Your message dated Wed, 20 Jan 2010 21:47:17 +0000
with message-id <[email protected]>
and subject line Bug#558355: fixed in lucene2 2.9.1+ds1-3
has caused the Debian Bug report #558355,
regarding lucene2: Please mention that CVE-2007-2383 has been fixed on next 
upload
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
558355: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=558355
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: lucene2
Severity: important

Hi

A recent upload of lucene2 fixed #555225; but did not mention that
this fixed CVE-2007-2383. This causes the security tracker to
believe that lucene2 is still affected.

Therefore please mention that CVE-2007-2383 has been fixed in the
changelog on next upload.

Thank you in advance,
~Niels

-- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.30-2-686 (SMP w/2 CPU cores)
Locale: LANG=en_DK.UTF-8, LC_CTYPE=en_DK.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash



--- End Message ---
--- Begin Message ---
Source: lucene2
Source-Version: 2.9.1+ds1-3

We believe that the bug you reported is fixed in the latest version of
lucene2, which is due to be installed in the Debian FTP archive:

liblucene2-java-doc_2.9.1+ds1-3_all.deb
  to main/l/lucene2/liblucene2-java-doc_2.9.1+ds1-3_all.deb
liblucene2-java_2.9.1+ds1-3_all.deb
  to main/l/lucene2/liblucene2-java_2.9.1+ds1-3_all.deb
lucene2_2.9.1+ds1-3.diff.gz
  to main/l/lucene2/lucene2_2.9.1+ds1-3.diff.gz
lucene2_2.9.1+ds1-3.dsc
  to main/l/lucene2/lucene2_2.9.1+ds1-3.dsc



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jan-Pascal van Best <[email protected]> (supplier of updated lucene2 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Wed, 20 Jan 2010 13:54:48 +0100
Source: lucene2
Binary: liblucene2-java liblucene2-java-doc
Architecture: source all
Version: 2.9.1+ds1-3
Distribution: unstable
Urgency: low
Maintainer: Debian Java Maintainers 
<[email protected]>
Changed-By: Jan-Pascal van Best <[email protected]>
Description: 
 liblucene2-java - Full-text search engine library for Java(TM)
 liblucene2-java-doc - Documentation for Lucene
Closes: 558355
Changes: 
 lucene2 (2.9.1+ds1-3) unstable; urgency=low
 .
   * Mention in this changelog that CVE-2007-2383 has been fixed
     (Closes: #558355; Fix CVE-2007-2383)
   * Providing OSGi metadata in the Manifest for the
     core and contrib packages (needed for building Eclipse).
Checksums-Sha1: 
 f491e5cd0255b55fa6ed914cc784771f66a0178a 1852 lucene2_2.9.1+ds1-3.dsc
 99cb9030daef2d8d5c1c70e427a39517cfcfca52 16389 lucene2_2.9.1+ds1-3.diff.gz
 44b22b4e314aaf793df0ed023d476cccdeaeccaf 5839806 
liblucene2-java_2.9.1+ds1-3_all.deb
 9704bb7216a5596cee8bacd39c88439e7dab3ba2 7297432 
liblucene2-java-doc_2.9.1+ds1-3_all.deb
Checksums-Sha256: 
 0027d20f8bdb84e7543961fd61919dada31d8329275c605d267f7ebace00831a 1852 
lucene2_2.9.1+ds1-3.dsc
 c3ffda3f502d1454508476106a079efd96c0b31743dea0dd31e6052392286a54 16389 
lucene2_2.9.1+ds1-3.diff.gz
 3abd2dac79f8ff40a7dc4c8806f7cc4d057780b58ce1a1e73b701dcec3de36a6 5839806 
liblucene2-java_2.9.1+ds1-3_all.deb
 6c0840246c27d7eefecd16b7995a8b32e3525cda4638d9d7a0f057d0f1429268 7297432 
liblucene2-java-doc_2.9.1+ds1-3_all.deb
Files: 
 eb05764227c974eb13c09d0d0aa7258f 1852 java optional lucene2_2.9.1+ds1-3.dsc
 340088353ef94ce4e7b759d5d2c50b41 16389 java optional 
lucene2_2.9.1+ds1-3.diff.gz
 48e961a8f2e9dea61074d273ac4872b9 5839806 java optional 
liblucene2-java_2.9.1+ds1-3_all.deb
 131371fe82cd935de1a9f820f5146e79 7297432 doc optional 
liblucene2-java-doc_2.9.1+ds1-3_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAktXbxYACgkQOkyycBqJzCPWrgCgifQOEKdfMDwCaSn3LwgbvLKT
QlUAoJFDbbRK2HxtdSF+4c2FDAkX3Wsd
=pCL9
-----END PGP SIGNATURE-----



--- End Message ---
_______________________________________________
pkg-java-maintainers mailing list
[email protected]
http://lists.alioth.debian.org/mailman/listinfo/pkg-java-maintainers

Reply via email to