Your message dated Sat, 03 Sep 2016 13:23:40 +0000
with message-id <[email protected]>
and subject line Bug#836371: fixed in gnutls28 3.5.3-4
has caused the Debian Bug report #836371,
regarding ocsptool --ask segfault
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
836371: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=836371
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: gnutls-bin
Version: 3.5.3-3
Severity: important

Hi,

the "STARTTLS-fix" makes ocsptool segfault as it tries to use a NULL
session.

I think the following upstream commit tries to fix it, but did not test
it:

    
https://gitlab.com/gnutls/gnutls/commit/4d8e1f716794bf7ca267091bb2017dfd73770762

I could provide a backtrace if needed, but it really crashes everytime
you have it send a request (i.e. --ask).

--- End Message ---
--- Begin Message ---
Source: gnutls28
Source-Version: 3.5.3-4

We believe that the bug you reported is fixed in the latest version of
gnutls28, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Andreas Metzler <[email protected]> (supplier of updated gnutls28 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 03 Sep 2016 14:00:22 +0200
Source: gnutls28
Binary: libgnutls28-dev libgnutls30 gnutls-bin gnutls-doc libgnutlsxx28 
libgnutls-openssl27
Architecture: source
Version: 3.5.3-4
Distribution: unstable
Urgency: high
Maintainer: Debian GnuTLS Maintainers <[email protected]>
Changed-By: Andreas Metzler <[email protected]>
Closes: 836371
Description: 
 gnutls-bin - GNU TLS library - commandline utilities
 gnutls-doc - GNU TLS library - documentation and examples
 libgnutls28-dev - GNU TLS library - development files
 libgnutls30 - GNU TLS library - main runtime library
 libgnutls-openssl27 - GNU TLS library - OpenSSL wrapper
 libgnutlsxx28 - GNU TLS library - C++ runtime library
Changes:
 gnutls28 (3.5.3-4) unstable; urgency=high
 .
   * 39_ocsptool-corrected-bug-in-session-establishment.patch: Fix segfault of
     ocsptool --ask ... Closes: #836371
   * 40_ocsp-corrected-the-comparison-of-the-serial-size-in-.patch: OCSP
     certificate check doesn't actually verify the serial length and might
     succeed when it shouldn't.
Checksums-Sha1: 
 b92a5edb3574fd5fc9265a9f90e482505eee2719 2847 gnutls28_3.5.3-4.dsc
 a3aef79b8f48b0e17d84383e6a3cf9d5f52df377 99320 gnutls28_3.5.3-4.debian.tar.xz
Checksums-Sha256: 
 a777d281e64116a2448e2c595378cb4a74029a6d4e3a93c6b287e1cc9ef3068e 2847 
gnutls28_3.5.3-4.dsc
 511bd5d829b6ab3eae0bdeb0bba8b124fbc4bf63308396bf90bc67baee1b5e28 99320 
gnutls28_3.5.3-4.debian.tar.xz
Files: 
 5617177f75df0345b5cf6618ba7aedb0 2847 libs optional gnutls28_3.5.3-4.dsc
 b76a9d5e93e8e0c219a3b5345421b7a2 99320 libs optional 
gnutls28_3.5.3-4.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJXysBtAAoJEKVPAYVDghSEqZgP/RZABvwW3dV/RC+rq4eI63Ps
lq7U4bjAKlZi9LlywJFMm7q1C3NomBuqvqIQd5cVovSzodrGRYVJolITXBgLfUg3
vg3h/mh1rPt77s0ga+9iIIHT3XbBbtAhwTc4GLorFRCIQ/ZYC70sok/YrWBAjxoP
xvQnvJVTI7ZKaxRuSc36b02/gg686CxtYc4KCET8QplVigKO57arhOPeS4sT2jH6
qAsL+JldX17XPfgyIra9p1m1dF2U7m6lJc7KZrLUy2PvmazB4zUlIsrBcO/wR1np
C8Jy6z2hZVdiCueZgWk1KBTTA6uKdZytPEQI2I1gZARx2kUF33BUKnzCP1HGPWSx
0XqRfU7hCsxsTFAmYQUGPi7xi9EsxC4hIsr/kDHX2eHn7QHyOhvP2qb0+HjaBrwE
H7hFWb0ta2jcbHT1rT2fmfHdtlH5K2VO9L9PLub5OaHemyLHZMynV+ugfaBr4d3P
Bt3mLOu/4ZjRXmIXmArHV2ibwNarDtrOQb+V0+nywLrJcbSKsxt3vi0sE+1Jrd1A
5rpDJzCLXd68B3fxgWCOZewLiwZgJTCoa9kwqz39TQFil93AgQE7u5Dgg91akmdO
jw7rAx01Lwpqa0/S+hi7Tz3rX+/gzxTw15pSalao/5xt8B/fr3pWmSW4A2jj63qf
8U5b6pFxZ2FeVWG86YSO
=NEHY
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to