Your message dated Tue, 20 Aug 2019 08:58:12 +0000
with message-id <[email protected]>
and subject line Bug#931041: fixed in basez 1.6-3+deb10u1
has caused the Debian Bug report #931041,
regarding basez: fails to decode base64url strings
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
931041: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931041
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: basez
Version: 1.6-3
Severity: important
Tags: upstream

Dear Maintainer,

   * Decoding a JWT signature showed that omitting the padding (as
     required by one of the JWS RFC) causes a failure in base64url -d.

    $ echo -n 
Igzmk82YO1cNEjjEF0WQMEv4tGPLrgm43Yrh_bFvHStV2Qju-eebyN82F-fASOZqQxOGL9sU_g6ewloKNk5yO7Dt__YqJ9GROXiovYD6cM4G2UboYn7BCf4lH84kfRNZAxrVNOOC50aYuVTvTGQrxXUooq9KnCkQzeZLbl26Vw7Yq0fP_D39ztoNu5Oyy0Nar_iHRyyPqAyia3VhrcETIK199IUG4QK0Rj2UIfEg6qPhVrE2rVKZy2zd4s871sLg0XuqOdwwZsYsIBP0tcd2C2-6HTfDNlBEoWo_XtF3DbkvNiBA75xHcxlXkq__ytCdicXDkdfOiS39IfsyzzmGEg==
 | tr -- '-_' '+/' | base64 -d | xxd -g0 -ps -c20
    220ce693cd983b570d1238c4174590304bf8b463
    cbae09b8dd8ae1fdb16f1d2b55d908eef9e79bc8
    df3617e7c048e66a4313862fdb14fe0e9ec25a0a
    364e723bb0edfff62a27d1913978a8bd80fa70ce
    06d946e8627ec109fe251fce247d1359031ad534
    e382e74698b954ef4c642bc57528a2af4a9c2910
    cde64b6e5dba570ed8ab47cffc3dfdceda0dbb93
    b2cb435aaff887472c8fa80ca26b7561adc11320
    ad7df48506e102b4463d9421f120eaa3e156b136
    ad5299cb6cdde2cf3bd6c2e0d17baa39dc3066c6
    2c2013f4b5c7760b6fba1d37c3365044a16a3f5e
    d1770db92f362040ef9c4773195792afffcad09d
    89c5c391d7ce892dfd21fb32cf398612

    $ echo -n 
Igzmk82YO1cNEjjEF0WQMEv4tGPLrgm43Yrh_bFvHStV2Qju-eebyN82F-fASOZqQxOGL9sU_g6ewloKNk5yO7Dt__YqJ9GROXiovYD6cM4G2UboYn7BCf4lH84kfRNZAxrVNOOC50aYuVTvTGQrxXUooq9KnCkQzeZLbl26Vw7Yq0fP_D39ztoNu5Oyy0Nar_iHRyyPqAyia3VhrcETIK199IUG4QK0Rj2UIfEg6qPhVrE2rVKZy2zd4s871sLg0XuqOdwwZsYsIBP0tcd2C2-6HTfDNlBEoWo_XtF3DbkvNiBA75xHcxlXkq__ytCdicXDkdfOiS39IfsyzzmGEg==
 | base64url -d
    base64url: invalid input

-- System Information:
Debian Release: 10.0
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 4.18.16-x86_64-linode118 (SMP w/1 CPU core; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages basez depends on:
ii  libc6  2.28-10

basez recommends no packages.

basez suggests no packages.

-- no debconf information

--- End Message ---
--- Begin Message ---
Source: basez
Source-Version: 1.6-3+deb10u1

We believe that the bug you reported is fixed in the latest version of
basez, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Milan Kupcevic <[email protected]> (supplier of updated basez package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 11 Aug 2019 18:59:28 -0400
Source: basez
Architecture: source
Version: 1.6-3+deb10u1
Distribution: buster
Urgency: medium
Maintainer: Milan Kupcevic <[email protected]>
Changed-By: Milan Kupcevic <[email protected]>
Closes: 931041
Changes:
 basez (1.6-3+deb10u1) buster; urgency=medium
 .
   * Properly decode base64url encoded strings (closes: #931041)
Checksums-Sha1:
 b51bbc5612908b4cd7a007dc2fe1bce4c5b98e96 1548 basez_1.6-3+deb10u1.dsc
 deb2f6efa1d88a40985f37ef719e8431ab7ed7c2 12180 
basez_1.6-3+deb10u1.debian.tar.xz
 3777a96cd05fdc4271c3bd18b8fef485fafe7c4e 5331 
basez_1.6-3+deb10u1_amd64.buildinfo
Checksums-Sha256:
 c3a4e217bcf33770ec8abaff2ae8d5cf896a8c83e7236f129d146169a9877076 1548 
basez_1.6-3+deb10u1.dsc
 66b9127f309231eae9be4377f972544fb47005ff2678c8cc83c7f5992b98c92f 12180 
basez_1.6-3+deb10u1.debian.tar.xz
 23d9562c13e73e94da7f0f3bb15f22fc50ff6062e1f1529fa7bf91afc6250970 5331 
basez_1.6-3+deb10u1_amd64.buildinfo
Files:
 8e888c3a22a9e621f1340c7607712072 1548 utils optional basez_1.6-3+deb10u1.dsc
 ac60b99a7330e7355dcf03930b71091b 12180 utils optional 
basez_1.6-3+deb10u1.debian.tar.xz
 b865f304b756b7affc2a0439e63e1bf6 5331 utils optional 
basez_1.6-3+deb10u1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQHFBAEBCgAvFiEEVkf/m69krCYf+z+G6e1ngbRVCQ4FAl1ZeY0RHG1pbGFuQGRl
Ymlhbi5vcmcACgkQ6e1ngbRVCQ4WNwv/dLWGwcBipbcKH5ywwQ85ZR64HIkWg56M
nCT4+hveKehsUjon4j+7VJu+FFRyQLnBqOCXj9Ek4uDRFydjxHkT6mFfidgjRDUM
b2j3i83f/SpJjIDdUWkYfuqVxieVzV5FnUJpz6Cfoi/npol1eQ/zwMwsQtqNmtZ7
5GOxAr26U6K11zlOHU+Y6GgBEoK7sCUfZ4M5zZoVqKB2cJS0oCO6V6LPINvsJL88
IHIswbKp36Xas8l19q2q5+OpNh6K1dmnrPDykZtLOd7E9jDcrCfiKaMLZKpAORLm
uNZtuq+Xt0/EGiFsD7AgJsmBfYJhC7+damJVP3MZBKYOqnp71LVhNSIaFemi2OtU
eaM0LdTX5yh/6mhm8rUAqT/z2EpN76cyoWE2rXybyWBEWAcyT2mBbkvXz91T/VHC
k6OMFw/3J36NRFql4L/pnclToppVOroguJM3kODFmK2+oAtxbHbO2ZsjwbCBGUZo
8937RRsYR3axx7f5x/YhtkWkhHhLeBET
=Lc7d
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to