Your message dated Wed, 10 Mar 2021 16:36:17 +0000
with message-id <[email protected]>
and subject line Bug#983698: fixed in spice 0.14.3-2.1
has caused the Debian Bug report #983698,
regarding spice: CVE-2021-20201: Client initiated renegotiation denial of
service
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
983698: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=983698
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: spice
Version: 0.14.3-2
Severity: important
Tags: security upstream
Forwarded: https://gitlab.freedesktop.org/spice/spice/-/issues/49
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 0.14.0-1.3+deb10u1
Control: found -1 0.14.0-1.3
Hi,
The following vulnerability was published for spice.
CVE-2021-20201[0]:
| Client initiated renegotiation denial of service
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2021-20201
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20201
[1] https://gitlab.freedesktop.org/spice/spice/-/issues/49
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: spice
Source-Version: 0.14.3-2.1
Done: Salvatore Bonaccorso <[email protected]>
We believe that the bug you reported is fixed in the latest version of
spice, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated spice package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 28 Feb 2021 16:29:54 +0100
Source: spice
Architecture: source
Version: 0.14.3-2.1
Distribution: unstable
Urgency: medium
Maintainer: Debian QEMU Team <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 983698
Changes:
spice (0.14.3-2.1) unstable; urgency=medium
.
* Non-maintainer upload.
* Client initiated renegotiation denial of service (CVE-2021-20201)
(Closes: #983698)
- With OpenSSL 1.1: Disable client-initiated renegotiation
- With OpenSSL 1.0.2 and earlier: disable client-side renegotiation
Checksums-Sha1:
ab2f826978b81da91079606571be4df60829eb4d 2864 spice_0.14.3-2.1.dsc
dfbb4bdcbd9f0e0af4dc3a73ac2612e70303b288 18824 spice_0.14.3-2.1.debian.tar.xz
5c4db9d212b0c47518e067beb683726ee8c8d683 5792 spice_0.14.3-2.1_source.buildinfo
Checksums-Sha256:
e584358cc89a4d8a28840132bf74983eac674775a6c74dae3443d766a218fcc3 2864
spice_0.14.3-2.1.dsc
fdc44cd7ec389178b56641ec5a8ac69343095601a8e8ce9507e026a61392ae6f 18824
spice_0.14.3-2.1.debian.tar.xz
730f8b5ed15ae3c97ac346598c3e0c9a506d2324961af4c87b0f4f6a373d42b6 5792
spice_0.14.3-2.1_source.buildinfo
Files:
8ec258f1a7a33c7c3e8a73ad25c98144 2864 misc optional spice_0.14.3-2.1.dsc
53af908b4eafe2be20ba5f968ebfa4a1 18824 misc optional
spice_0.14.3-2.1.debian.tar.xz
5f899fc8e02f95f6c00d337e3afb0ee4 5792 misc optional
spice_0.14.3-2.1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmA7ukpfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89ESJ0P/1C4KkJKGKAddMcXTNtZubk9CJZwF/jA
lURSfW4AZihhJTJN1xplMVQfOxxengegJA4N3I7asB7h1FraDfcQzFvt0vZZBIZA
4vHatD7ya0yCZqrtGQrRFKdwRk/igubnv6irF4vzu4gzm5AHzDQcEJPptIDKEbPg
b36La4/M3DcfP7n46zCgOz9cDWIObagQWIBKH0hffTKFepxzkGtljKAWcqp3nLWF
G0uxff5eL0zHDni6I5URRaO84gsx/O2X14K5v3ZIj4MktxNYHIGtVlO7Y8xpQdUj
lE4CU1UlUcb6MFYjLXNb2g0IqtLwJ0Folndn93CoX8VYrY+RH5K4o4Bf612JmXAw
F8HFw/qhjf6s5JvbsdgjVTf7C6bXv9M1ArX8MfHAThvUFKJNTOnWVZikCslxwpvj
HOmuOdncz4xvcXu8fZCCTcS3tl3Ru6rHDy+BA/9p4G3wShdPgUFxK6dE7Oz3G4vu
egefLOmor2pMuiVLl7abGDLBothCrpVrQpbSKvu3PwMjHIXohI7SXKDfNcOGZGlA
omtn0Gi8ijrZ83hR5/G6mKo5oYhOSfMmceGAfSFfagHon/4a+n4UVLa9spV+O1an
ci4mC962HvHF82qWjLLIerGAW4F0Q+ePWi8dQTJVfTH7S43/V2JWky7a5He/guFp
G9+BkE/3Iy5I
=cUXg
-----END PGP SIGNATURE-----
--- End Message ---