Your message dated Mon, 05 Aug 2019 22:33:22 +0000
with message-id <e1hulxe-0005qe...@fasolo.debian.org>
and subject line Bug#933801: fixed in 
golang-github-docker-docker-credential-helpers 0.6.1-3
has caused the Debian Bug report #933801,
regarding golang-github-docker-docker-credential-helpers: CVE-2019-1020014
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
933801: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=933801
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: golang-github-docker-docker-credential-helpers
Version: 0.6.1-2
Severity: important
Tags: security upstream

Hi,

The following vulnerability was published for
golang-github-docker-docker-credential-helpers.

CVE-2019-1020014[0]:
| docker-credential-helpers before 0.6.3 has a double free in the List
| functions.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-1020014
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1020014

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: golang-github-docker-docker-credential-helpers
Source-Version: 0.6.1-3

We believe that the bug you reported is fixed in the latest version of
golang-github-docker-docker-credential-helpers, which is due to be installed in 
the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 933...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Arnaud Rebillout <arnaud.rebill...@collabora.com> (supplier of updated 
golang-github-docker-docker-credential-helpers package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 05 Aug 2019 15:04:28 +0700
Source: golang-github-docker-docker-credential-helpers
Architecture: source
Version: 0.6.1-3
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team 
<pkg-go-maintain...@lists.alioth.debian.org>
Changed-By: Arnaud Rebillout <arnaud.rebill...@collabora.com>
Closes: 933801
Changes:
 golang-github-docker-docker-credential-helpers (0.6.1-3) unstable; 
urgency=medium
 .
   * Add myself to uploaders.
   * Add upstream patch to fix CVE-2019-1020014 (Closes: #933801).
Checksums-Sha1:
 0624bec2f7daf14deeb99a74496e0e9d8cec846b 2341 
golang-github-docker-docker-credential-helpers_0.6.1-3.dsc
 56858aa3f8f1927c2cbaafb77fa7d8475fbc9719 4516 
golang-github-docker-docker-credential-helpers_0.6.1-3.debian.tar.xz
 c4b1f1aa72c750b32b600b7a5eeba186ba250a39 7529 
golang-github-docker-docker-credential-helpers_0.6.1-3_amd64.buildinfo
Checksums-Sha256:
 c4e24dc133e1359c675b97ac4ec4ac1f65a4901d1a72c5e4584340ad77d9af12 2341 
golang-github-docker-docker-credential-helpers_0.6.1-3.dsc
 4722e7729d360d444826f4855183001992af4d43d98a3210ad5c737fe7ffc8f3 4516 
golang-github-docker-docker-credential-helpers_0.6.1-3.debian.tar.xz
 c850a2f2f6a2df8cd87cfb601e7139f997bcc7c798b2d32704366aee5b01117b 7529 
golang-github-docker-docker-credential-helpers_0.6.1-3_amd64.buildinfo
Files:
 f325fde609604be05cc58de6de9c83f4 2341 devel optional 
golang-github-docker-docker-credential-helpers_0.6.1-3.dsc
 d118eb5668e7541a1cd4a537d665477e 4516 devel optional 
golang-github-docker-docker-credential-helpers_0.6.1-3.debian.tar.xz
 66fcae9a97574d9b67555b34b5de5b79 7529 devel optional 
golang-github-docker-docker-credential-helpers_0.6.1-3_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQFEBAEBCgAuFiEE85F2DZP0aJKsSKyHONAPABi+PjUFAl1IQkoQHHpoc2pAZGVi
aWFuLm9yZwAKCRA40A8AGL4+NT3TB/9uvVYv5YZHLLloL6iKE4WV/x90dwqQw+pr
c0nbnkRA/bXElRUdrF6mMv8UdkZvFaNh9kzkm0VwIZIbeccWe5vLUPoLD9Eexwp6
RHg9ej03zBDIaGIWPNcrzuWdM6CG21ZmxA1Ctqxwvn0Xwr3t6Z2P+i0GgkoFuGOM
8Q2JwcxGNRv8ITtfSL007q5SvcY2oFuDcahJ5siuZdpJyG7OCYgUcQOTWwEChIje
ueNV28QM+XT+ADGDALF/xkEAaitYW3C2By05cAuyXGkt3g/Amwc0qNmqqVfMisV9
NnyUBZ/ySxMORoVBywDJFBwbY5XltUbXQkl3pPHfRz9hOk6teOSO
=3ye7
-----END PGP SIGNATURE-----

--- End Message ---
_______________________________________________
Pkg-go-maintainers mailing list
Pkg-go-maintainers@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-go-maintainers

Reply via email to