Your message dated Wed, 15 Jun 2016 22:26:06 +0000
with message-id <[email protected]>
and subject line Bug#827405: fixed in cgit 1.0+git2.8.3-1
has caused the Debian Bug report #827405,
regarding cgit: update to version 1.0 fixes CVE-2016-2315
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
827405: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=827405
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: cgit
Version: 0.12.0.git2.7.0-1
Severity: grave
Tags: security upstream
Justification: user security hole

Dear Maintainer,

The above version of cgit embeds git 2.7.0, which is affected
by CVE-2016-2315 [1]. The update to cgit 1.0 [2, 3] includes
git 2.8.3, which fixes the issue.

[1] https://security-tracker.debian.org/tracker/CVE-2016-2315
[2] http://article.gmane.org/gmane.comp.version-control.cgit/3076
[2] https://bugs.debian.org/826764

Regards,
Peter

--- End Message ---
--- Begin Message ---
Source: cgit
Source-Version: 1.0+git2.8.3-1

We believe that the bug you reported is fixed in the latest version of
cgit, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Peter Colberg <[email protected]> (supplier of updated cgit package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Wed, 15 Jun 2016 15:18:24 -0400
Source: cgit
Binary: cgit
Architecture: source
Version: 1.0+git2.8.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Cgit Packaging Team <[email protected]>
Changed-By: Peter Colberg <[email protected]>
Description:
 cgit       - hyperfast web frontend for git repositories written in C
Closes: 826764 827405
Changes:
 cgit (1.0+git2.8.3-1) unstable; urgency=medium
 .
   * New upstream release
     - Uses internally Git 2.8.3, which fixes CVE-2016-2315 (Closes: #827405)
   * Update patch headers to conform to DEP-3
   * Set Maintainer to Debian Cgit Packaging Team (Closes: #826764)
   * Add myself to Uploaders
   * Update Homepage to https
   * Add Vcs-Git and Vcs-Browser
   * Bump Standards-Version to 3.9.8
   * Update debian/copyright
   * Enable verbose compilation
   * Re-enable hardening flags
   * Revise debian/rules
   * Fix spelling
   * Add debian/watch
   * Add debian/gbp.conf
   * Add get-orig-source target to pack orig tarball
Checksums-Sha1:
 b587b2c8912fe805b99da87bde12384762a0736f 2059 cgit_1.0+git2.8.3-1.dsc
 f20e086fca3757307217a310d9ba2309d56d829b 5897262 cgit_1.0+git2.8.3.orig.tar.gz
 10a3a69faf2e22052506fcb54a1ffa7ee4f0170b 10072 
cgit_1.0+git2.8.3-1.debian.tar.xz
Checksums-Sha256:
 f2e2e8915577558e57b8f8e01c991d16aa019d65296732dbd93039e0c8c147fa 2059 
cgit_1.0+git2.8.3-1.dsc
 c4a22466ae735c4f94668b6c3a1e6b15e7b71fd11068ec6852772f8274c0d07b 5897262 
cgit_1.0+git2.8.3.orig.tar.gz
 5f597027bf80b98c0cb62a364d47116de6b1c16d395e6cc6ce21a564b3652f79 10072 
cgit_1.0+git2.8.3-1.debian.tar.xz
Files:
 e93af93215cb48f188c565defd376ce4 2059 net extra cgit_1.0+git2.8.3-1.dsc
 d7349aab440877a6a6921c08828d2ffb 5897262 net extra 
cgit_1.0+git2.8.3.orig.tar.gz
 4653d6e98a6fec4865e1e15bd3d253f6 10072 net extra 
cgit_1.0+git2.8.3-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJXYbKvAAoJEB5F+Mqd4jsW+88QAI7xI77FCJFHLjplIfCVqhix
SzIG5JcyJq/GkyqoOhNRly10qVn47M8zrxxNTE3bamGYvQXU4jpFM7P5CAVY1Jof
zp1bhoKly/K/91Ux3BPyN14/EuREav/1MBNYHmmoWG9QHG/2p3wBs2i8E+RdlC6R
Pj31qW6JtdDbMUKcYAIvu38Q8cRayNyeeOqTWRGBBlhZESmpHuY5TYCnN4JItSJY
auvW44HkC6HjOExRy0Hm/WyuELB64vuYq/Pf5ZtVh0kgk+QfJ40dBh0SI2Z8DqTM
2n0S8Jk+F1CkhTsyyXyB96I8bPsdf/wQLIUwVnqtcRgqSHFZDuk65ZcHAAo72lik
PtD1DFtvRA7HeBAEGx1srN+Yv2nlxWcp2f/AArGrCm/ERd8CGZ/2uIUOSHdnclic
56Z4nJ8quFettbzSaHe8ob7+fb3dgy+UgbQexkWOnkR/MuLdOaNQ3dZ4K/s6r6uW
0TmyJQuYl/y0Zmn/JlX7M60BHIwkp7a8XwQnmgFBBGNXzfrdkuNvpdZYTl0JzWE6
gmeYw881MrRQUuq6Ti8VFqfQCD/nJskTw0DzX3LjTeh7WGYUICKMb5vJURokt7U5
bFbjTgfcWcR2p9J7S2MdV/M+uKxGdzkpPHkZdKt1kUnKiILlky3BfW7ldyhYDmFc
6sOkcjxVaxbiwVpnZBKL
=TpPG
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to