Your message dated Wed, 25 May 2016 21:47:13 +0000
with message-id <[email protected]>
and subject line Bug#812923: fixed in chrony 1.30-2+deb8u2
has caused the Debian Bug report #812923,
regarding chrony: CVE-2016-1567
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
812923: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=812923
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: chrony
Version: 1.30-2
Severity: important
Tags: security upstream fixed-upstream

Hi,

the following vulnerability was published for chrony.

CVE-2016-1567[0]:
| chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer
| associations of symmetric keys when authenticating packets, which
| might allow remote attackers to conduct impersonation attacks via an
| arbitrary trusted key, aka a "skeleton key."

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2016-1567

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: chrony
Source-Version: 1.30-2+deb8u2

We believe that the bug you reported is fixed in the latest version of
chrony, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Vincent Blut <[email protected]> (supplier of updated chrony package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sat, 21 May 2016 02:27:34 +0200
Source: chrony
Binary: chrony
Architecture: source amd64
Version: 1.30-2+deb8u2
Distribution: jessie
Urgency: medium
Maintainer: Joachim Wiedorn <[email protected]>
Changed-By: Vincent Blut <[email protected]>
Description:
 chrony     - Set the computer clock from time servers on the Net
Closes: 568492 763542 812923
Changes:
 chrony (1.30-2+deb8u2) jessie; urgency=medium
 .
   * Fix CVE-2016-1567: Restrict authentication of server/peer to specified
     key. (Closes: #812923)
 .
   * debian/postrm:
     - Remove /var/lib/chrony on purge only. (Closes: #568492)
 .
   * debian/logrotate:
     - Rework postrotate script. (Closes: #763542)
Checksums-Sha1:
 98cc6d600faba89028345e4cc98c9c10862ae597 1610 chrony_1.30-2+deb8u2.dsc
 20b2e09e0cb81fe2f9885a41fe17e86c573f4a67 25136 
chrony_1.30-2+deb8u2.debian.tar.xz
 620b238285eb49a916f53c7bdded383669270855 252924 chrony_1.30-2+deb8u2_amd64.deb
Checksums-Sha256:
 481a2765c5545776fa2a719f2bf9676aa4ee7e90290a9e3328d076ec92f630e4 1610 
chrony_1.30-2+deb8u2.dsc
 4eda715c2b455b227c7b9c256abcc66e5e029bd1a29297099abf3a321e256500 25136 
chrony_1.30-2+deb8u2.debian.tar.xz
 1cea85b2e5e796afce2f9b8529b4d3955266eca9619a8b5bcd4f88103c005307 252924 
chrony_1.30-2+deb8u2_amd64.deb
Files:
 7f2fff73027bf1ba71654342feb99d16 1610 admin extra chrony_1.30-2+deb8u2.dsc
 30df4e238e9bd2644e806b15c1e18b0d 25136 admin extra 
chrony_1.30-2+deb8u2.debian.tar.xz
 a28dd93c1dbdc3816bdfea4f64dd7e36 252924 admin extra 
chrony_1.30-2+deb8u2_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBCAAGBQJXRezFAAoJEJxcmesFvXUKK7kIAIKOXlYSH1l9dCRjjRcTIHwM
JHMNjlwPwOQ69k/iKwnUwlc0pplYkOYcxdq9YU2DN3hbpngCcqdM/Nm/hcAd+lnM
0ZQWrNMMTcD8E4mVZGAcUg4Nl9uRZ6/lPI8Rrkhe7NTKE7gIaJ9B4nIzsKe7AM1R
OE3y/SwdEVzw0Kb0dwskm+SA00WPsTbVSoCzAuJY8Hw7+nPeENhrLPXq451lOtG9
IrphauPqZ/5T9JzQ4qEQB+cQ0zco4K1NIR7oftGJiycLQ/3PNMPw2gY2DuC/WEts
hi4FYZ/iTZOabQ4nzTkvqFmSXwuZ3arqceHqAXyOs/wzRod8Z9eRPmXLGZKoMCA=
=1dMJ
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to