Your message dated Fri, 30 Mar 2018 19:48:31 +0000
with message-id <e1f200l-0004jx...@fasolo.debian.org>
and subject line Bug#892766: fixed in icu 57.1-6+deb9u2
has caused the Debian Bug report #892766,
regarding CVE-2017-15422
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
892766: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=892766
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: icu
Severity: grave
Tags: security
Hi Laszlo,
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
refers to a ICU vulnerability, but there's little information what fixes/fixed
that.
Could you reach out to upstream whether they've been in touch with them so that
we can pinpoint this a specific task/commit?
Cheers,
Moritz
--- End Message ---
--- Begin Message ---
Source: icu
Source-Version: 57.1-6+deb9u2
We believe that the bug you reported is fixed in the latest version of
icu, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 892...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <g...@debian.org> (supplier of updated icu package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Wed, 14 Mar 2018 18:28:38 +0000
Source: icu
Binary: libicu57 libicu57-dbg libicu-dev icu-devtools icu-devtools-dbg icu-doc
Architecture: source amd64 all
Version: 57.1-6+deb9u2
Distribution: stretch-security
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <g...@debian.org>
Changed-By: Laszlo Boszormenyi (GCS) <g...@debian.org>
Description:
icu-devtools - Development utilities for International Components for Unicode
icu-devtools-dbg - Development utilities for International Components for
Unicode (d
icu-doc - API documentation for ICU classes and functions
libicu-dev - Development files for International Components for Unicode
libicu57 - International Components for Unicode
libicu57-dbg - International Components for Unicode (debug symbols)
Closes: 892766
Changes:
icu (57.1-6+deb9u2) stretch-security; urgency=high
.
* Backport upstream security fix for CVE-2017-15422: Persian calendar
integer overflow (closes: #892766).
Checksums-Sha1:
4073b22b886813d5fd6b374bc03e4e771bb7dbfe 2133 icu_57.1-6+deb9u2.dsc
ca5f5cc584f45e87bf56bf8b7f9244d12a5ada67 22360664 icu_57.1.orig.tar.gz
72ba82cd89ff744a8ec4b0db7e43de6368220e9e 34240 icu_57.1-6+deb9u2.debian.tar.xz
d2682ecb512aea6b6cac29e580c3e3df9cdef7ad 642646
icu-devtools-dbg_57.1-6+deb9u2_amd64.deb
b2b51590499ee2ba76685cf90ac8935ee6a08386 177666
icu-devtools_57.1-6+deb9u2_amd64.deb
ca19855eaa80187d393ee4bff12697151def6bc7 2396828 icu-doc_57.1-6+deb9u2_all.deb
ba77e6611ecfa6b4031d6c94fd9ed4445214c054 7564 icu_57.1-6+deb9u2_amd64.buildinfo
4560de98d57726ad8d4a2bc02c8b0fafc5304144 16480276
libicu-dev_57.1-6+deb9u2_amd64.deb
4c2e4851be6d633b463d09b2147cd431fd8a4a38 7370114
libicu57-dbg_57.1-6+deb9u2_amd64.deb
8d02adaaa0189459ecc5678c62c8ec7330f3fce5 7700438
libicu57_57.1-6+deb9u2_amd64.deb
Checksums-Sha256:
a25881728746f3a882fce270b9a8c957d4a8e3999b8871a0781ec2099555ad32 2133
icu_57.1-6+deb9u2.dsc
ff8c67cb65949b1e7808f2359f2b80f722697048e90e7cfc382ec1fe229e9581 22360664
icu_57.1.orig.tar.gz
7f7ca8e89cca1a21616c72b4f89c7beacb78c369323219ddd0021053a5e1aa38 34240
icu_57.1-6+deb9u2.debian.tar.xz
5bd06c742144bcd1f11556df4c12ced88d2e184e798c5444529191a6e570a28b 642646
icu-devtools-dbg_57.1-6+deb9u2_amd64.deb
cee97b47f3bf70b6896fdd4544564f4d576a2ab69de08819704bffcb19d8e8b1 177666
icu-devtools_57.1-6+deb9u2_amd64.deb
9732f54b49e98c17af84233267ce24aa32277481736218a6a0afd134095c713e 2396828
icu-doc_57.1-6+deb9u2_all.deb
c65c40143641cbbfc360656f3a522f1c121294825bfa814bf59c1604184d379e 7564
icu_57.1-6+deb9u2_amd64.buildinfo
1fcda52fcc0929880f63eb7c76d05a2dfb3ec037b60b058dcd41fc894ae92c27 16480276
libicu-dev_57.1-6+deb9u2_amd64.deb
1b4aab7756788418fa16f2e745e99d3c2552261c0f43ae3a8c9b3fc39fe2e5aa 7370114
libicu57-dbg_57.1-6+deb9u2_amd64.deb
c2dee82e7ae8fa4dc8fd0d9ad5a28cd41598cfccf5d0a71d0cd6a6bb4ac71f25 7700438
libicu57_57.1-6+deb9u2_amd64.deb
Files:
c3bac1c585be1cd72cdf2755d1c31d21 2133 libs optional icu_57.1-6+deb9u2.dsc
976734806026a4ef8bdd17937c8898b9 22360664 libs optional icu_57.1.orig.tar.gz
d7723b250eadd82d811d13b072f56ab6 34240 libs optional
icu_57.1-6+deb9u2.debian.tar.xz
759dcb856b3e128bdc9d0437568cd79f 642646 debug extra
icu-devtools-dbg_57.1-6+deb9u2_amd64.deb
c7596dd31f2e339ef47f630ee0e92bea 177666 libdevel optional
icu-devtools_57.1-6+deb9u2_amd64.deb
5c79c1a6bf12a20d1907dd615144f1e3 2396828 doc optional
icu-doc_57.1-6+deb9u2_all.deb
72bc97882b84508034db381da44f924f 7564 libs optional
icu_57.1-6+deb9u2_amd64.buildinfo
8bdd8882a8fa8327ef30a994b8ded630 16480276 libdevel optional
libicu-dev_57.1-6+deb9u2_amd64.deb
24ee138b4115d9b91165e8d3f6a9d589 7370114 debug extra
libicu57-dbg_57.1-6+deb9u2_amd64.deb
6c9dfd2fb77fdc813885f51647352efa 7700438 libs optional
libicu57_57.1-6+deb9u2_amd64.deb
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAlqzR9UACgkQ3OMQ54ZM
yL+J/hAAgpj2hFyDn78YHgN+QPk1P5iLEuPtc3AHRg4t//pr+EHxCHaMcvmsCT98
04EUtobF2EPtv2Rd8NBDFVeSL8OAmnUpAnam7ZNevqKrUWTntn+wgyFhOIb2L9EX
G0zbTHmOMjRgHMuoa45NjqR9vj2egwaArPJTxjoklh+9L+OV3oCDs9SQQB38bBY2
mSs5hipbKJtY1MTf7+vRCokzqC01XPrCDfgixGPSAi7yBV9zC9t1kPY2LOH8emCB
n+Y9W+ZFxgYZkwuKi9hjrFt5L/t5IjmpO/TqTrTcKxteFMSsmpEt1NIidpxNDjFh
7rS6kRjSXAZAvO8eQkrbJxaQl5DWOW3DUInwaLlc50J6TBK51CQqbVEZxltngbGg
whxQ60j0/AKtYvYUBvhyJJez5OH0Hjmhx4rhDpNU4UI5wCLPuxQ4UtWSEQ3QIc2N
uTRopIbSyztgVKymR2WUhmsTWQ3nB+E5u7rJ3EP1HgFhE9A/G0Y0Bnj56uc2wjjv
b9XLnciiLbnj57n10IBTdjGpiQluam0DjyFbGaxpYnSoLs9sfMQkxItL0EDEhxT5
9viioMiTnqVRx4AJxbkS4JHSl3jN7t9aZhhSlLKNh8/QdrzCUUkgss2HlMs4E2GU
p0cgX5sRYBmmRlZPek4IgltqyihdHdPJ65HLgVB0GZyijoh0xXo=
=VDQ4
-----END PGP SIGNATURE-----
--- End Message ---