CVE-2011-1431 in TLS patch

Related Vulnerabilities: CVE-2011-1431  

Debian Bug report logs - #652378
CVE-2011-1431 in TLS patch

version graph

Package: src:qmail; Maintainer for src:qmail is Gerrit Pape <pape@smarden.org>;

Reported by: Moritz Muehlenhoff <jmm@debian.org>

Date: Fri, 16 Dec 2011 21:00:12 UTC

Severity: serious

Tags: security

Fixed in version 1.03-49.3+rm

Done: Debian FTP Masters <ftpmaster@ftp-master.debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Jon Marler <jmarler@debian.org>:
Bug#652378; Package src:qmail. (Fri, 16 Dec 2011 21:00:15 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Jon Marler <jmarler@debian.org>. (Fri, 16 Dec 2011 21:00:15 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2011-1431 in TLS patch
Date: Fri, 16 Dec 2011 22:01:26 +0100
Source: qmail
Severity: important
Tags: security

The source package embeds the qmail TLS patch, which is affected by
this STARTTLS issue:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1431

It appears as if the TLS patch isn't applied, it makes sense however
to update the patch anyway.

BTW, shouldn't this package be removed altogether now that netqmail
is in the archive?

Cheers,
        Moritz

-- System Information:
Debian Release: wheezy/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.1.0-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash




Severity set to 'serious' from 'important' Request was from Osamu Aoki <osamu@debian.org> to control@bugs.debian.org. (Fri, 19 Oct 2012 14:00:05 GMT) (full text, mbox, link).


Information stored :
Bug#652378; Package src:qmail. (Tue, 13 Nov 2012 16:27:10 GMT) (full text, mbox, link).


Acknowledgement sent to gregor herrmann <gregoa@debian.org>:
Extra info received and filed, but not forwarded. (Tue, 13 Nov 2012 16:27:10 GMT) (full text, mbox, link).


Message #12 received at 652378-quiet@bugs.debian.org (full text, mbox, reply):

From: gregor herrmann <gregoa@debian.org>
To: 652378-quiet@bugs.debian.org
Subject: Re: Bug#652378: CVE-2011-1431 in TLS patch
Date: Tue, 13 Nov 2012 17:23:21 +0100
[Message part 1 (text/plain, inline)]
On Fri, 16 Dec 2011 22:01:26 +0100, Moritz Muehlenhoff wrote:

> The source package embeds the qmail TLS patch, which is affected by
> this STARTTLS issue:
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1431
> 
> It appears as if the TLS patch isn't applied, it makes sense however
> to update the patch anyway.
> 
> BTW, shouldn't this package be removed altogether now that netqmail
> is in the archive?

Ansgar has filed an RM bug now: #692558


Cheers,
gregor

-- 
 .''`.  Homepage: http://info.comodo.priv.at/ - OpenPGP key 0xBB3A68018649AA06
 : :' : Debian GNU/Linux user, admin, and developer  -  http://www.debian.org/
 `. `'  Member of VIBE!AT & SPI, fellow of the Free Software Foundation Europe
   `-   NP: Red Hot Chili Peppers: Road Trippin
[signature.asc (application/pgp-signature, inline)]

Reply sent to Debian FTP Masters <ftpmaster@ftp-master.debian.org>:
You have taken responsibility. (Mon, 26 Nov 2012 21:57:40 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@debian.org>:
Bug acknowledged by developer. (Mon, 26 Nov 2012 21:57:40 GMT) (full text, mbox, link).


Message #17 received at 652378-done@bugs.debian.org (full text, mbox, reply):

From: Debian FTP Masters <ftpmaster@ftp-master.debian.org>
To: 40629-done@bugs.debian.org,52665-done@bugs.debian.org,54617-done@bugs.debian.org,64165-done@bugs.debian.org,68431-done@bugs.debian.org,88020-done@bugs.debian.org,107414-done@bugs.debian.org,122137-done@bugs.debian.org,139664-done@bugs.debian.org,143098-done@bugs.debian.org,181944-done@bugs.debian.org,199143-done@bugs.debian.org,235479-done@bugs.debian.org,272071-done@bugs.debian.org,293328-done@bugs.debian.org,316115-done@bugs.debian.org,326415-done@bugs.debian.org,532484-done@bugs.debian.org,652378-done@bugs.debian.org,
Cc: qmail@packages.debian.org, qmail@packages.qa.debian.org
Subject: Bug#692558: Removed package(s) from unstable
Date: Mon, 26 Nov 2012 21:55:57 +0000
Version: 1.03-49.3+rm

Dear submitter,

as the package qmail has just been removed from the Debian archive
unstable we hereby close the associated bug reports.  We are sorry
that we couldn't deal with your issue properly.

For details on the removal, please see http://bugs.debian.org/692558

The version of this package that was in Debian prior to this removal
can still be found using http://snapshot.debian.org/.

This message was generated automatically; if you believe that there is
a problem with it please contact the archive administrators by mailing
ftpmaster@debian.org.

Debian distribution maintenance software
pp.
Luca Falavigna (the ftpmaster behind the curtain)



Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Tue, 25 Dec 2012 07:29:30 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 14:40:03 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.