Your message dated Wed, 16 Sep 2009 19:57:18 +0000
with message-id <[email protected]>
and subject line Bug#539899: fixed in openssl 0.9.8c-4etch8
has caused the Debian Bug report #539899,
regarding CVE-2009-2409: spoof certificates by using MD2 design flaws
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
539899: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=539899
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: openssl
Severity: important
Tags: security patch
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for openssl.
CVE-2009-2409[0]:
| The NSS library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4
| and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support
| MD2 with X.509 certificates, which might allow remote attackers to
| spoof certificates by using MD2 design flaws to generate a hash
| collision in less than brute-force time. NOTE: the scope of this
| issue is currently limited because the amount of computation required
| is still large.
If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409
http://security-tracker.debian.net/tracker/CVE-2009-2409
Patch: http://cvs.openssl.org/chngview?cn=18381
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAkp4Cc0ACgkQNxpp46476ar5xwCcCZpTP5SD4GYle1w/WBBDJ3v1
PSAAmwU4C+BHnO1HbIgK5m3MKm55D8jO
=9WpU
-----END PGP SIGNATURE-----
--- End Message ---
--- Begin Message ---
Source: openssl
Source-Version: 0.9.8c-4etch8
We believe that the bug you reported is fixed in the latest version of
openssl, which is due to be installed in the Debian FTP archive:
libcrypto0.9.8-udeb_0.9.8c-4etch8_amd64.udeb
to pool/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch8_amd64.udeb
libssl-dev_0.9.8c-4etch8_amd64.deb
to pool/main/o/openssl/libssl-dev_0.9.8c-4etch8_amd64.deb
libssl0.9.8-dbg_0.9.8c-4etch8_amd64.deb
to pool/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch8_amd64.deb
libssl0.9.8_0.9.8c-4etch8_amd64.deb
to pool/main/o/openssl/libssl0.9.8_0.9.8c-4etch8_amd64.deb
openssl_0.9.8c-4etch8.diff.gz
to pool/main/o/openssl/openssl_0.9.8c-4etch8.diff.gz
openssl_0.9.8c-4etch8.dsc
to pool/main/o/openssl/openssl_0.9.8c-4etch8.dsc
openssl_0.9.8c-4etch8_amd64.deb
to pool/main/o/openssl/openssl_0.9.8c-4etch8_amd64.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Kurt Roeckx <[email protected]> (supplier of updated openssl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.7
Date: Tue, 11 Aug 2009 23:00:55 +0200
Source: openssl
Binary: libssl-dev openssl libssl0.9.8-dbg libcrypto0.9.8-udeb libssl0.9.8
Architecture: source amd64
Version: 0.9.8c-4etch8
Distribution: oldstable-security
Urgency: low
Maintainer: Debian OpenSSL Team <[email protected]>
Changed-By: Kurt Roeckx <[email protected]>
Description:
libcrypto0.9.8-udeb - crypto shared library - udeb (udeb)
libssl-dev - SSL development libraries, header files and documentation
libssl0.9.8 - SSL shared libraries
libssl0.9.8-dbg - Symbol tables for libssl and libcrypt
openssl - Secure Socket Layer (SSL) binary and related cryptographic tools
Closes: 539899
Changes:
openssl (0.9.8c-4etch8) oldstable-security; urgency=low
.
* Remove MD2 from digest algorithm table. (CVE-2009-2409) (Closes: #539899)
Files:
cf94a4986dfcc842080ae3834e74281a 1455 utils optional openssl_0.9.8c-4etch8.dsc
27ce2927820e131fe30fc9645c35be9f 58618 utils optional
openssl_0.9.8c-4etch8.diff.gz
24f7d0f13310d576ee3c8fcb560fb002 1017722 utils optional
openssl_0.9.8c-4etch8_amd64.deb
6261a8f16e97a67c7362c1e5fbe0c0c8 891804 libs important
libssl0.9.8_0.9.8c-4etch8_amd64.deb
34c2cf5bd45d3ab46bca03634783f2ec 580330 debian-installer optional
libcrypto0.9.8-udeb_0.9.8c-4etch8_amd64.udeb
44f16ab718d67701a3747d7f50146310 2187900 libdevel optional
libssl-dev_0.9.8c-4etch8_amd64.deb
076e35dd2b65817753f2d3f89c0422cf 1655898 libdevel extra
libssl0.9.8-dbg_0.9.8c-4etch8_amd64.deb
Package-Type: udeb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iQIcBAEBCgAGBQJKgd7MAAoJEGpMZM6DE7XwjyIP+wdytSMuFsyGFNoMLM9Plt6g
d6ZWD50oEyYqzixIu3o+EHsHTWdt0trleuiO/47yVvpZEB735tOCXJRVf4fdjAJs
LPF8Wb/z8KSyU6/BxdH/AYd1MboHUlw04Qee9CFIwAm5a/ch6zeoJyN7X/RM89Ab
p0r9xE4sYffYIzA5EEI73NNZkR7QSDvBQVxulFLYMfvaErIC48pn9zZZj76ma9rn
5OJeH6ZFTfYWOyqWd8ENC13Siy1LOGrnFtRnSv60UGIVmZ8Z3aryt05wj2TKiudG
mHHc/rGz2cvMewcQ0BFe5CoruM46Mx02sdXCSh+//AAh3stq9wHwnEfZLK8MCSoh
+s10Rl4CCWL4EjiJUR48gZ+WrY1spLCVISp1RYeuZQQ8AEGqec2XHNb2FyvDqsSM
Tez7qnfPKK58KHP+gVTGjAdWaE6FD9Wtrcl9s8VanyCen09noALywKja2Vu68zT/
nKdfHA1PMJmzlVYdQ7cESEigoXvIAq3kJn3BV6YgXCDjsHU1+rpEaC2FYDPB1r6R
c9IpFMguy4B1hSevqpX6RITR70rMl1R8cgeJ21uv+Zowshj3WR37UuJbo0bC9nAK
3lKk/8wVdJePAKkHUO5DfyDPvPBWIfT/3d9g1MByFE+NSpsewyh8a3NkUwfkKeEV
aB8U+OnZoXoNGDVTrjN8
=Os/o
-----END PGP SIGNATURE-----
--- End Message ---