[pkg-go] Bug#947403: marked as done (golang-github-miekg-dns: CVE-2019-19794)
Your message dated Thu, 20 Feb 2020 06:04:20 + with message-id and subject line Bug#947403: fixed in golang-github-miekg-dns 1.1.26-1 has caused the Debian Bug report #947403, regarding golang-github-miekg-dns: CVE-2019-19794 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact ow...@bugs.debian.org immediately.) -- 947403: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=947403 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems --- Begin Message --- Source: golang-github-miekg-dns Version: 1.0.4+ds-1 Severity: important Tags: security upstream Forwarded: https://github.com/miekg/dns/issues/1043 Hi, The following vulnerability was published for golang-github-miekg-dns. CVE-2019-19794[0]: | The miekg Go DNS package before 1.1.25, as used in CoreDNS before | 1.6.6 and other products, improperly generates random numbers because | math/rand is used. The TXID becomes predictable, leading to response | forgeries. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2019-19794 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19794 [1] https://github.com/miekg/dns/issues/1043 Please adjust the affected versions in the BTS as needed. Regards, Salvatore --- End Message --- --- Begin Message --- Source: golang-github-miekg-dns Source-Version: 1.1.26-1 Done: Dmitry Smirnov We believe that the bug you reported is fixed in the latest version of golang-github-miekg-dns, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 947...@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Dmitry Smirnov (supplier of updated golang-github-miekg-dns package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmas...@ftp-master.debian.org) -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Mon, 30 Dec 2019 12:05:08 +1100 Source: golang-github-miekg-dns Architecture: source Version: 1.1.26-1 Distribution: unstable Urgency: medium Maintainer: pkg-go Changed-By: Dmitry Smirnov Closes: 939217 947403 Changes: golang-github-miekg-dns (1.1.26-1) unstable; urgency=medium . [ Alexandre Viau ] * Point Vcs-* urls to salsa.debian.org. . [ Martín Ferrari ] * debian/control: Depend on latest x/net. * debian/control: Update golang dependency to 1.10. . [ Dmitry Smirnov ] * New upstream release + fixed CVE-2019-19794 (Closes: #947403) * Build with "go generate" * (Build-)Depends += "golang-golang-x-sync-dev" * Removed transitional package "golang-dns-dev" (Closes: #939217) Thanks, Holger Levsen. * DH to version 12 * Standards-Version: 4.4.1 * Added myself to Uploaders Checksums-Sha1: 9c314d283044b64975434aec4f0e26dbfd6cfd5c 2413 golang-github-miekg-dns_1.1.26-1.dsc 402f1f2af6e40662467187d7aae9b3f31a035f21 143892 golang-github-miekg-dns_1.1.26.orig.tar.xz 47a6447dd6cf800d348734d1841b07838f805e45 5312 golang-github-miekg-dns_1.1.26-1.debian.tar.xz 62eab0c9b0ed93cb58b1f518622c4053dcd1989f 6331 golang-github-miekg-dns_1.1.26-1_amd64.buildinfo Checksums-Sha256: 606f85c178ddbc19c2e65822d6114152999a2c4773d2f798302310c524de84dc 2413 golang-github-miekg-dns_1.1.26-1.dsc 0f62be201f8711ad6e23d61808f779305879e65b489589436dc23b89681f3008 143892 golang-github-miekg-dns_1.1.26.orig.tar.xz 548dcff4100bdbe5864df11a6f0719953fe8997188df128eb7e4f6977c9f4478 5312 golang-github-miekg-dns_1.1.26-1.debian.tar.xz 3213566c0400c0d44290a466aaa70b2531028254f078ba33be5451df27af84c2 6331 golang-github-miekg-dns_1.1.26-1_amd64.buildinfo Files: 8b26c0b0635a4e0c547cdf043d867b67 2413 devel optional golang-github-miekg-dns_1.1.26-1.dsc fa6411bc496254ac4fe672611b2d4022 143892 devel optional golang-github-miekg-dns_1.1.26.orig.tar.xz c110998f5e1d8aef121eb1ba38b7637d 5312 devel optional golang-github-miekg-dns_1.1.26-1.debian.tar.xz bf03d23b4ea6bd251ff5ca0b3874c428 6331 devel optional golang-github-miekg-dns_1.1.26-1_amd64.buildinfo -BEGIN PGP SIGNATURE- iQIzBAEBCAAdFiEEULx8+TnSDCcqawZWUra72VOWjRsFAl5OHu0ACgkQUra72VOW jRvbfw/+N9G5dPQWNoo/LnKCT6ZhYJSlnD46U59GkY2S/9wQvMloO6Vd3oQQyw+s fXA+D5tunz/c3Cdgv8OqGWb4CYgk+zl+8xj4/w+zfBO0fwC4mYjZchVp5PNDdy1W 7Yybio1j3LQVSPIlJzJ
[pkg-go] Bug#939217: marked as done (please drop transitional package golang-dns-dev from src:golang-github-miekg-dns)
Your message dated Thu, 20 Feb 2020 06:04:20 + with message-id and subject line Bug#939217: fixed in golang-github-miekg-dns 1.1.26-1 has caused the Debian Bug report #939217, regarding please drop transitional package golang-dns-dev from src:golang-github-miekg-dns to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact ow...@bugs.debian.org immediately.) -- 939217: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=939217 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems --- Begin Message --- Package: golang-github-miekg-dns Version: 1.0.4+ds-1 Severity: normal user: qa.debian@packages.debian.org usertags: transitional Please drop the transitional package golang-dns-dev (from the source package golang-github-miekg-dns) for bullseye, as it has been released with stretch and buster already. Description: transitional package for golang-github-miekg-dns-dev Package: golang-dns-dev Version: 0.0~git20161018.0.58f52c5-1 Version: 1.0.4+ds-1 Thanks for maintaining golang-github-miekg-dns! -- cheers, Holger --- holger@(debian|reproducible-builds|layer-acht).org PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A AA1C signature.asc Description: PGP signature --- End Message --- --- Begin Message --- Source: golang-github-miekg-dns Source-Version: 1.1.26-1 Done: Dmitry Smirnov We believe that the bug you reported is fixed in the latest version of golang-github-miekg-dns, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 939...@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Dmitry Smirnov (supplier of updated golang-github-miekg-dns package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmas...@ftp-master.debian.org) -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Mon, 30 Dec 2019 12:05:08 +1100 Source: golang-github-miekg-dns Architecture: source Version: 1.1.26-1 Distribution: unstable Urgency: medium Maintainer: pkg-go Changed-By: Dmitry Smirnov Closes: 939217 947403 Changes: golang-github-miekg-dns (1.1.26-1) unstable; urgency=medium . [ Alexandre Viau ] * Point Vcs-* urls to salsa.debian.org. . [ Martín Ferrari ] * debian/control: Depend on latest x/net. * debian/control: Update golang dependency to 1.10. . [ Dmitry Smirnov ] * New upstream release + fixed CVE-2019-19794 (Closes: #947403) * Build with "go generate" * (Build-)Depends += "golang-golang-x-sync-dev" * Removed transitional package "golang-dns-dev" (Closes: #939217) Thanks, Holger Levsen. * DH to version 12 * Standards-Version: 4.4.1 * Added myself to Uploaders Checksums-Sha1: 9c314d283044b64975434aec4f0e26dbfd6cfd5c 2413 golang-github-miekg-dns_1.1.26-1.dsc 402f1f2af6e40662467187d7aae9b3f31a035f21 143892 golang-github-miekg-dns_1.1.26.orig.tar.xz 47a6447dd6cf800d348734d1841b07838f805e45 5312 golang-github-miekg-dns_1.1.26-1.debian.tar.xz 62eab0c9b0ed93cb58b1f518622c4053dcd1989f 6331 golang-github-miekg-dns_1.1.26-1_amd64.buildinfo Checksums-Sha256: 606f85c178ddbc19c2e65822d6114152999a2c4773d2f798302310c524de84dc 2413 golang-github-miekg-dns_1.1.26-1.dsc 0f62be201f8711ad6e23d61808f779305879e65b489589436dc23b89681f3008 143892 golang-github-miekg-dns_1.1.26.orig.tar.xz 548dcff4100bdbe5864df11a6f0719953fe8997188df128eb7e4f6977c9f4478 5312 golang-github-miekg-dns_1.1.26-1.debian.tar.xz 3213566c0400c0d44290a466aaa70b2531028254f078ba33be5451df27af84c2 6331 golang-github-miekg-dns_1.1.26-1_amd64.buildinfo Files: 8b26c0b0635a4e0c547cdf043d867b67 2413 devel optional golang-github-miekg-dns_1.1.26-1.dsc fa6411bc496254ac4fe672611b2d4022 143892 devel optional golang-github-miekg-dns_1.1.26.orig.tar.xz c110998f5e1d8aef121eb1ba38b7637d 5312 devel optional golang-github-miekg-dns_1.1.26-1.debian.tar.xz bf03d23b4ea6bd251ff5ca0b3874c428 6331 devel optional golang-github-miekg-dns_1.1.26-1_amd64.buildinfo -BEGIN PGP SIGNATURE- iQIzBAEBCAAdFiEEULx8+TnSDCcqawZWUra72VOWjRsFAl5OHu0ACgkQUra72VOW jRvbfw/+N9G5dPQWNoo/LnKCT6ZhYJSlnD46U59GkY2S/9wQvMloO6Vd3oQQyw+s fXA+D5tunz/c3Cdgv8OqGWb4CYgk+zl+8xj4/w+zfBO0fwC4mYjZchVp5PNDdy1W 7Yybio1j3LQVSPIlJzJor59n1x+vHzG1HLG0zwd2I+lH9Q+MZG54Sc1rMIpbiWap 6
[pkg-go] golang-github-miekg-dns_1.1.26-1_source.changes ACCEPTED into unstable
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Mon, 30 Dec 2019 12:05:08 +1100 Source: golang-github-miekg-dns Architecture: source Version: 1.1.26-1 Distribution: unstable Urgency: medium Maintainer: pkg-go Changed-By: Dmitry Smirnov Closes: 939217 947403 Changes: golang-github-miekg-dns (1.1.26-1) unstable; urgency=medium . [ Alexandre Viau ] * Point Vcs-* urls to salsa.debian.org. . [ Martín Ferrari ] * debian/control: Depend on latest x/net. * debian/control: Update golang dependency to 1.10. . [ Dmitry Smirnov ] * New upstream release + fixed CVE-2019-19794 (Closes: #947403) * Build with "go generate" * (Build-)Depends += "golang-golang-x-sync-dev" * Removed transitional package "golang-dns-dev" (Closes: #939217) Thanks, Holger Levsen. * DH to version 12 * Standards-Version: 4.4.1 * Added myself to Uploaders Checksums-Sha1: 9c314d283044b64975434aec4f0e26dbfd6cfd5c 2413 golang-github-miekg-dns_1.1.26-1.dsc 402f1f2af6e40662467187d7aae9b3f31a035f21 143892 golang-github-miekg-dns_1.1.26.orig.tar.xz 47a6447dd6cf800d348734d1841b07838f805e45 5312 golang-github-miekg-dns_1.1.26-1.debian.tar.xz 62eab0c9b0ed93cb58b1f518622c4053dcd1989f 6331 golang-github-miekg-dns_1.1.26-1_amd64.buildinfo Checksums-Sha256: 606f85c178ddbc19c2e65822d6114152999a2c4773d2f798302310c524de84dc 2413 golang-github-miekg-dns_1.1.26-1.dsc 0f62be201f8711ad6e23d61808f779305879e65b489589436dc23b89681f3008 143892 golang-github-miekg-dns_1.1.26.orig.tar.xz 548dcff4100bdbe5864df11a6f0719953fe8997188df128eb7e4f6977c9f4478 5312 golang-github-miekg-dns_1.1.26-1.debian.tar.xz 3213566c0400c0d44290a466aaa70b2531028254f078ba33be5451df27af84c2 6331 golang-github-miekg-dns_1.1.26-1_amd64.buildinfo Files: 8b26c0b0635a4e0c547cdf043d867b67 2413 devel optional golang-github-miekg-dns_1.1.26-1.dsc fa6411bc496254ac4fe672611b2d4022 143892 devel optional golang-github-miekg-dns_1.1.26.orig.tar.xz c110998f5e1d8aef121eb1ba38b7637d 5312 devel optional golang-github-miekg-dns_1.1.26-1.debian.tar.xz bf03d23b4ea6bd251ff5ca0b3874c428 6331 devel optional golang-github-miekg-dns_1.1.26-1_amd64.buildinfo -BEGIN PGP SIGNATURE- iQIzBAEBCAAdFiEEULx8+TnSDCcqawZWUra72VOWjRsFAl5OHu0ACgkQUra72VOW jRvbfw/+N9G5dPQWNoo/LnKCT6ZhYJSlnD46U59GkY2S/9wQvMloO6Vd3oQQyw+s fXA+D5tunz/c3Cdgv8OqGWb4CYgk+zl+8xj4/w+zfBO0fwC4mYjZchVp5PNDdy1W 7Yybio1j3LQVSPIlJzJor59n1x+vHzG1HLG0zwd2I+lH9Q+MZG54Sc1rMIpbiWap 6AGVTjcx5LztBlPa30kajsupIXb0TaLjvYCQ0iCQMW2h4UL2gp68R8418yF+mSmA 0ArxgrcEdswmfb56ALQvO8wKIAAQ+yfqJLY++Uz22YpJY63qsi/TBESjzad+itPz TeN33N6pZDfs4cbt6qKQKOLSdPO+hQx3YK9AdCpShTPPu2DBQ0JeyKxpHS948wS2 WhHm4m05DIEVtPUPxiJ8lZFapdiQsi9owp/zMXZUaJJhGEMACVZ6IMTxvRQgsC1o iSHEMqE3rP8XhiIf+VIvD+pTQfeiO7FxaErQc+Mm9AH/0GOWmHNl4EX4QQOM3P96 QGycTomWsZKzfIvQZBP8P2WHUivC6aB876y+gsdSuL+KaCLSE2Qlocjnn7O0A9P0 AhyopXTz3CcM2gvTWsOy6dYyyDP9P3jz8sqFXoNw7iCXeYWo3kHRzldw+BmYe5SO c+X01oiNsksNMJylYX4nUUzFQPqGOr4UpjZt93p+gyAZ+vSHSPE= =4pD0 -END PGP SIGNATURE- Thank you for your contribution to Debian. ___ Pkg-go-maintainers mailing list Pkg-go-maintainers@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-go-maintainers
[pkg-go] Processing of golang-github-miekg-dns_1.1.26-1_source.changes
golang-github-miekg-dns_1.1.26-1_source.changes uploaded successfully to localhost along with the files: golang-github-miekg-dns_1.1.26-1.dsc golang-github-miekg-dns_1.1.26.orig.tar.xz golang-github-miekg-dns_1.1.26-1.debian.tar.xz golang-github-miekg-dns_1.1.26-1_amd64.buildinfo Greetings, Your Debian queue daemon (running on host usper.debian.org) ___ Pkg-go-maintainers mailing list Pkg-go-maintainers@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-go-maintainers
[pkg-go] golang-github-hashicorp-go-rootcerts_1.0.2-1_source.changes ACCEPTED into unstable
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Thu, 20 Feb 2020 09:51:49 +1100 Source: golang-github-hashicorp-go-rootcerts Architecture: source Version: 1.0.2-1 Distribution: unstable Urgency: medium Maintainer: Debian Go Packaging Team Changed-By: Dmitry Smirnov Changes: golang-github-hashicorp-go-rootcerts (1.0.2-1) unstable; urgency=medium . [ Alexandre Viau ] * Point Vcs-* urls to salsa.debian.org. . [ Dmitry Smirnov ] * New upstream release. * DH to version 12. * Fixed "watch" file. * Rules-Requires-Root: no. * Standards-Version: 4.5.0. * Added myself to Uploaders. Checksums-Sha1: 3c36c2e1a9c5e43db570d6a7ec58f581720f6cf6 2376 golang-github-hashicorp-go-rootcerts_1.0.2-1.dsc 512ffa3edfe484f78cc41be9537572a9d1fe500b 11472 golang-github-hashicorp-go-rootcerts_1.0.2.orig.tar.xz 25882270163af4e6a12a2106c688208932aa05a6 2564 golang-github-hashicorp-go-rootcerts_1.0.2-1.debian.tar.xz 8563ad8ea9e989dfb762b5510979d82bed5e3680 6158 golang-github-hashicorp-go-rootcerts_1.0.2-1_amd64.buildinfo Checksums-Sha256: dbd137f801997ed93b8e2592c640f55665e28a2f372de50b8cdb2a3095611068 2376 golang-github-hashicorp-go-rootcerts_1.0.2-1.dsc 9bc69e1bb4a92bc452053f3de20ca2c493b92dfdefd1bcef68f2e7cb91d44adf 11472 golang-github-hashicorp-go-rootcerts_1.0.2.orig.tar.xz eaa8d2ec8dc476a71832ce2b2cfa533d94b753c555be62c9f12338aad36432cb 2564 golang-github-hashicorp-go-rootcerts_1.0.2-1.debian.tar.xz 2379fb4650cca2d215f0c2c895b28d0a30f5997dea4b9a971baa075dda008e14 6158 golang-github-hashicorp-go-rootcerts_1.0.2-1_amd64.buildinfo Files: 1c3462a30b3111c4a605470559ec6b60 2376 devel optional golang-github-hashicorp-go-rootcerts_1.0.2-1.dsc 5ab75740d3f4b5c2568ca163863f6028 11472 devel optional golang-github-hashicorp-go-rootcerts_1.0.2.orig.tar.xz 6065442f825c1fdccef6d459d21f4331 2564 devel optional golang-github-hashicorp-go-rootcerts_1.0.2-1.debian.tar.xz bfdf3246e97df450881ede1b0f711623 6158 devel optional golang-github-hashicorp-go-rootcerts_1.0.2-1_amd64.buildinfo -BEGIN PGP SIGNATURE- iQIzBAEBCAAdFiEEULx8+TnSDCcqawZWUra72VOWjRsFAl5NvOMACgkQUra72VOW jRtWmxAAnEeVzfSlvYy5sVpqf0JiO3EYlZ8lciz+gKUYRu1tssXPrvb5isWNdfdo AtVtgmJjdBAJSpMwflRNOudJLHYWvSMlDoOvnOv+UB9cB08ZoVuVlFzgDiZAJnNf QHxtthXDazAmQC0xPV3HROYL6MgkspFzRMFUtu6XCD6A6O/zh0S1o1n3E7qqccs3 TjCJ+0s/zVl4qYzkOu941eFIIHTUzAGcJHld2BfQvYHnSHKcQt+M81Cz1bLqN6Ln gxn0u6RrzeSwBOBlqwJEXDyIL4fp19Ybtf7QU67Ztg4g3se0ZGFkAMmkHhjmvn53 WiOyacg0BNYw52G/DLOl8MAY3hv3WF19mXc1peV73RGm8odog4DVx30I/Ctywu/c rRKoRlNsEXlsMl2WJB+LhJQNZWvpgCN7BopPH+pp6jJwZvaxd+VM7fg7i/pxW+FP Hn31DgptvAAw+9/aMg8ushVaGeddAMfCoohENzL/hdLswiF4gJYjrZS4urnrjFfz lyhgQ048V3SlsmEsFUlA7di47rvKqxNBnC/D/XDFW5hw/to64rW/91w3kj58gkxd 8kxiWe0FZ2GYG68ejPea6LlfTjzCEySltOBitojUrB99QmOzOenenz0UYByMRJRx bTB6Z8UpBzaMbk9eC/LGgzNdypOZQXN0b97sKhaX7FCM5dls/1g= =Wnrg -END PGP SIGNATURE- Thank you for your contribution to Debian. ___ Pkg-go-maintainers mailing list Pkg-go-maintainers@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-go-maintainers
[pkg-go] Processing of golang-github-hashicorp-go-rootcerts_1.0.2-1_source.changes
golang-github-hashicorp-go-rootcerts_1.0.2-1_source.changes uploaded successfully to localhost along with the files: golang-github-hashicorp-go-rootcerts_1.0.2-1.dsc golang-github-hashicorp-go-rootcerts_1.0.2.orig.tar.xz golang-github-hashicorp-go-rootcerts_1.0.2-1.debian.tar.xz golang-github-hashicorp-go-rootcerts_1.0.2-1_amd64.buildinfo Greetings, Your Debian queue daemon (running on host usper.debian.org) ___ Pkg-go-maintainers mailing list Pkg-go-maintainers@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-go-maintainers