f4ac1-1_all.deb
 dd0ad8e4cb88bc0e0002a2057deaf109 2846448 sound optional mumble_1.2.3-277-g98f4ac1-1_amd64.deb
 4b2f900f19a6b89ea765c7e36aeb6164 956276 sound optional mumble-server_1.2.3-277-g98f4ac1-1_amd64.deb
 913431ba295767007bbfa3c3d2db4545 28297966 debug extra mumble-dbg_1.2.3-277-g98f4ac1-1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAEBCAAGBQJPN+e9AAoJEBLZsEqQy9jk6FoP/31BT72rp3QJPdw2yBmDg2wX
TLomd1MpZH3CH5p7qZrFQkpUOePEIho7YrcqIY3jc48KDYFYGI18HR3ddlRVD3HR
3aL+AVy+HLzA6hSvyquhMiVFxL37WVETmSiNM5SOm8x8Fcg5+SaKbpUH8pg5EBuh
XMMxWhd8Cw6w+9nU6FaLMxn51zzDDkcP8Akc+DhFzEypLctuDrzCN8cGFmef42Ci
wPBA4zpGwaDjrTwvcsKWdCCd7NzMthc6M1f+1gYyMCQsIgxbgTV76yOfACuEPXRy
CR+kPlI9n8uLMK0jcH7IFjuk+1cE6Wf3vZeMd/99Xpj4s4UHIFLrxCBYrteDeLVP
3YH/gZ8SsId42Oapmy/Ti07eNEfiOG97uwWlfH7luyRt7PbneIYLJyyjuf326Ug1
VXl5rlVVbDSfmRG4NHMYfB0L3LuBLlqAMA8tWfj85ApjMW3F0xxO9JA/ROIRF8QF
mkSXLN5l+dZz3dtXshO8j+Dt6pIDn4bczv1W53oJ8iKDtExxLenvFyuQCWkWpHnz
KvD5++vcmx3dJY+n/+Sn/TfJGB95ZGnZIzH/WVq6nGVXSI4ve4418JLqOvuSVfAW
uiDavW2gx5Ibab4YFpVD+EW/Rft9nGOD60+rCiDpOL9HqzH+28TI03BKo4JyxSqp
DPUq14TuY+EjvtaG2Uhc
=XgPU
-----END PGP SIGNATURE-----





Reply sent to Patrick Matthäi <pmatthaei@debian.org>:
You have taken responsibility. (Sun, 12 Feb 2012 17:06:11 GMT) (full text, mbox, link).


Notification sent to Marc Deslauriers <marc.deslauriers@ubuntu.com>:
Bug acknowledged by developer. (Sun, 12 Feb 2012 17:06:11 GMT) (full text, mbox, link).


Message #17 received at 659039-close@bugs.debian.org (full text, mbox, reply):

From: Patrick Matthäi <pmatthaei@debian.org>
To: 659039-close@bugs.debian.org
Subject: Bug#659039: fixed in mumble 1.2.3-3
Date: Sun, 12 Feb 2012 17:03:36 +0000
Source: mumble
Source-Version: 1.2.3-3

We believe that the bug you reported is fixed in the latest version of
mumble, which is due to be installed in the Debian FTP archive:

mumble-11x_1.2.3-3_amd64.deb
  to main/m/mumble/mumble-11x_1.2.3-3_amd64.deb
mumble-dbg_1.2.3-3_amd64.deb
  to main/m/mumble/mumble-dbg_1.2.3-3_amd64.deb
mumble-server-web_1.2.3-3_all.deb
  to main/m/mumble/mumble-server-web_1.2.3-3_all.deb
mumble-server_1.2.3-3_amd64.deb
  to main/m/mumble/mumble-server_1.2.3-3_amd64.deb
mumble_1.2.3-3.debian.tar.gz
  to main/m/mumble/mumble_1.2.3-3.debian.tar.gz
mumble_1.2.3-3.dsc
  to main/m/mumble/mumble_1.2.3-3.dsc
mumble_1.2.3-3_amd64.deb
  to main/m/mumble/mumble_1.2.3-3_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 659039@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Patrick Matthäi <pmatthaei@debian.org> (supplier of updated mumble package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sun, 12 Feb 2012 17:09:07 +0100
Source: mumble
Binary: mumble mumble-11x mumble-server mumble-dbg mumble-server-web
Architecture: source all amd64
Version: 1.2.3-3
Distribution: unstable
Urgency: high
Maintainer: Debian VoIP Team <pkg-voip-maintainers@lists.alioth.debian.org>
Changed-By: Patrick Matthäi <pmatthaei@debian.org>
Description: 
 mumble     - Low latency VoIP client
 mumble-11x - Low latency VoIP client (1.1.x)
 mumble-dbg - Low latency VoIP client (debugging symbols)
 mumble-server - Low latency VoIP server
 mumble-server-web - Web scripts for mumble-server
Closes: 627139 657632 659039
Changes: 
 mumble (1.2.3-3) unstable; urgency=high
 .
   * Add Dutch debconf translation.
     Closes: #657632
   * Add patch 01-fix-spelling-error.diff to fix an minor spelling error in
     the source code.
   * Add patch 05-lsb-description which fixes the lintian warning
     init.d-script-missing-lsb-description.
   * Add patch 02-reject-with-ip-in-log to show up the IP address of a rejected
     connection in the mumble-server log.
     Closes: #627139
   * Add patch 04-set-file-permissions from Marc Deslauriers, which fixes the
     file permissions of the Mumble database.
     Closes: #659039
Checksums-Sha1: 
 e8b11e39f40daebf905ec2ef1a3e4adc0a8d0d3d 2851 mumble_1.2.3-3.dsc
 93262d433674c88dfa2a1949a854570ef51d84b3 34433 mumble_1.2.3-3.debian.tar.gz
 e7645409458b0d5ddcddb60e47dd8091a7e9fc2b 115914 mumble-server-web_1.2.3-3_all.deb
 dcf17cc6a178f0bd23e4189e7d0d9e7b0a1faa44 2639066 mumble_1.2.3-3_amd64.deb
 2cee1c2befc42641f65ffb8fd860cb80006b72a4 1300988 mumble-11x_1.2.3-3_amd64.deb
 ce987e48b5ef398376bf2f5d4390a6f26ebbde8e 860764 mumble-server_1.2.3-3_amd64.deb
 ba5ed404362d8741fad3b8b33954ce569e74249d 39858282 mumble-dbg_1.2.3-3_amd64.deb
Checksums-Sha256: 
 2b7738cd117bac1ce97d26b0fa999aa862e3020915c133e148fc7779c9b10d19 2851 mumble_1.2.3-3.dsc
 d674d4e83fe07b8151649e94aa32ca8fac752308d18c53e15f2e8d3df525b7c2 34433 mumble_1.2.3-3.debian.tar.gz
 91279d47d1dc9fc00f31592b3fe154724c7a8b87f596a18153e56aee8486f23e 115914 mumble-server-web_1.2.3-3_all.deb
 5b83d025fbffe4e4319a45cb7792719d3dc6b1b459684935986ad422d1a2eff6 2639066 mumble_1.2.3-3_amd64.deb
 2cb16c434f96aaaf6951e8e754e8648ff50232d645d6aeab96ae9483a862bc89 1300988 mumble-11x_1.2.3-3_amd64.deb
 17c7adae151a33bbbc9637d1612b21a394c9ce9d991d47ecb71430fbd3c53801 860764 mumble-server_1.2.3-3_amd64.deb
 704d4b6edf7f030ab5bee46534d572afff7fca1e14c84178bbe6096f8c8cfffa 39858282 mumble-dbg_1.2.3-3_amd64.deb
Files: 
 b987f9e00b97f0f8414dff7122ed2b8c 2851 sound optional mumble_1.2.3-3.dsc
 ef187f85c2eed00df2ef6ebb5c019b93 34433 sound optional mumble_1.2.3-3.debian.tar.gz
 67395ac00c09b7efbd7a478845fb68ce 115914 sound optional mumble-server-web_1.2.3-3_all.deb
 445e9cec3df5cfb0c77519b9fb11364c 2639066 sound optional mumble_1.2.3-3_amd64.deb
 4fc5784a9a2c56525a2bff596caff5b4 1300988 sound optional mumble-11x_1.2.3-3_amd64.deb
 32670488a13cf0bb1f9cac278ea4b246 860764 sound optional mumble-server_1.2.3-3_amd64.deb
 525dd78aa7cb043053fbc3a5f90b9dce 39858282 debug extra mumble-dbg_1.2.3-3_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAEBCAAGBQJPN+e+AAoJEBLZsEqQy9jkyYMQAJVJz2bhD4cxHPUJbHClThVd
N/50S5j8uD9osy90UUHNoAP3+Fu/SEKy/FIfjp4eokFT2VZi6uQDIm94HiGeMumD
hmME8M/k8vF5Ks9G+5cBlE6xJXdlh4d0AnoOVZtWhFIkOur4xLHvIHRTrGn3QwCk
PH3ffJktWAVrB0x1UNF6GejemvOzkhtzrT3k+jEGgw7heQdjkd8LXPLDf455aOSo
A2HN+u8tAj5O73Bdw7yVCBtKcQLgJVYoPCWmdTsm4p0q2GH9ZT31Oc9lpetMOcCX
643E6FmoXHC3h4ZvN5Vu377pchXaEYry9eR/k8IEp/pnvjk1vUf2F2kUoitvXWOd
Vza3idbXnkB6wjejGQLyDeybCTCiMA4QFocigrIXhIfacwYCHMzAt94FYx5pfF9e
sDa+5bpnGUdZY9ir35pw4l7cBCz8CvM+hwOtBvKvXCVN6ALwbnVvS1lLO2KXKc3N
xmGGpcNUPj98MA+DcuwDPfViUrwyV0DqCMT7Q/wLaIyDVqt/iaVExHDszLlJ/o4w
kXsVJ8RgOlHGZ/Q4lCR7mmnxG8/R4o2EnSifNkU1bCrA7aBFlwCgqypNV+mRVXdx
9CGtsYKhCVMZW7bav3H9gMbkdyEhg8eJly1/jvZit721swGwAzbJ/eKwZwX4lfLR
k4iH16tnyOJTML5DYav/
=dW3+
-----END PGP SIGNATURE-----





Added tag(s) security. Request was from Paul Wise <pabs@debian.org> to control@bugs.debian.org. (Wed, 15 Feb 2012 08:03:04 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Debian VoIP Team <pkg-voip-maintainers@lists.alioth.debian.org>:
Bug#659039; Package mumble. (Thu, 16 Feb 2012 02:45:03 GMT) (full text, mbox, link).


Acknowledgement sent to Michael Gilbert <michael.s.gilbert@gmail.com>:
Extra info received and forwarded to list. Copy sent to Debian VoIP Team <pkg-voip-maintainers@lists.alioth.debian.org>. (Thu, 16 Feb 2012 02:45:03 GMT) (full text, mbox, link).


Message #24 received at 659039@bugs.debian.org (full text, mbox, reply):

From: Michael Gilbert <michael.s.gilbert@gmail.com>
To: 659039@bugs.debian.org
Subject: stable affected
Date: Wed, 15 Feb 2012 21:42:41 -0500
It looks like the version in squeeze is also affected by this.  It
should probably be fixed in a proposed-update if not as a security
fix.

Mike




Information forwarded to debian-bugs-dist@lists.debian.org, Debian VoIP Team <pkg-voip-maintainers@lists.alioth.debian.org>:
Bug#659039; Package mumble. (Thu, 16 Feb 2012 08:45:11 GMT) (full text, mbox, link).


Acknowledgement sent to Henri Salo <henri@nerv.fi>:
Extra info received and forwarded to list. Copy sent to Debian VoIP Team <pkg-voip-maintainers@lists.alioth.debian.org>. (Thu, 16 Feb 2012 08:45:11 GMT) (full text, mbox, link).


Message #29 received at 659039@bugs.debian.org (full text, mbox, reply):

From: Henri Salo <henri@nerv.fi>
To: 659039@bugs.debian.org
Subject: mumble: Mumble database is world-readable
Date: Thu, 16 Feb 2012 10:36:49 +0200
If this is same issue as http://www.openwall.com/lists/oss-security/2012/02/15/1 then this is security issue and can be referred as CVE-2012-0863 (http://www.openwall.com/lists/oss-security/2012/02/15/2).

- Henri Salo




Reply sent to Patrick Matthäi <pmatthaei@debian.org>:
You have taken responsibility. (Sun, 19 Feb 2012 19:21:12 GMT) (full text, mbox, link).


Notification sent to Marc Deslauriers <marc.deslauriers@ubuntu.com>:
Bug acknowledged by developer. (Sun, 19 Feb 2012 19:21:12 GMT) (full text, mbox, link).


Message #34 received at 659039-close@bugs.debian.org (full text, mbox, reply):

From: Patrick Matthäi <pmatthaei@debian.org>
To: 659039-close@bugs.debian.org
Subject: Bug#659039: fixed in mumble 1.2.2-6+squeeze1
Date: Sun, 19 Feb 2012 19:17:11 +0000
Source: mumble
Source-Version: 1.2.2-6+squeeze1

We believe that the bug you reported is fixed in the latest version of
mumble, which is due to be installed in the Debian FTP archive:

mumble-11x_1.2.2-6+squeeze1_amd64.deb
  to main/m/mumble/mumble-11x_1.2.2-6+squeeze1_amd64.deb
mumble-dbg_1.2.2-6+squeeze1_amd64.deb
  to main/m/mumble/mumble-dbg_1.2.2-6+squeeze1_amd64.deb
mumble-server-web_1.2.2-6+squeeze1_all.deb
  to main/m/mumble/mumble-server-web_1.2.2-6+squeeze1_all.deb
mumble-server_1.2.2-6+squeeze1_amd64.deb
  to main/m/mumble/mumble-server_1.2.2-6+squeeze1_amd64.deb
mumble_1.2.2-6+squeeze1.debian.tar.gz
  to main/m/mumble/mumble_1.2.2-6+squeeze1.debian.tar.gz
mumble_1.2.2-6+squeeze1.dsc
  to main/m/mumble/mumble_1.2.2-6+squeeze1.dsc
mumble_1.2.2-6+squeeze1_amd64.deb
  to main/m/mumble/mumble_1.2.2-6+squeeze1_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 659039@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Patrick Matthäi <pmatthaei@debian.org> (supplier of updated mumble package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Fri, 17 Feb 2012 14:13:34 +0100
Source: mumble
Binary: mumble mumble-11x mumble-server mumble-dbg mumble-server-web
Architecture: source all amd64
Version: 1.2.2-6+squeeze1
Distribution: stable-security
Urgency: high
Maintainer: Debian VoIP Team <pkg-voip-maintainers@lists.alioth.debian.org>
Changed-By: Patrick Matthäi <pmatthaei@debian.org>
Description: 
 mumble     - Low latency VoIP client
 mumble-11x - Low latency VoIP client (1.1.x)
 mumble-dbg - Low latency VoIP client (debugging symbols)
 mumble-server - Low latency VoIP server
 mumble-server-web - Web scripts for mumble-server
Closes: 659039
Changes: 
 mumble (1.2.2-6+squeeze1) stable-security; urgency=high
 .
   * Add patch 0005-set-file-permissions from Marc Deslauriers, which fixes the
     word readable file permissions of the Mumble SQLite database, as described
     in CVE-2012-0863.
     Closes: #659039
Checksums-Sha1: 
 940701430019a4178b81165fa152cfa3b5e5fc3d 2557 mumble_1.2.2-6+squeeze1.dsc
 b2a7fd50e70147b3ea2361cbc5a577b0e1ae45ea 2920587 mumble_1.2.2.orig.tar.gz
 ac613eb9d289448ecf3e974e0a8f9481277003e2 32430 mumble_1.2.2-6+squeeze1.debian.tar.gz
 eb769c54327b1eaec9c3be40ead444bc09246752 94742 mumble-server-web_1.2.2-6+squeeze1_all.deb
 76d2371cc84d96f70a8c1e8637dfe7e5c72dddf9 2215346 mumble_1.2.2-6+squeeze1_amd64.deb
 0ff0aae4f1db44da6dfd0a27767b73ab9e614e19 1279340 mumble-11x_1.2.2-6+squeeze1_amd64.deb
 f7da3c81635defae574db32017d482c88994a171 815390 mumble-server_1.2.2-6+squeeze1_amd64.deb
 d77df6d1cf6a3062f549ef03b0513f08d5ba24c9 24314666 mumble-dbg_1.2.2-6+squeeze1_amd64.deb
Checksums-Sha256: 
 a8a0a530f1cddb827e1c54034b5f4893d1ce9106601f3c3520a27ff61141a183 2557 mumble_1.2.2-6+squeeze1.dsc
 2c564e3d5b7481129482f2365375a2dc77e134c0c00012073cfdfbeadaa49be8 2920587 mumble_1.2.2.orig.tar.gz
 b15b080cf9932491efbc051f191042be7c13e697a374a140e96223eba5866b72 32430 mumble_1.2.2-6+squeeze1.debian.tar.gz
 0d9713ec27ad89e06259a2b692e821018238227827acdf2cfb6d138ea79c0106 94742 mumble-server-web_1.2.2-6+squeeze1_all.deb
 8278a6a2e9cf81c09c0f8e2273659d493abad1d007a1835dd0b68b86c25571a2 2215346 mumble_1.2.2-6+squeeze1_amd64.deb
 1f6bb4a30ab2de983dfbaac7877fbfb3dcf0c23852a33c206d7de4cf464999db 1279340 mumble-11x_1.2.2-6+squeeze1_amd64.deb
 d1ed776acb24d11f16ec9491a555be016ccb817f2b23f99f6f73a18b57dffced 815390 mumble-server_1.2.2-6+squeeze1_amd64.deb
 c71755308c16f50a1e8c32f4450b5172e6750bf4f594a34bee03f177f4b093dc 24314666 mumble-dbg_1.2.2-6+squeeze1_amd64.deb
Files: 
 ea02a2d446b2edd36e1d1502ea6cfb88 2557 sound optional mumble_1.2.2-6+squeeze1.dsc
 de30ee85170e183b66568b53b04c5727 2920587 sound optional mumble_1.2.2.orig.tar.gz
 2a4ada84870c369d2b180145e73d4512 32430 sound optional mumble_1.2.2-6+squeeze1.debian.tar.gz
 4f072221f76f8328a41521d738e4769f 94742 sound optional mumble-server-web_1.2.2-6+squeeze1_all.deb
 4ecab88ebab758860598a09f8b4673bb 2215346 sound optional mumble_1.2.2-6+squeeze1_amd64.deb
 7c5f778f7eb2ec8717d922a2c69576fc 1279340 sound optional mumble-11x_1.2.2-6+squeeze1_amd64.deb
 62245b83b73a57f6f7dd7bba0c055c1f 815390 sound optional mumble-server_1.2.2-6+squeeze1_amd64.deb
 3c9f28bc05dcaaf344b265b0226846df 24314666 debug extra mumble-dbg_1.2.2-6+squeeze1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iQIcBAEBCAAGBQJPPliWAAoJEBLZsEqQy9jk0XkP/2i3EjwFae5AIeA+Z0K/4Ezt
Q7ezcQUFfL3ZRctcNUrwkPm2ahyp9+of6KeW4EZhnOmUCiX9bkmVSe8d35wAFsf/
86pp2i3PsSR0deOMLIGin5X5qOsVpwszTTAS/pcTDIKwJLoxsft+1mCnpNwyc2vn
LmCRNKjBHCyFPK/xEYb1SB4JhHN1VcfhAoLqeqsxZxSYQFTkOnKigFO54kgEsv3F
99XVo2VfFuvBicv1O1UDMyIH6sRkW0ZgwH2miMZDmfXKSwDlntXsTFcXcThbTOUg
6Ic34iG0UQk7W4cMJ0JgBxSxLZqOJg9JHPKcC4xJcVmhiS4YLcxpl0p8jgCMcL1C
isAlAmX90wuPTYb6vVIJcsIRqd4x/98JDHxJDliBQvISS/iYapsVU1+QUP8L2fwH
1/JfHDEz1G9LV+vLHUhtQyRf/Wo8hWV8MMx9Yccvk71Q1l3hamBxBjDvZpPKYhcJ
5uNpiSl/NEiFze1HaTehSCga8rdadikA9qcHe9yF4r/0DyzimfwKodpdIcKtq+AO
dFBd4924ictznj4P1kCVtr8IcpJcBzWU2/tj5v6qAzj1rdxSyaXF6REh5V6BJ5zm
EkpD4XYyee1ZIN8vyHPDulWSV65guRlOjj6aoMGvi2WJuGyEjSEWRG6o1CeQoAaa
+R4b9P7v4+RZrVbsE6wL
=KhMH
-----END PGP SIGNATURE-----





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 19 Mar 2012 07:34:20 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 19:18:20 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.