Your message dated Thu, 22 Jul 2021 06:16:27 +0200
with message-id <[email protected]>
and subject line [[email protected]: Accepted redis 5:6.0.15-1 
(source) into unstable]
has caused the Debian Bug report #991365,
regarding krb5: CVE-2021-36222
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
991365: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=991365
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: krb5
Version: 1.18.3-5
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for krb5.

CVE-2021-36222[0]:
| sending a request containing a PA-ENCRYPTED-CHALLENGE padata element
| without using FAST could result in null dereference in the KDC which
| leads to DoS

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2021-36222
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36222
[1] https://github.com/krb5/krb5/commit/fc98f520caefff2e5ee9a0026fdf5109944b3562

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: redis
Source-Version: 5:6.0.15-1

----- Forwarded message from Debian FTP Masters 
<[email protected]> -----

Date: Wed, 21 Jul 2021 21:50:11 +0000
From: Debian FTP Masters <[email protected]>
To: [email protected]
Subject: Accepted redis 5:6.0.15-1 (source) into unstable
Resent-From: [email protected]
Reply-To: [email protected]
Message-Id: <[email protected]>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 21 Jul 2021 22:21:54 +0100
Source: redis
Built-For-Profiles: nocheck
Architecture: source
Version: 5:6.0.15-1
Distribution: unstable
Urgency: medium
Maintainer: Chris Lamb <[email protected]>
Changed-By: Chris Lamb <[email protected]>
Changes:
 redis (5:6.0.15-1) unstable; urgency=medium
 .
   * New upstream security release.
     - CVE-2021-32761: Integer overflow issues with BITFIELD command
       on 32-bit systems.
   * Bump Standards-Version to 4.5.1.
Checksums-Sha1:
 5ff4ac0f849353deeae893e0a0af3f135fa2496c 2264 redis_6.0.15-1.dsc
 b11db088d5db518f257d73258d65ced61279e606 2302141 redis_6.0.15.orig.tar.gz
 e0c6482efd1fba394a4a5896dcf13b16d1cb4141 29132 redis_6.0.15-1.debian.tar.xz
 de95c81dd4cfe55753c9de11aeffaf2dbfd0fd7b 7301 redis_6.0.15-1_amd64.buildinfo
Checksums-Sha256:
 6ef42e05ccd18b5b4e5c393975948b4fc752ee5ab50d0b1023fb77899b02485c 2264 
redis_6.0.15-1.dsc
 00e65fae3307bf73a1197dda7f533f06d8688eb8e097f49cd3bd0958f3ffa5c5 2302141 
redis_6.0.15.orig.tar.gz
 49eb004bfc804e561b87621b36f1c85e82fb005f702ca591898fba062100f543 29132 
redis_6.0.15-1.debian.tar.xz
 55de2e270d0597f494b107563f148603b72689924a909d32514a6f621d24111a 7301 
redis_6.0.15-1_amd64.buildinfo
Files:
 60d3d1840975fcb3f1c8f45bee54949e 2264 database optional redis_6.0.15-1.dsc
 6a799917b7af7a754ca621c053b650d0 2302141 database optional 
redis_6.0.15.orig.tar.gz
 30ec264d3af363b259575cd37ff993fe 29132 database optional 
redis_6.0.15-1.debian.tar.xz
 aaea01a1c52574dd1391b16a911db718 7301 database optional 
redis_6.0.15-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmD4kD0ACgkQHpU+J9Qx
Hljibg/8DqOWjGjqm/p+joH3vhwJgMcmmY1akMQRQ9XYbSUPd+gFBF5DpsfXIu20
gBEwiRsXGj/EecZQ90lCdLOEMoQnyI3tALkSoiFcYPlRvKBfCbZguuqIEe89luT+
94fwk1HC21ri+nAOIWw7MmaPLjGJ1P78fM3Ti8/hGwDbDgDV9izOG9UKx4j/izsu
W2wND+0zy3/YI4jChjz81aauPhQHBcxEtkVVJYThgNsRTNmiByVRnt9Wx68a7BY5
kYfOxaKVQXxfr9yjyxjADk11pUYl4crsSUPnP/+15dtpL43gDRd673TXIIVKAgWy
eNZPBOhTPTe6lCL3Rb/qLCHa62mkHFyhnCT6h0em/dspO8mp81o2ONqlLPeYMcKd
dGMoGee3hc8bKbXoSSGLwHmi1pwpm+J9omfoRuHkrcIOEfGSLzXF/+UojJgobfjA
Clt5i8SBD7L/q2d4GNn2ijmdiYL0kirSIkPeDHKzLH7pDpNS2KEAqXBHJgEJioBV
jqkm5PnNESaU48QldRNPDzEuILLE+UqRoDVSKB4VHylb5TN7tUCAiBtwaTjbwamh
B20zRRh0vgJIYCKVHgbM+jGtyDLH9phohfuwgdbybSUPNWVKDyrz38APQzqAtAbe
2NMqa+PVhFJ5YgmrZw++4rvq4p5+vmYMkyhaVvCdKOP077vyKK4=
=Hj1x
-----END PGP SIGNATURE-----


----- End forwarded message -----

--- End Message ---

Reply via email to