Your message dated Sun, 20 Aug 2017 10:19:11 +0000
with message-id <[email protected]>
and subject line Bug#869153: fixed in tor 0.3.1.5-alpha-2
has caused the Debian Bug report #869153,
regarding tor: CVE-2017-11565: aa-exec is not longer in /usr/sbin and now 
apparmor is silently scraped
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
869153: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=869153
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: tor
Version: 0.2.9.11-1~deb9u1
Severity: important
Tags: security patch

Hi Peter,
  I got this report[1]
   aa-exec is not in /usr/sbin anymore, at least not in every arch [2].

Cheers, luciano

[1]  https://twitter.com/pissquark/status/888142796414226432
[2]  
https://packages.debian.org/search?searchon=contents&keywords=bin%2Faa-exec&mode=path&suite=unstable&arch=any

--- End Message ---
--- Begin Message ---
Source: tor
Source-Version: 0.3.1.5-alpha-2

We believe that the bug you reported is fixed in the latest version of
tor, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Peter Palfrader <[email protected]> (supplier of updated tor package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sat, 19 Aug 2017 10:21:30 +0200
Source: tor
Binary: tor tor-geoipdb
Architecture: source
Version: 0.3.1.5-alpha-2
Distribution: experimental
Urgency: medium
Maintainer: Peter Palfrader <[email protected]>
Changed-By: Peter Palfrader <[email protected]>
Description:
 tor        - anonymizing overlay network for TCP
 tor-geoipdb - GeoIP database for Tor
Closes: 867342 869153
Changes:
 tor (0.3.1.5-alpha-2) experimental; urgency=medium
 .
   * apparmor: use Pix instead of PUx for obfs4proxy, giving us
     better confinement of the child process while actually working
     with systemd's NoNewPrivileges.  (closes: #867342)
   * Do not rely on aa-exec and aa-enabled being in /usr/sbin in the
     SysV init script.  This change enables apparmor confinement
     on some system-V systems again.  (closes: #869153)
Checksums-Sha1:
 92fe095eac351786b7a2d7f5ea25a8b1ab8f6f6b 1843 tor_0.3.1.5-alpha-2.dsc
 e662ab1ce5fae6f82cf16d379d64350dead5a6e5 5997514 tor_0.3.1.5-alpha.orig.tar.gz
 fada63cb06691fdd60961c84959f4e468886ce63 47546 tor_0.3.1.5-alpha-2.diff.gz
Checksums-Sha256:
 4f0f98b69587d6fcb31cb8d1215dfe95d21f93c0ba8a3ea2dacdb2bca0ede19d 1843 
tor_0.3.1.5-alpha-2.dsc
 04281b87e8b97517ba52232cd58de06a816f5a136b9b7a7316be878b36df8313 5997514 
tor_0.3.1.5-alpha.orig.tar.gz
 47882eb8c84c0299cc1887cb7c887c939e025a15526d4bafe62dbd3120da889a 47546 
tor_0.3.1.5-alpha-2.diff.gz
Files:
 91f4210653f65481166b0d56f1db9ccd 1843 net optional tor_0.3.1.5-alpha-2.dsc
 138b80f8b365225f8aa080388ef565a7 5997514 net optional 
tor_0.3.1.5-alpha.orig.tar.gz
 c6400384cb05cf8977610bcf309d87dd 47546 net optional tor_0.3.1.5-alpha-2.diff.gz

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEs4PXhajJL968BgN2hgLIIDhyMx8FAlmZXKoACgkQhgLIIDhy
Mx84+AgAvnZKAgIdzk4rZNR1Yf6gqEr3Thz5F8s4LSI3NdI+sQPvKt+/CH0gBSL3
IRm2he3433Xi64QgDg16iylLZyOyF6OrKECzK13SWnGuc3b2OjvbOebz28GpCXND
YWTolkQy1rJLHHQWlRCkX/nW9oI95/3g6HBwv3xmhy/Oo20dQtCmkZsR8tyEWXJP
GnTqpXjxJC6wZJNTKpvFZaOoRsud/bLmksJ1VFWPyr4H6m3uzlz4DLWK7GumWSJ5
jZj+SizZ7/9ikKBz0XjTyUA6fyimTWsB6JzFEvoTlVCu0Qwm/+4LICHAQsRhfVBw
kMwf/fAdSRct5Xtcnjgf0hq+1F9nZg==
=2Fo5
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to