Your message dated Sun, 04 Aug 2019 05:19:21 +0000
with message-id <[email protected]>
and subject line Bug#931041: fixed in basez 1.6-4
has caused the Debian Bug report #931041,
regarding basez: fails to decode base64url strings
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
931041: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931041
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: basez
Version: 1.6-3
Severity: important
Tags: upstream

Dear Maintainer,

   * Decoding a JWT signature showed that omitting the padding (as
     required by one of the JWS RFC) causes a failure in base64url -d.

    $ echo -n 
Igzmk82YO1cNEjjEF0WQMEv4tGPLrgm43Yrh_bFvHStV2Qju-eebyN82F-fASOZqQxOGL9sU_g6ewloKNk5yO7Dt__YqJ9GROXiovYD6cM4G2UboYn7BCf4lH84kfRNZAxrVNOOC50aYuVTvTGQrxXUooq9KnCkQzeZLbl26Vw7Yq0fP_D39ztoNu5Oyy0Nar_iHRyyPqAyia3VhrcETIK199IUG4QK0Rj2UIfEg6qPhVrE2rVKZy2zd4s871sLg0XuqOdwwZsYsIBP0tcd2C2-6HTfDNlBEoWo_XtF3DbkvNiBA75xHcxlXkq__ytCdicXDkdfOiS39IfsyzzmGEg==
 | tr -- '-_' '+/' | base64 -d | xxd -g0 -ps -c20
    220ce693cd983b570d1238c4174590304bf8b463
    cbae09b8dd8ae1fdb16f1d2b55d908eef9e79bc8
    df3617e7c048e66a4313862fdb14fe0e9ec25a0a
    364e723bb0edfff62a27d1913978a8bd80fa70ce
    06d946e8627ec109fe251fce247d1359031ad534
    e382e74698b954ef4c642bc57528a2af4a9c2910
    cde64b6e5dba570ed8ab47cffc3dfdceda0dbb93
    b2cb435aaff887472c8fa80ca26b7561adc11320
    ad7df48506e102b4463d9421f120eaa3e156b136
    ad5299cb6cdde2cf3bd6c2e0d17baa39dc3066c6
    2c2013f4b5c7760b6fba1d37c3365044a16a3f5e
    d1770db92f362040ef9c4773195792afffcad09d
    89c5c391d7ce892dfd21fb32cf398612

    $ echo -n 
Igzmk82YO1cNEjjEF0WQMEv4tGPLrgm43Yrh_bFvHStV2Qju-eebyN82F-fASOZqQxOGL9sU_g6ewloKNk5yO7Dt__YqJ9GROXiovYD6cM4G2UboYn7BCf4lH84kfRNZAxrVNOOC50aYuVTvTGQrxXUooq9KnCkQzeZLbl26Vw7Yq0fP_D39ztoNu5Oyy0Nar_iHRyyPqAyia3VhrcETIK199IUG4QK0Rj2UIfEg6qPhVrE2rVKZy2zd4s871sLg0XuqOdwwZsYsIBP0tcd2C2-6HTfDNlBEoWo_XtF3DbkvNiBA75xHcxlXkq__ytCdicXDkdfOiS39IfsyzzmGEg==
 | base64url -d
    base64url: invalid input

-- System Information:
Debian Release: 10.0
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 4.18.16-x86_64-linode118 (SMP w/1 CPU core; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages basez depends on:
ii  libc6  2.28-10

basez recommends no packages.

basez suggests no packages.

-- no debconf information

--- End Message ---
--- Begin Message ---
Source: basez
Source-Version: 1.6-4

We believe that the bug you reported is fixed in the latest version of
basez, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Milan Kupcevic <[email protected]> (supplier of updated basez package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 04 Aug 2019 00:53:50 -0400
Source: basez
Architecture: source
Version: 1.6-4
Distribution: sid
Urgency: medium
Maintainer: Milan Kupcevic <[email protected]>
Changed-By: Milan Kupcevic <[email protected]>
Closes: 931041
Changes:
 basez (1.6-4) sid; urgency=medium
 .
   * Properly decode base64url encoded strings (closes: #931041)
Checksums-Sha1:
 8205c1bc936ce69a8c9142eb4224dcf4fea8a804 1516 basez_1.6-4.dsc
 f338b904465cdb4c3dcbec23167468dd9e9fbf79 12172 basez_1.6-4.debian.tar.xz
 39c3b39b7dbbd252bf4881616eac9d954423b768 5380 basez_1.6-4_amd64.buildinfo
Checksums-Sha256:
 39ced7daab71a8b241e9e1c31ed8a1c6b1ab2fbc0e184ae04ad72caf2b8cd995 1516 
basez_1.6-4.dsc
 cc7a0162c8fea280cc8ec3f09982f57d4cc4d80166ac6f6b4d44e85bcd708bee 12172 
basez_1.6-4.debian.tar.xz
 4f5ee45b798e8cc9e2db330471ded2d2778e0279457633c10148978c9ff9c67d 5380 
basez_1.6-4_amd64.buildinfo
Files:
 713fe2c93e80871c3243a26801bd6257 1516 utils optional basez_1.6-4.dsc
 b0884c31aa3c92cc594330b0b31398d8 12172 utils optional basez_1.6-4.debian.tar.xz
 72890315aae6ce631484b70687aaeca0 5380 utils optional 
basez_1.6-4_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQHFBAEBCgAvFiEEVkf/m69krCYf+z+G6e1ngbRVCQ4FAl1GZZ8RHG1pbGFuQGRl
Ymlhbi5vcmcACgkQ6e1ngbRVCQ7j6gv/awmB9PcGBtRPc8H1WEfgCl8xJozHwVHd
tsCQ+pvqKtoDsRni4pxd6/8P1dnD5DshhodXWw9VDUCpmYPsonH8r61Icw8nG4Sk
s0/cRDuqR8KkNMKGK4Redbr2Uf68iN4OeWCvxwowzztcVpGMEMmYXi48ehIEd9NK
ThsEGj1Ke6h/t8t8uX6lDPVpQn6Rlwc2SeUe85JTPxOJeFK8vFzhTWNg39NsMFbi
tEWC3n8Jc9tyP/61ALBDFQdLfz8Y8HU+owjhP6oKm3ea+pzNcvQW3Y1exytYwPCg
APmeRafAp4qgQDsehmrII1Hww6l+XCfDraqLlxwyFC7P1C7WjddeFcC1GI33oyt0
VVpsbjQHat2J0iMYISUwg3J4vlCisoSflw52izwLdVgULoCJdNlcO45CIApVNFc3
RkU+da+Py2++q7f6P/5t3y/1MhjGSmIez46gubW3/pbYSMW7ct+Nc5i3xvW0osjD
8lZIyL5GWIyKo/MvM+Px67wQLkaBba8c
=QyK6
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to