Your message dated Fri, 17 Apr 2015 22:03:26 +0000
with message-id <[email protected]>
and subject line Bug#775582: fixed in debian-security-support 2015.04.04~~deb6u1
has caused the Debian Bug report #775582,
regarding Remove php5 and memcached from limited support
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
775582: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775582
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: debian-security-support
Version: 2014.12.17
Severity: normal

Hi,

Please see attached patch that removes php5 and memcached from limited
security support. These packages receive full support according to
what is commonly understood as proper normal use cases for this
software. As discussed at the security team meeting.

Please apply.

Thanks,
Thijs
>From 22817e551a4b55c9f94bc66c027d42ab87492fdb Mon Sep 17 00:00:00 2001
From: Thijs Kinkhorst <[email protected]>
Date: Sat, 17 Jan 2015 18:26:40 +0100
Subject: [PATCH] Remove php5,memcached from limited-support

Our PHP support is not different from upstream's and is well understood
by the community. Even stronger for memcached, which everyone running it
knows not to expose to the world as it doesn't do any protection by
design.
---
 security-support-limited |    2 --
 1 file changed, 2 deletions(-)

diff --git a/security-support-limited b/security-support-limited
index 19f0143..2d9db0f 100644
--- a/security-support-limited
+++ b/security-support-limited
@@ -14,12 +14,10 @@ glpi            Only supported behind an authenticated HTTP zone for trusted use
 kde4libs        khtml has no security support upstream, only for use on trusted content
 libv8-3.14      Not covered by security support, only suitable for trusted content
 ltp             Pure Testsuite, only supported on non-production non-multiuser systems
-memcached       Attacks that require an attacker to be able to access the memcached port/sock are not supported, it's running as nobody and in a typical setup attackers don't have access to this
 mozjs           Not covered by security support, only suitable for trusted content
 mozjs17         Not covered by security support, only suitable for trusted content
 mozjs24         Not covered by security support, only suitable for trusted content
 ocsinventory-server Only supported behind an authenticated HTTP zone
-php5            See README.Debian.security for the PHP security policy
 pidgin          Support in oldstable is limited to IRC, Jabber/XMPP, Sametime and SIMPLE
 qtwebkit        No security support upstream and backports not feasible, only for use on trusted content
 sql-ledger      Only supported behind an authenticated HTTP zone
-- 
1.7.10.4


--- End Message ---
--- Begin Message ---
Source: debian-security-support
Source-Version: 2015.04.04~~deb6u1

We believe that the bug you reported is fixed in the latest version of
debian-security-support, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Holger Levsen <[email protected]> (supplier of updated debian-security-support 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 17 Apr 2015 21:46:17 +0000
Source: debian-security-support
Binary: debian-security-support
Architecture: source all
Version: 2015.04.04~~deb6u1
Distribution: squeeze-lts
Urgency: high
Maintainer: Christoph Biedl <[email protected]>
Changed-By: Holger Levsen <[email protected]>
Description: 
 debian-security-support - Debian security support coverage checker
Closes: 772858 773048 774312 775582 776904 779104
Changes: 
 debian-security-support (2015.04.04~~deb6u1) squeeze-lts; urgency=low
 .
   * Rebuild for squeeze-lts.
 .
 debian-security-support (2015.04.04) unstable; urgency=high
 .
   * Add wireshark to unsupported packages in Squeeze (Closes: #774312)
   * Remove php5 and memcached from "limited support": Debian's PHP support is 
not
     different from upstream's and is well understood by the community. The same
     applies to memcached (Closes: #775582)
   * Mark chromium-browser as unsupported in Wheezy (Closes: #776904). The
     same applies to rails
   * Mark piwigo as unsupported in Squeeze (Closes: #779104)
   * Mark xulrunner as unsupported
 .
 debian-security-support (2014.12.17) unstable; urgency=high
 .
   * Add to list of packages not supported in squeeze-lts:
     - src:qemu (Closes: #772858)
     - src:textpattern (Closes: #773048)
Checksums-Sha1: 
 7ab2c497b0248e49ddda07ff3d7f08056ec7ccbb 1755 
debian-security-support_2015.04.04~~deb6u1.dsc
 216fd016efa42c56f4e2abed3d03e3ac09b73e00 27449 
debian-security-support_2015.04.04~~deb6u1.tar.gz
 a5dc7831847d9bf4802fb5b238b5183da09cb21f 22140 
debian-security-support_2015.04.04~~deb6u1_all.deb
Checksums-Sha256: 
 5455920b2bc03707f089964ab5e158c2d0a7fd9ca9fd7536517c3fe02cba6f39 1755 
debian-security-support_2015.04.04~~deb6u1.dsc
 90081df238859d160818abf01af42051a7b2cf00ba0b211f3ce420ca17031e95 27449 
debian-security-support_2015.04.04~~deb6u1.tar.gz
 c962a142aa7fff39c7f06c8e2fa0f5bb29cf51e72130024cb1d906d1ed9f1fb5 22140 
debian-security-support_2015.04.04~~deb6u1_all.deb
Files: 
 31d542d7109f8d5f32b74db925cc9aae 1755 admin optional 
debian-security-support_2015.04.04~~deb6u1.dsc
 7764b1649e895c4e8b6a11d5a2b3128b 27449 admin optional 
debian-security-support_2015.04.04~~deb6u1.tar.gz
 ee97828a720036c87d356c0b1d6d03da 22140 admin optional 
debian-security-support_2015.04.04~~deb6u1_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIVAwUBVTGBqwkauFYGmqocAQqb5g/+JDKMcqXJDm39zOdo2puh+j6rkKQbkfB9
lR7QwwKfhPgoD38w9L8RyW00PzuFJgdPRvnzRQ0AKp4uI6d9OybQ65EZJv9NYosU
iebqUJSKTtpMCmxFkjLkpbygBvOCzYDALS5RymANXH5cRKo+X+8PGGmoUy1AeyOM
kLA8Phktqko5YoepYAlMDPUyPzTsKWl8bRoA6EUEAEYJYIGxUEuWEsRUwTeGTcEs
xO39L/G3BbNP6Wfq+qBU1F2F30lhbhukiYLIy/lYhdlFNEDYZxFA9iCNx3qluyjb
E7tmXpGTmt4ikbkEtmrrL9AL+D/ohN0fi3+vGUqQAxNC6emG57h/2Rflq9tDW/Lz
TUFSLL8YyHq7/cBT173YYytVMyRaR/Znr7bZZJFD8L4gBLlDEbU4SQpq4W8rgLUN
9YEIE0BkXglTRMDkVP7JYKIMK8cogA4FAqcZAG2phpaVZ1+MXBq1FWB4Wa5QmTE+
AlBHe5rr9vP8QYVXlIwbRQQDp7vyk5tM6dpOQPG8CaUxVN3FGijNfjm3T+e1wEHk
/Zn+Q8ZbrS8cx/4Ib5QoIR6QmDCrteKJnfUxjP1OSOgugse9KMfrrkhUnM1afzRU
bA4CUflysdj3VLGP2OxDEGZsr8mHaIAIxkRWslxJuExdkeonLs4y+vjM/SkOgOkg
IGTLEdsjlSg=
=xj+s
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to