Your message dated Mon, 08 Jun 2026 21:09:34 +0000
with message-id <[email protected]>
and subject line Bug#1118629: fixed in ckermit 416~beta12-1+deb13u1
has caused the Debian Bug report #1118629,
regarding reportbug: ckermit built with older version of OpenSSL than in trixie
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1118629: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1118629
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: ckermit
Version: 416~beta12-1
Severity: normal

Dear Maintainer,

ckermit reports a mismatch between the OpenSSL version it was built with
and the version currently available in trixie.

    ?OpenSSL libraries do not match required version:
      . C-Kermit built with OpenSSL 3.4.1 11 Feb 2025
      . Version found  OpenSSL 3.5.1 1 Jul 2025
      OpenSSL versions 1.0.0 or newer must be the same
      major and minor version number, and Kermit may not
      be used with a version of OpenSSL older than the one
      supplied at compile time.
      Set LD_LIBRARY_PATH for OpenSSL 3.4.1 11 Feb 2025.
      Or rebuild C-Kermit from source on this computer to make versions agree.
      C-Kermit makefile target: linux+ssl
      Or if that is what you did then try to find out why
      the program loader (image activator) is choosing a
      different OpenSSL library than the one specified in the build.

      All SSL/TLS features disabled.

Fortunately this does not affect my use of ckermit over a serial line but
would affect users who use any of the functionality dependent on OpenSSL.

-- System Information:
Debian Release: 13.1
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.12.48+deb13-amd64 (SMP w/4 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages ckermit depends on:
ii  debconf [debconf-2.0]  1.5.91
ii  libc6                  2.41-12
ii  libncurses6            6.5+20250216-2
ii  libpam0g               1.7.0-5
ii  libssl3t64             3.5.1-1+deb13u1
ii  libtinfo6              6.5+20250216-2

Versions of packages ckermit recommends:
ii  openssh-client [ssh-client]  1:10.0p1-7

Versions of packages ckermit suggests:
pn  openbsd-inetd | inet-superserver  <none>

-- debconf information:
  ckermit/iksd-anon: false
  ckermit/iksd: false
  ckermit/iksd-no-inetd:
  ckermit/iksd-anondir: /srv/ftp

--- End Message ---
--- Begin Message ---
Source: ckermit
Source-Version: 416~beta12-1+deb13u1
Done: Adrian Bunk <[email protected]>

We believe that the bug you reported is fixed in the latest version of
ckermit, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Adrian Bunk <[email protected]> (supplier of updated ckermit package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 04 Mar 2026 19:30:35 +0200
Source: ckermit
Architecture: source
Version: 416~beta12-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: John Goerzen <[email protected]>
Changed-By: Adrian Bunk <[email protected]>
Closes: 1118629 1123025
Changes:
 ckermit (416~beta12-1+deb13u1) trixie; urgency=medium
 .
   * Non-maintainer upload.
 .
   [ John Goerzen ]
   * CVE-2025-68920: Block remote control of the local kermit by default.
     Closes: #1123025
   * Permanently disable OpenSSL version check.  Closes: #1118629.
Checksums-Sha1:
 ca0dfd9a061f417924291a0743e3c198530600d9 1954 ckermit_416~beta12-1+deb13u1.dsc
 e01b6b6de78f21782604ec2cd645852db15eadf8 2353340 ckermit_416~beta12.orig.tar.gz
 bce2c9f0325b7743997b2fc91c942283a209ce4c 25128 
ckermit_416~beta12-1+deb13u1.debian.tar.xz
Checksums-Sha256:
 3f3976f0056abf224884b541926eaddcfbd3a088c59c2ecae4a4626bde2c2bea 1954 
ckermit_416~beta12-1+deb13u1.dsc
 1e38f6f813a8d97ec46bc1002c1bc389a3a3412b1188ace5027143d5c561c5ab 2353340 
ckermit_416~beta12.orig.tar.gz
 3fb9a9d125700186805e715f27abe856d97714131043c21e0e6d267f2e71ee1c 25128 
ckermit_416~beta12-1+deb13u1.debian.tar.xz
Files:
 19c18c0e80c5b0e3718e0bacc0718fb8 1954 comm optional 
ckermit_416~beta12-1+deb13u1.dsc
 3e3e18619b8bfa84b0fd99b17292d743 2353340 comm optional 
ckermit_416~beta12.orig.tar.gz
 35ccb26cf7eb2651389319244c400476 25128 comm optional 
ckermit_416~beta12-1+deb13u1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmoiwy8ACgkQiNJCh6LY
mLEIug//aRHqLDtdv5PKqtLwS62ccWi7z+ocRf1Ojzglo+jT7gYU6fzORCxcdNzN
nRp0YPBX6BZva6cq6n3ZHIwzd1ZL+lM4+elP5DEbVt6TR8qKWrU83IFXEWanqnFW
9RnW/R9lE6ysS447IdFOij31mlz8OeL1NRPIyPXBD94JQBz//4X/uxaSZbGUMdlV
Z0PV5SbJLACXcSU3L3t7PJxiXdZ5mqj/dqgrEfcWCJPIdeDcKcnMgzhKFpvx/wAS
VLULd8iAG7Ak56BwVBqYeFTSB36uR39JDMTj1xmnDrSxbLwXtKbFKHuRwucMMAhU
Qos2tjDu9VtfuDGDCPFow8p7PJRVzZngokCpljSP/eQaGzqKvVof5I3zx8t6ILW8
apHdxuLHZkebFBwz3GBzHSXEIUobrQ135gxA+D2kqPTb6dMQP1vCScf2czWRRBJ7
VzFKU78A5Rz5xRcPp0PP6wYcNKn9QM3fZdL4HQQfFYu/WNIyN/iq3V8Mp/eG84AG
3e3Uh1VdBAfdv2eBPEKBceOA7quyTbMsSs+1l3+ijOBacW0q//kgVZrZWjXscJzT
rUFauZlRTW3x9rIfCugBNA3ifEWFdU7Y/GkflNbqt6TmMQKNPd08yytXEdfw43JY
5rHtpGS8N6Xzr47GmdFl1N8bKX2PNusukOD/owNh+XBHcjJKeIg=
=baeQ
-----END PGP SIGNATURE-----

Attachment: pgpPrDEZqGUz_.pgp
Description: PGP signature


--- End Message ---

Reply via email to