Your message dated Thu, 04 Mar 2021 09:18:29 +0000
with message-id <[email protected]>
and subject line Bug#863892: fixed in zziplib 0.13.62-3.3
has caused the Debian Bug report #863892,
regarding zziplib: Update Homepage field
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
863892: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863892
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: zziplib
Severity: grave
Tags: security
Hi,
multiple security issues have been found in zziplib by Agostino Sarubbo
of Gentoo:
http://www.openwall.com/lists/oss-security/2017/02/09/10
http://www.openwall.com/lists/oss-security/2017/02/09/11
http://www.openwall.com/lists/oss-security/2017/02/09/12
http://www.openwall.com/lists/oss-security/2017/02/09/13
http://www.openwall.com/lists/oss-security/2017/02/09/14
http://www.openwall.com/lists/oss-security/2017/02/09/15
http://www.openwall.com/lists/oss-security/2017/02/09/16
http://www.openwall.com/lists/oss-security/2017/02/09/17
http://www.openwall.com/lists/oss-security/2017/02/09/18
http://www.openwall.com/lists/oss-security/2017/02/09/19
http://www.openwall.com/lists/oss-security/2017/02/09/20
He points out that upstream seems dead:
http://www.openwall.com/lists/oss-security/2017/02/09/21
Aside from that, there's also older, unacknowleged bugs from the
Mayhem project in the BTS.
So unless you want to pick up upstream maintenace yourself, we should
rather remove zziplib from stretch.
Cheers,
Moritz
--- End Message ---
--- Begin Message ---
Source: zziplib
Source-Version: 0.13.62-3.3
Done: Matthias Klose <[email protected]>
We believe that the bug you reported is fixed in the latest version of
zziplib, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Matthias Klose <[email protected]> (supplier of updated zziplib package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Thu, 04 Mar 2021 09:54:37 +0100
Source: zziplib
Architecture: source
Version: 0.13.62-3.3
Distribution: unstable
Urgency: medium
Maintainer: Scott Howard <[email protected]>
Changed-By: Matthias Klose <[email protected]>
Closes: 856566 863892 967237
Changes:
zziplib (0.13.62-3.3) unstable; urgency=medium
.
* Non-maintainer upload.
* Build using python2. Closes: #856566, #967237.
* Update home page. Closes: #863892.
* Update watch file.
Checksums-Sha1:
a52d9c063dffd820aff35c9cf7e19bc5794003e9 2066 zziplib_0.13.62-3.3.dsc
4fd124ca4a805febf138e247e17cde62a8a012dc 17036
zziplib_0.13.62-3.3.debian.tar.xz
394be391d69cbfb3aa9c4bcb0482826c8fd0c573 6753
zziplib_0.13.62-3.3_source.buildinfo
Checksums-Sha256:
7913767c0a6439a08f8dab05babfbaa3de9219515ab1216c3c0ba25b4c6dfc8c 2066
zziplib_0.13.62-3.3.dsc
7d95e46fb0ebbcb598ce4ab256ceb3a021d89859db8b36d53bafc821948ed569 17036
zziplib_0.13.62-3.3.debian.tar.xz
d1c82e3e00f86e061ca3672bc48854280883359d1a766e69149949172a3c95f0 6753
zziplib_0.13.62-3.3_source.buildinfo
Files:
7ceaa0ea74ed10d2203801a4f480c0c5 2066 libs optional zziplib_0.13.62-3.3.dsc
49c1857880e748d1b9b48d7e506aebe1 17036 libs optional
zziplib_0.13.62-3.3.debian.tar.xz
e704f512ed365e5604a6d2f8410b891a 6753 libs optional
zziplib_0.13.62-3.3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJEBAEBCAAuFiEE1WVxuIqLuvFAv2PWvX6qYHePpvUFAmBAoogQHGRva29AZGVi
aWFuLm9yZwAKCRC9fqpgd4+m9cMCEACGYXzRZ6T+a3p5YXGuywohfFetY40Jic4W
TDL6vTXM4oKGdbAsOBp0o0OfVjMd71J4rxWVLMquUR9lFUxd8B3PI48ukJkbH6B5
eszUajP3LeN7ugn3E3HsNS7dBy+nIXnztuHcx3KAeEDEXjnjN4Cl8i8relwnjUZu
CiFol8UwqCPxLopho5IZF3knSj4tHpenVtP6fs/+dQZGC/KEjeaTkp2NDr7Q712H
6nncnnOmw6fOh/c6ArPdZcCarySEZNxk/RDrOdpt8TJtSgQnPpJcQZsLHRtiKqyZ
piZJGBZ4swufYlq3mE06auEDutIkIExdx3XnfuEIBIF86OtIQHx7VZ6C1cRsD12d
e6lFwmieNsOvO57S0HGGHSwpCLm+HV9gJWkPIJB43tmsH07Lkh0Vd0bC5bGrR+JP
/IKKH7MJOGpbFqA1RMkd1ZLztnOnnR/n3nIA4IfUmw4M9aMgq12TSdW6bMum8hJ+
LTDPPoejr9Q2lTCxFRjJhBsViZsXJZcFuSWAwfxkgdocru1MqWaWwmp2V2VrF4uF
Hk+JDHEQc1Gg8LawpFOWlmHXAiKbc7ggyDODhYQc4F3tGuQDEC5vyVjHD5Go0EkJ
tzKHZTGX7l1q/BbyjFLbX2wgCmv928lYxW/MBoGC8wdDD+689wOZO8/qw+7XB5w0
RQcJfwq1bg==
=qrTj
-----END PGP SIGNATURE-----
--- End Message ---