Your message dated Fri, 13 Jan 2006 03:47:08 -0800
with message-id <[EMAIL PROTECTED]>
and subject line Bug#345518: fixed in kdesvn 0.7.2-1
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 1 Jan 2006 13:18:40 +0000
>From [EMAIL PROTECTED] Sun Jan 01 05:18:39 2006
Return-path: <[EMAIL PROTECTED]>
Received: from mail.gmx.de ([213.165.64.21] helo=mail.gmx.net)
        by spohr.debian.org with smtp (Exim 4.50)
        id 1Et36d-0003pp-JU
        for [EMAIL PROTECTED]; Sun, 01 Jan 2006 05:18:39 -0800
Received: (qmail invoked by alias); 01 Jan 2006 13:18:08 -0000
Received: from p548BB8E3.dip.t-dialin.net (EHLO morpheus.apaku.dnsalias.org) 
[84.139.184.227]
  by mail.gmx.net (mp020) with SMTP; 01 Jan 2006 14:18:08 +0100
X-Authenticated: #15861332
Received: from andreas by morpheus.apaku.dnsalias.org with local (Exim 4.60)
        (envelope-from <[EMAIL PROTECTED]>)
        id 1Et36E-00075N-Ul; Sun, 01 Jan 2006 14:18:14 +0100
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Andreas Pakulat <[EMAIL PROTECTED]>
To: Debian Bug Tracking System <[EMAIL PROTECTED]>
Subject: kdesvn ignores subversion-auth-config
Message-ID: <[EMAIL PROTECTED]>
X-Mailer: reportbug 3.18
Date: Sun, 01 Jan 2006 14:18:14 +0100
X-Y-GMX-Trusted: 0
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
        (1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Level: 
X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE 
        autolearn=no version=2.60-bugs.debian.org_2005_01_02

Package: kdesvn
Version: 0.7.1-1
Severity: important

Hi,

just found out that kdesvn stores my user/password for authenticating
against the subversion repository even though my .subversion/config
says:

[auth]
store-auth-creds = no

I'm not sure wether this is a user security hole, thus I'm not tagging
this critical but please upgrade severity if you think it's needed.

Andreas

-- System Information:
Debian Release: testing/unstable
  APT prefers unstable
  APT policy: (990, 'unstable'), (500, 'experimental'), (500, 'testing'), (500, 
'stable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.14.3-cherry+radeon
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)

Versions of packages kdesvn depends on:
ii  kdelibs4c2a               4:3.4.3-2      core libraries for all KDE applica
ii  kdesvn-kio-plugins        0.7.1-1        subversion I/O slaves for KDE
ii  libapr0                   2.0.55-3       the Apache Portable Runtime
ii  libc6                     2.3.5-9        GNU C Library: Shared libraries an
ii  libdb4.3                  4.3.29-3       Berkeley v4.3 Database Libraries [
ii  libexpat1                 1.95.8-3       XML parsing C library - runtime li
ii  libgcc1                   1:4.0.2-5      GCC support library
ii  libice6                   6.9.0.dfsg.1-1 Inter-Client Exchange library
ii  libldap2                  2.1.30-12      OpenLDAP libraries
ii  libpng12-0                1.2.8rel-5     PNG library - runtime
ii  libqt3-mt                 3:3.3.5-3      Qt GUI Library (Threaded runtime v
ii  libsm6                    6.9.0.dfsg.1-1 X Window System Session Management
ii  libstdc++6                4.0.2-5        The GNU Standard C++ Library v3
ii  libsvn0                   1.2.3dfsg1-3   shared libraries used by Subversio
ii  libx11-6                  6.9.0.dfsg.1-1 X Window System protocol client li
ii  libxext6                  6.9.0.dfsg.1-1 X Window System miscellaneous exte
ii  zlib1g                    1:1.2.3-9      compression library - runtime

Versions of packages kdesvn recommends:
ii  kompare                       4:3.4.3-1  a KDE GUI for viewing differences 

-- no debconf information

---------------------------------------
Received: (at 345518-close) by bugs.debian.org; 13 Jan 2006 11:50:32 +0000
>From [EMAIL PROTECTED] Fri Jan 13 03:50:32 2006
Return-path: <[EMAIL PROTECTED]>
Received: from katie by spohr.debian.org with local (Exim 4.50)
        id 1ExNOe-0006EC-VF; Fri, 13 Jan 2006 03:47:08 -0800
From: Michael Biebl <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
X-Katie: $Revision: 1.65 $
Subject: Bug#345518: fixed in kdesvn 0.7.2-1
Message-Id: <[EMAIL PROTECTED]>
Sender: Archive Administrator <[EMAIL PROTECTED]>
Date: Fri, 13 Jan 2006 03:47:08 -0800
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
        (1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Level: 
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER 
        autolearn=no version=2.60-bugs.debian.org_2005_01_02

Source: kdesvn
Source-Version: 0.7.2-1

We believe that the bug you reported is fixed in the latest version of
kdesvn, which is due to be installed in the Debian FTP archive:

kdesvn-kio-plugins_0.7.2-1_alpha.deb
  to pool/main/k/kdesvn/kdesvn-kio-plugins_0.7.2-1_alpha.deb
kdesvn-kio-plugins_0.7.2-1_i386.deb
  to pool/main/k/kdesvn/kdesvn-kio-plugins_0.7.2-1_i386.deb
kdesvn_0.7.2-1.diff.gz
  to pool/main/k/kdesvn/kdesvn_0.7.2-1.diff.gz
kdesvn_0.7.2-1.dsc
  to pool/main/k/kdesvn/kdesvn_0.7.2-1.dsc
kdesvn_0.7.2-1_alpha.deb
  to pool/main/k/kdesvn/kdesvn_0.7.2-1_alpha.deb
kdesvn_0.7.2-1_i386.deb
  to pool/main/k/kdesvn/kdesvn_0.7.2-1_i386.deb
kdesvn_0.7.2.orig.tar.gz
  to pool/main/k/kdesvn/kdesvn_0.7.2.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Biebl <[EMAIL PROTECTED]> (supplier of updated kdesvn package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Fri, 13 Jan 2006 04:31:54 +0100
Source: kdesvn
Binary: kdesvn kdesvn-kio-plugins
Architecture: source i386 alpha
Version: 0.7.2-1
Distribution: unstable
Urgency: low
Maintainer: Michael Biebl <[EMAIL PROTECTED]>
Changed-By: Michael Biebl <[EMAIL PROTECTED]>
Description: 
 kdesvn     - subversion client with tight KDE integration
 kdesvn-kio-plugins - subversion I/O slaves for KDE
Closes: 345518
Changes: 
 kdesvn (0.7.2-1) unstable; urgency=low
 .
   * New upstream release.
     + Removed patch context_menu.diff, merged upstream.
   * Added patch store_passwords_config.diff. Closes: #345518
   * Added patch settings_icons.diff for more distinct icons in the settings
     dialog.
Files: 
 e09ca1f1b8842bbbe49a243b93a377b8 694 devel optional kdesvn_0.7.2-1.dsc
 7ebc3e786bab67f23826df99a1828b08 1805596 devel optional 
kdesvn_0.7.2.orig.tar.gz
 816d3bf6b8d0cabe8f5ff21d77828d5c 9815 devel optional kdesvn_0.7.2-1.diff.gz
 15be7651143b38c32680fd707d89d6a7 1325452 devel optional kdesvn_0.7.2-1_i386.deb
 149e51d7a46105bf2a98e52a0ec8a8a0 351576 devel optional 
kdesvn-kio-plugins_0.7.2-1_i386.deb
 a20b50064cb2e3fc5712e7e6e0a338b3 1364610 devel optional 
kdesvn_0.7.2-1_alpha.deb
 681fa9112cb2b7ed2cb501f00264f5f9 384078 devel optional 
kdesvn-kio-plugins_0.7.2-1_alpha.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD4DBQFDx4/wipBneRiAKDwRAh/wAJi3oJ7CQeUnSZjroka69DHNSVvXAJ0W7Dds
VEU/olCjREgi8e5kH7imgg==
=SqD6
-----END PGP SIGNATURE-----


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to