golang-github-appc-cni: CVE-2021-20206

Related Vulnerabilities: CVE-2021-20206  

Debian Bug report logs - #983659
golang-github-appc-cni: CVE-2021-20206

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Sun, 28 Feb 2021 08:39:01 UTC

Severity: important

Tags: security, upstream

Found in versions golang-github-appc-cni/0.8.0-2, golang-github-appc-cni/0.4.0+dfsg-1

Fixed in version golang-github-appc-cni/0.8.1-1

Done: Shengjing Zhu <zhsj@debian.org>

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, Debian Go Packaging Team <pkg-go-maintainers@lists.alioth.debian.org>:
Bug#983659; Package src:golang-github-appc-cni. (Sun, 28 Feb 2021 08:39:03 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, Debian Go Packaging Team <pkg-go-maintainers@lists.alioth.debian.org>. (Sun, 28 Feb 2021 08:39:06 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: golang-github-appc-cni: CVE-2021-20206
Date: Sun, 28 Feb 2021 09:35:13 +0100
Source: golang-github-appc-cni
Version: 0.8.0-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>

Hi,

The following vulnerability was published for golang-github-appc-cni.

CVE-2021-20206[0].

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2021-20206
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20206

Please adjust the affected versions in the BTS as needed.

As Thorsten has asked, I beleive this does not warrant a DSA fur
buster but can be fixed in a point release. Can you make sure the fix
goes though into bullseye?

Regards,
Salvatore



Marked as found in versions golang-github-appc-cni/0.4.0+dfsg-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 28 Feb 2021 08:42:03 GMT) (full text, mbox, link).


Reply sent to Shengjing Zhu <zhsj@debian.org>:
You have taken responsibility. (Sun, 28 Feb 2021 12:06:05 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sun, 28 Feb 2021 12:06:05 GMT) (full text, mbox, link).


Message #12 received at 983659-close@bugs.debian.org (full text, mbox, reply):

From: Debian FTP Masters <ftpmaster@ftp-master.debian.org>
To: 983659-close@bugs.debian.org
Subject: Bug#983659: fixed in golang-github-appc-cni 0.8.1-1
Date: Sun, 28 Feb 2021 12:03:57 +0000
Source: golang-github-appc-cni
Source-Version: 0.8.1-1
Done: Shengjing Zhu <zhsj@debian.org>

We believe that the bug you reported is fixed in the latest version of
golang-github-appc-cni, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 983659@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Shengjing Zhu <zhsj@debian.org> (supplier of updated golang-github-appc-cni package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sun, 28 Feb 2021 19:20:44 +0800
Source: golang-github-appc-cni
Architecture: source
Version: 0.8.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
Changed-By: Shengjing Zhu <zhsj@debian.org>
Closes: 983659
Changes:
 golang-github-appc-cni (0.8.1-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream version 0.8.1
     + Tighten up plugin-finding logic (Closes: #983659)
       CVE-2021-20206
   * Update Section to golang
   * Update maintainer address to team+pkg-go@tracker.debian.org
   * Bump debhelper-compat to 13
   * Add Rules-Requires-Root
   * Add Multi-Arch hint
   * Skip integration test
   * Replace golang-ginkgo-dev with golang-github-onsi-ginkgo-dev
   * Update Standards-Version to 4.5.1 (no changes)
Checksums-Sha1:
 80aa4c1350a97a2a67637c8dab8a367811c0a7d1 1685 golang-github-appc-cni_0.8.1-1.dsc
 f4f1b0ec5075b76080ce7c7749b096444ef8f97f 100379 golang-github-appc-cni_0.8.1.orig.tar.gz
 dc4d83f80d2601ba95446b3d572f7e41e801963d 3112 golang-github-appc-cni_0.8.1-1.debian.tar.xz
 2703d125193c34cfc5f67bdd9b1b51cbdb3e1e32 6079 golang-github-appc-cni_0.8.1-1_amd64.buildinfo
Checksums-Sha256:
 67df66e871e269d79afc9afc17317661d2177fbd4b3676f04c6c2dc33eeb4bbf 1685 golang-github-appc-cni_0.8.1-1.dsc
 6242e7905b5f8f7561a21f595209b569998727927380a8cdf5ab58e7fd5ac2d5 100379 golang-github-appc-cni_0.8.1.orig.tar.gz
 a38f6b2a474e2aaf0ac216fbe1a3c53a42611bfed9ae10677939219eb04aee27 3112 golang-github-appc-cni_0.8.1-1.debian.tar.xz
 7c43e36b00b8d1f9d048c00805c86d29f52c23cd0752f5ad1ae88f24f988e30f 6079 golang-github-appc-cni_0.8.1-1_amd64.buildinfo
Files:
 9ffc4e78575bd8f4cf4c9b1ff54983cd 1685 golang optional golang-github-appc-cni_0.8.1-1.dsc
 4f5e4225a4b8d0ca6f4783b25739e9b1 100379 golang optional golang-github-appc-cni_0.8.1.orig.tar.gz
 fe6af62416d28c727e1daf8e8afcb849 3112 golang optional golang-github-appc-cni_0.8.1-1.debian.tar.xz
 407e805923a715204656eae470eea25b 6079 golang optional golang-github-appc-cni_0.8.1-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iIYEARYIAC4WIQTiXc95jUQrjt9HgU3EhUo4GOCwFgUCYDuErhAcemhzakBkZWJp
YW4ub3JnAAoJEMSFSjgY4LAWY/sA/0JgwC3uVWnuhuvGKRN0/pKJ2ucD4pF8WzQ3
+EG7QWgeAQCssZ9KXlEBOsV3DGFrtflVBPQrd1bOrnUdcyIKHp9QAA==
=vsgm
-----END PGP SIGNATURE-----




Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Mon Mar 1 16:05:12 2021; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.