Your message dated Thu, 07 Jan 2010 21:33:04 +0000 with message-id <e1nszya-0005bk...@ries.debian.org> and subject line Bug#512674: fixed in aiccu 20070115-11 has caused the Debian Bug report #512674, regarding leaves password in debconf database to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact ow...@bugs.debian.org immediately.) -- 512674: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512674 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems
--- Begin Message ---Package: aiccu Version: 20070115-9 Severity: normal If you look at /var/cache/debconf/passwords.dat, you'll probably find a copy of the password in there. While the file is only readable by root, this is an unnecessary way to leak the password. Best practice for password prompting with debconf is to call db_reset to clear the password out of the database as soon as possible after you use it. -- System Information: Debian Release: 5.0 APT prefers unstable APT policy: (500, 'unstable') Architecture: i386 (i686) Kernel: Linux 2.6.27-1-686 (SMP w/2 CPU cores) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/bash Versions of packages aiccu depends on: ii debconf 1.5.24 Debian configuration management sy ii iproute 20080725-2 networking and traffic control too ii iputils-ping 3:20071127-1 Tools to test the reachability of ii iputils-tracepath 3:20071127-1 Tools to trace the network path to ii libc6 2.7-18 GNU C Library: Shared libraries ii libgnutls26 2.4.2-4 the GNU TLS library - runtime libr ii lsb-base 3.2-20 Linux Standard Base 3.2 init scrip Versions of packages aiccu recommends: ii ntpdate 1:4.2.4p4+dfsg-8 client for setting system time fro aiccu suggests no packages. -- debconf information excluded -- see shy josignature.asc
Description: Digital signature
--- End Message ---
--- Begin Message ---Source: aiccu Source-Version: 20070115-11 We believe that the bug you reported is fixed in the latest version of aiccu, which is due to be installed in the Debian FTP archive: aiccu_20070115-11.diff.gz to main/a/aiccu/aiccu_20070115-11.diff.gz aiccu_20070115-11.dsc to main/a/aiccu/aiccu_20070115-11.dsc aiccu_20070115-11_i386.deb to main/a/aiccu/aiccu_20070115-11_i386.deb A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 512...@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Reinier Haasjes <rein...@haasjes.com> (supplier of updated aiccu package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmas...@debian.org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 06 Jan 2010 10:02:24 +0100 Source: aiccu Binary: aiccu Architecture: source i386 Version: 20070115-11 Distribution: unstable Urgency: low Maintainer: Reinier Haasjes <rein...@haasjes.com> Changed-By: Reinier Haasjes <rein...@haasjes.com> Description: aiccu - SixXS Automatic IPv6 Connectivity Client Utility Closes: 512674 529185 531003 559683 561324 562803 Changes: aiccu (20070115-11) unstable; urgency=low . * New maintainer. (Closes: #529185: ITA: aiccu -- SixXS Automatic IPv6 Connectivity Client Utility) * Install aiccu.conf to usr/share/aiccu/conf-templates/ and use in postinst (Closes: #559683) - Thanks to Patrick Schoenfeld * Fix "leaves password in debconf database" add db_reset to postinst (Closes: #512674) * Fix "tunnel does not survive suspend" Add restart script to /etc/pm/sleep.d (Closes: #531003) * Added Japanese translation (Closes: #562803) - Thanks to Hideki Yamane * Fix "uses non-essential tools in the config script" (Closes: #561324) - get brokers list by dns (instead of own binary) - supply static brokerlist if dns is unavailable - get tunnel ID in postinst (using own binary) * Minimize rules file - Thanks to Patrick Schoenfeld * Added VCS-Headers * Fixed spelling-error-in-binary * Fixed maintainer-script-empty preinst * Fixed maintainer-script-without-set-e postinst * Upgraded compat version to 7 * Added debian/README.source * Upgraded standards-version to 3.8.3 * Added "no-upstream-changelog" to lintian-overrides * Add dependency on ucf Checksums-Sha1: 2e38ca6c2b391a7b5e68a84a4ef2a33918534cec 1128 aiccu_20070115-11.dsc 123233e0e202e4fe87441950341500823da03c59 23487 aiccu_20070115-11.diff.gz f36e0dc9830c002c648c32c0d427dd496b240d44 47656 aiccu_20070115-11_i386.deb Checksums-Sha256: f0a0f2dce5f9c629aa6940ce51972d5329edbca904bbb817c947c9849d2d5e17 1128 aiccu_20070115-11.dsc e036d67859552d3e4fb601a8f3ac94d695f9667f52328fcf27c63536f1200078 23487 aiccu_20070115-11.diff.gz 9a98deb945d4a2721b580c10b21cf75797b64d9ed907783f9b86ba4fa49fe3ec 47656 aiccu_20070115-11_i386.deb Files: ad9b9e8488d6adec83baa29c7ff7d2dc 1128 net optional aiccu_20070115-11.dsc 645bde58455ca0b2585e0f0f8d000f05 23487 net optional aiccu_20070115-11.diff.gz bb9ac22f98dd5e6f096d538eb841caa8 47656 net optional aiccu_20070115-11_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAktGOe4ACgkQBxd04ADYzRbVkACfZ+9ck2wooYv/sRHXyKTTWNhl ulcAoIvUaKMZrJovA93xXT4MY1W1U2ha =jRgq -----END PGP SIGNATURE-----
--- End Message ---