Your message dated Fri, 03 Aug 2007 17:47:03 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#429224: fixed in cacti 0.8.6j-1.1
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: cacti
Tags: security

Two (apparently) related post-authentication DoS bugs have been
disclosed in cacti:

<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3112>
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3113>

(I'm not sure if those warrant a security update for stable.)

Please mention the respective names in the changelog when fixing these
bugs.


--- End Message ---
--- Begin Message ---
Source: cacti
Source-Version: 0.8.6j-1.1

We believe that the bug you reported is fixed in the latest version of
cacti, which is due to be installed in the Debian FTP archive:

cacti_0.8.6j-1.1.diff.gz
  to pool/main/c/cacti/cacti_0.8.6j-1.1.diff.gz
cacti_0.8.6j-1.1.dsc
  to pool/main/c/cacti/cacti_0.8.6j-1.1.dsc
cacti_0.8.6j-1.1_all.deb
  to pool/main/c/cacti/cacti_0.8.6j-1.1_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Steffen Joeris <[EMAIL PROTECTED]> (supplier of updated cacti package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Fri,  3 Aug 2007 19:27:17 +0200
Source: cacti
Binary: cacti
Architecture: source all
Version: 0.8.6j-1.1
Distribution: unstable
Urgency: high
Maintainer: sean finney <[EMAIL PROTECTED]>
Changed-By: Steffen Joeris <[EMAIL PROTECTED]>
Description: 
 cacti      - Frontend to rrdtool for monitoring systems and services
Closes: 429224
Changes: 
 cacti (0.8.6j-1.1) unstable; urgency=high
 .
   * Non-maintainer upload with the permission of the maintainer
   * Fix DoS caused by large values passed to the graph_height,
     graph_width, graph_start and graph_end parameter parameters
     (Closes: #429224) Fixes: CVE-2007-3112, CVE-2007-3113
Files: 
 71970460da70b55e2da32d561d29a68f 581 web extra cacti_0.8.6j-1.1.dsc
 94024d53937adfe7f6e993d7c0102426 32921 web extra cacti_0.8.6j-1.1.diff.gz
 316900d2bed5f3940ba36bc6c5b09ae4 963652 web extra cacti_0.8.6j-1.1_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGs2do62zWxYk/rQcRAqkqAJ9B2zDYAt1aJmxR2NPep3FfjawlTQCfXG4d
xCsC7W4sOhwzCPy4K5DuzEg=
=EmIB
-----END PGP SIGNATURE-----


--- End Message ---

Reply via email to