Your message dated Mon, 20 Sep 2010 20:02:05 +0000
with message-id <[email protected]>
and subject line Bug#592716: fixed in drupal6 6.6-3lenny6
has caused the Debian Bug report #592716,
regarding drupal6: SA-CORE-2010-002 - Drupal core - Multiple vulnerabilities
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
592716: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=592716
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: drupal6
Version: 6.16-1~bpo50+1
Severity: grave
Tags: security
Justification: user security hole
DRUPAL-SA-CORE-2010-002 from 2010-08-12 includes several vulnerabilities, some
of them allowing malicious site identifying as existing users and gaining
administrative access.
The problems got fixed in 6.18, so it looks like all versions currently in
Debian are affected.
Thanks,
-- System Information:
Debian Release: 5.0.5
APT prefers stable
APT policy: (990, 'stable'), (190, 'testing')
Architecture: i386 (i686)
Kernel: Linux 2.6.18.8-linode22 (SMP w/4 CPU cores)
Locale: LANG=ca_ES.UTF-8, LC_CTYPE=ca_ES.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash
Versions of packages drupal6 depends on:
ii curl 7.18.2-8lenny4 Get a file from an HTTP, HTTPS or
ii dbconfig-common 1.8.39 common framework for packaging dat
ii debconf [debconf-2 1.5.24 Debian configuration management sy
ii mysql-client 5.0.51a-24+lenny4 MySQL database client (metapackage
ii mysql-client-5.0 [ 5.0.51a-24+lenny4 MySQL database client binaries
ii nginx [httpd] 0.7.67-3 small, but very powerful and effic
ii php5 5.2.6.dfsg.1-1+lenny9 server-side, HTML-embedded scripti
ii php5-gd 5.2.6.dfsg.1-1+lenny9 GD module for php5
ii php5-mysql 5.2.6.dfsg.1-1+lenny9 MySQL module for php5
ii postfix [mail-tran 2.5.5-1.1 High-performance mail transport ag
ii wwwconfig-common 0.1.2 Debian web auto configuration
Versions of packages drupal6 recommends:
ii mysql-server 5.0.51a-24+lenny4 MySQL database server (metapackage
ii mysql-server-5.0 [mysq 5.0.51a-24+lenny4 MySQL database server binaries
drupal6 suggests no packages.
-- debconf information excluded
--- End Message ---
--- Begin Message ---
Source: drupal6
Source-Version: 6.6-3lenny6
We believe that the bug you reported is fixed in the latest version of
drupal6, which is due to be installed in the Debian FTP archive:
drupal6_6.6-3lenny6.diff.gz
to main/d/drupal6/drupal6_6.6-3lenny6.diff.gz
drupal6_6.6-3lenny6.dsc
to main/d/drupal6/drupal6_6.6-3lenny6.dsc
drupal6_6.6-3lenny6_all.deb
to main/d/drupal6/drupal6_6.6-3lenny6_all.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Luigi Gangitano <[email protected]> (supplier of updated drupal6 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Thu, 09 Sep 2010 08:40:21 +0200
Source: drupal6
Binary: drupal6
Architecture: source all
Version: 6.6-3lenny6
Distribution: stable-security
Urgency: low
Maintainer: Luigi Gangitano <[email protected]>
Changed-By: Luigi Gangitano <[email protected]>
Description:
drupal6 - a fully-featured content management framework
Closes: 592716
Changes:
drupal6 (6.6-3lenny6) stable-security; urgency=low
.
[ Luigi Gangitano ]
* debian/patches/20_SA-CORE-2010-002
- Fixes multiple XSS vulnerabilities (Closes: #592716)
Fixes: SA-CORE-2010-002, CVE-2010-3091, CVE-2010-3092, CVE-2010-3093,
CVE-2010-3094
Checksums-Sha1:
0d4af87412e171ba6e8999bbd8220004a544430a 1130 drupal6_6.6-3lenny6.dsc
0132ff7b79ef560e1f9edc768326aa234be3287e 32605 drupal6_6.6-3lenny6.diff.gz
1f33c68dec41c214610428e66b31b3bc99e8e593 1093210 drupal6_6.6-3lenny6_all.deb
Checksums-Sha256:
e85807bcae27efa72f2986ddb63302efb2cd8ad394e339d280fbb43c687ffcb9 1130
drupal6_6.6-3lenny6.dsc
dd650711d3eec49ae734ac70f45aa05f294ac673ad0da062a37cb645f8bf50fe 32605
drupal6_6.6-3lenny6.diff.gz
6d77d73a6948fef25dd4d91e4f3959f7aeaef7054bdc5ffba24bb951497066c0 1093210
drupal6_6.6-3lenny6_all.deb
Files:
7a2cb0258096a2076a4c16ee1ba7b74b 1130 web extra drupal6_6.6-3lenny6.dsc
b6ec50b492dc28d6a3273e6cafdcaf64 32605 web extra drupal6_6.6-3lenny6.diff.gz
1f8147473dd2a1a7d48247c974892991 1093210 web extra drupal6_6.6-3lenny6_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (Darwin)
iEYEARECAAYFAkyXUJwACgkQ8ZumGJJMDCY9VwCeLO85cdmPPOwycoWcQhkLPYly
7n4An1yYoYAuHEYokHRZ7cHlhHBIkpoQ
=tYHF
-----END PGP SIGNATURE-----
--- End Message ---