Your message dated Fri, 28 May 2021 12:37:44 +0000
with message-id <e1lmbkg-00075q...@fasolo.debian.org>
and subject line Bug#988893: fixed in squid 4.13-10
has caused the Debian Bug report #988893,
regarding squid: CVE-2021-28651
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
988893: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=988893
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: squid
Version: 4.13-9
Severity: important
Tags: security upstream
X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>
Control: found -1 4.6-1+deb10u5
Control: found -1 4.6-1+deb10u5
Control: found -1 4.6-1

Hi,

The following vulnerability was published for squid.

CVE-2021-28651[0]:
| Denial of Service in URN processing

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2021-28651
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28651
[1] https://github.com/squid-cache/squid/security/advisories/GHSA-ch36-9jhx-phm4

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: squid
Source-Version: 4.13-10
Done: Santiago Garcia Mantinan <ma...@debian.org>

We believe that the bug you reported is fixed in the latest version of
squid, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 988...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Santiago Garcia Mantinan <ma...@debian.org> (supplier of updated squid package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 28 May 2021 12:28:20 +0200
Source: squid
Architecture: source
Version: 4.13-10
Distribution: unstable
Urgency: medium
Maintainer: Luigi Gangitano <lu...@debian.org>
Changed-By: Santiago Garcia Mantinan <ma...@debian.org>
Closes: 988891 988892 988893 989043
Changes:
 squid (4.13-10) unstable; urgency=medium
 .
   [ Francisco Vilmar Cardoso Ruviaro ]
   * Add debian/patches/0007-CVE-2021-28651.patch to fix a Denial
     of Service in URN processing. (Closes: #988893, CVE-2021-28651)
 .
   [ Santiago Garcia Mantinan ]
   * Add patch to fix a Denial of Service in HTTP Response Processing.
     Fixes: CVE-2021-28662. Closes: #988891.
   * Add patch to fix a Denial of Service issue in Cache Manager.
     Fixes: CVE-2021-28652. Closes: #988892.
   * Add patch to fix Multiple Issues in HTTP Range header.
     Fixes: CVE-2021-31806 CVE-2021-31807 CVE-2021-31808. Closes: #989043.
   * Add patch to fix a Denial of Service in HTTP Response processing.
     Fixes: GHSA-572g-rvwr-6c7f.
Checksums-Sha1:
 2420289a0ac276e96c81cb8ed0bae43a5f0bd599 2956 squid_4.13-10.dsc
 192286b7bf7d54028c3fc8304463f110aee80ec0 52936 squid_4.13-10.debian.tar.xz
 f1878431898e211bc1a65e40d3e6e4f23408ab4d 7800 squid_4.13-10_source.buildinfo
Checksums-Sha256:
 c3fcfcb6378a900ea78a76d76d1eba0425646d2236464c7ee7f61ef9fbfdd603 2956 
squid_4.13-10.dsc
 120f8b867ec6c8abfeada7b4db6ef401c3a92e55e177a1a9d5bc1067a140270c 52936 
squid_4.13-10.debian.tar.xz
 b5417b705db391002ffcfe118023cdc99c4f1acdee2b38d031271117656527ab 7800 
squid_4.13-10_source.buildinfo
Files:
 a902743425c59c5e16e919ccf5d44c53 2956 web optional squid_4.13-10.dsc
 bb6425a65ef6b7b87b464ca49816caaa 52936 web optional squid_4.13-10.debian.tar.xz
 f0911c3661b9c5ef099ec183e7777e58 7800 web optional 
squid_4.13-10_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEBqPldg9hG0uxqQ5ouGiMo9h21aMFAmCw3lMACgkQuGiMo9h2
1aNHohAAg6pZUqXob2S0DhCGHO8wXO5ZmHyE46Kc5XvKevEejyP9ouodfNwxKCTL
OegDQjqYt2FQIENqir09nR0DJflUjSVdInmCBapomcoyS0VqBcka7mQ6ltXwfY7K
hy93OW3/O5oxMZFlIAvuwqC+06A39eplCOy5aOmVgRt4QS+6SDp85tSXDrBEHZI+
69g928MFrVw+hHYtdIzZDAIS8pYa3aSha9dKjwlgghSWieL8eW2+fuwa6mlZhmt5
pVAGRRWc6CG3mLA/YcHeEEv1G67oioA41qZB7tA70UKREO+we8LaYgP7o2RNqA8M
lYBgd6zD/BUoKXmif7tQVq2sluFGtD//xaJ3L3xsL4hs1g2f37Zf7KDPJHJdXZ9U
k41RdPVIoy0VmeuQ6alYmmsJ+nbGuEIrtc4IqCxL26nF1p/cUEgin97nBgO2hfbh
/wYb+DSUI+fmg58nhSoqIZVEREwAwsnJVfwNkwP629Wi+AziFMfhatkldm/uL/DZ
+nZ54DyhOumd34cTi2Muy5vG5FRr3EgdHyzUz60YmVYzH4jyqR7ykL5D2/7ZS/5z
1cXZaTNTafINqibUliCsIS3RJNDragnfzGgTPsRSSoP9WkBg/BDu7pOjEdiG592S
FAHwtWL9g3vQiD3q58cUOis5cd6LYK4Cc2w+9rqq0SBFurKPgZk=
=3vsv
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to