Your message dated Sat, 13 Jul 2013 19:03:38 +0000
with message-id <[email protected]>
and subject line Bug#709931: fixed in socat 1.7.1.3-1.5
has caused the Debian Bug report #709931,
regarding socat: CVE-2013-3571: file descriptor leak
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
709931: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=709931
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: socat
Severity: important
Tags: security patch upstream

Hi,

the following vulnerability was published for socat.

CVE-2013-3571[0]:
FD leak

Upstream advisory is at [1], and also contain patches.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3571
    http://security-tracker.debian.org/tracker/CVE-2013-3571
[1] http://www.dest-unreach.org/socat/contrib/socat-secadv4.html

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: socat
Source-Version: 1.7.1.3-1.5

We believe that the bug you reported is fixed in the latest version of
socat, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated socat package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 03 Jul 2013 17:17:33 +0200
Source: socat
Binary: socat
Architecture: source amd64
Version: 1.7.1.3-1.5
Distribution: unstable
Urgency: low
Maintainer: Chris Taylor <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Description: 
 socat      - multipurpose relay for bidirectional data transfer
Closes: 709931
Changes: 
 socat (1.7.1.3-1.5) unstable; urgency=low
 .
   * Non-maintainer upload.
   * Add CVE-2013-3571.patch patch.
     CVE-2013-3571: Fix denial of service due to file descriptor leak.
     (Closes: #709931)
Checksums-Sha1: 
 3e59850e04ff103f31b4e1f37413677e64f07afd 1737 socat_1.7.1.3-1.5.dsc
 cd1bb93d16b17c2da0f50d5a1dccdf20a29ca623 13742 socat_1.7.1.3-1.5.debian.tar.gz
 609123c40dad0d09bff88daf7cb246df93c50c9c 379320 socat_1.7.1.3-1.5_amd64.deb
Checksums-Sha256: 
 3d729985466aa985152e505e83078ef17336eb5ddd40a4a76d615d6d1aa8b529 1737 
socat_1.7.1.3-1.5.dsc
 1a6445dc605d5838994c9520057a140e241dbb05f7088e24d60ff566d54f1b7d 13742 
socat_1.7.1.3-1.5.debian.tar.gz
 feb7eb0167abb3b426b7134bbf58491c999d40ec288805bdc37a8e5fc751c49f 379320 
socat_1.7.1.3-1.5_amd64.deb
Files: 
 4fe4c18113672a7f980e20a73c436c94 1737 net extra socat_1.7.1.3-1.5.dsc
 3b6bc9998b9fcd5507b5ee5b6bf6222f 13742 net extra 
socat_1.7.1.3-1.5.debian.tar.gz
 2d0edb84ca3de77a93c637a1a4023c8f 379320 net extra socat_1.7.1.3-1.5_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBCgAGBQJR1GoFAAoJEHidbwV/2GP+zH4P/3YVkcGaAmlY2FDT0zIJT4au
ozusvGdNvQSTEnzacuoRSv2vm7urBu4GKqAVjIfpXqkah3/m3ikUcm4Hyb7B6Usb
B5hqXIzJuPNANAEh4kV3vQOdy+Yak7Y+cGJ26MkQx5tk7IywVo6RrMNjL6ltHSA7
Aj2UAVpIOhuMzFzNsF+Oe/oTMi+kZsBM7m9SBOeVRorzxXDIpqppJe9JP8AkjCrC
SMoYLYSnSL+HCsIF8F7Hf1U0kU2d0xviIt9qdlgvKmbRDW1QNjwP8dBOSiKWL/h7
tR3uH4IGNsPRiWEedzrJv2hYLeqtfxp2bsDJzFZqgB8spzs04frjYDz2t6aAjet6
7h+4VNXSfkYobtzMcDCoV+JYDnR5SbUZd5BzJCHQRrz9NawM2lxzki7lse0/icQ6
UCo6afkBUnwJJg5U1WZrQuIBSiozOFLLSuJHTmGjaNDubpizy859Z+SpsDGXw8rz
f1trTop+vY9ZYWsH8ZKmRqBaWOXZBSRuWrLtQ3FCqAZuhkLp6NoRMEINCWU0L4Ai
UenOvKRYCioEtNIpmfAoJSq7JkHGiiPOZr7FUymxDqfWf1/yYgC3sIcrZyrJMpb+
EIjjSxMvaEh78daHDgRGHZdq0Z4TuZEgjCZX4cei4JjYgpD5iK43x1E8zB+h4ujn
41TDotchERWVzVaURKm7
=QrKU
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to