Your message dated Mon, 17 Jul 2017 23:05:07 +0000
with message-id <e1dxf4d-000cxa...@fasolo.debian.org>
and subject line Bug#868162: fixed in nodejs 6.11.1~dfsg-1
has caused the Debian Bug report #868162,
regarding July 11th Security release
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
868162: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=868162
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: nodejs
Severity: grave
Tags: security

Hi,
please see https://nodejs.org/en/blog/release/v4.8.4/
and https://nodejs.org/en/blog/release/v6.11.1/

The hash see vulnerabiliy doesn't have a CVE ID yet and the
c-ares one is being addressed via the sec:c-ares package.

Cheers,
        Moritz

--- End Message ---
--- Begin Message ---
Source: nodejs
Source-Version: 6.11.1~dfsg-1

We believe that the bug you reported is fixed in the latest version of
nodejs, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 868...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jérémy Lal <kapo...@melix.org> (supplier of updated nodejs package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Tue, 18 Jul 2017 00:40:24 +0200
Source: nodejs
Binary: nodejs-dev nodejs nodejs-dbg nodejs-legacy
Architecture: source
Version: 6.11.1~dfsg-1
Distribution: experimental
Urgency: medium
Maintainer: Debian Javascript Maintainers 
<pkg-javascript-devel@lists.alioth.debian.org>
Changed-By: Jérémy Lal <kapo...@melix.org>
Description:
 nodejs     - evented I/O for V8 javascript
 nodejs-dbg - evented I/O for V8 javascript (debug)
 nodejs-dev - evented I/O for V8 javascript (development files)
 nodejs-legacy - evented I/O for V8 javascript (legacy symlink)
Closes: 864735 868162
Changes:
 nodejs (6.11.1~dfsg-1) experimental; urgency=medium
 .
   * New upstream version 6.11.1~dfsg
   * Priority: optional on source package (Closes: #864735)
 .
   [ Upstream ]
   * Security fix: Constant Hashtable Seeds (CVE pending)
     Closes: #868162.
Checksums-Sha1:
 6b664846a5916f3f9fbe11d5c98ce103739b8303 2575 nodejs_6.11.1~dfsg-1.dsc
 29d5e7936ff6a55af6f98d4552481650c66e914c 11617895 
nodejs_6.11.1~dfsg.orig.tar.gz
 4385e45de1ec719bf503b1ebf93ded96c2ec118d 61440 
nodejs_6.11.1~dfsg-1.debian.tar.xz
 46888a1fdd23eef773ccaaee5c03b6c47283c6e5 7101 
nodejs_6.11.1~dfsg-1_source.buildinfo
Checksums-Sha256:
 6effcd7c582454d4a6d8562503ff856170d85f7468f0b08072b1ce65a314df07 2575 
nodejs_6.11.1~dfsg-1.dsc
 5e8d1a18def4f7bb111472bb3cf2e19f7460423750d5e4a700dd4c3e5c398ea0 11617895 
nodejs_6.11.1~dfsg.orig.tar.gz
 c8240a7b7a7bea5af0a57b1af7b071643a2fba7eebee9c0bb31605fc11350055 61440 
nodejs_6.11.1~dfsg-1.debian.tar.xz
 0be5777dedc59246b800607315bd08050ddf5cc42a0fdf9b4d2ba51123a181d0 7101 
nodejs_6.11.1~dfsg-1_source.buildinfo
Files:
 57b9d8c1edad6bcf5b49372358fa7409 2575 web - nodejs_6.11.1~dfsg-1.dsc
 af1832868595f6c383d3dfa1715c79f3 11617895 web - nodejs_6.11.1~dfsg.orig.tar.gz
 10630afcee730bc9e5429a0e3705e9fb 61440 web - nodejs_6.11.1~dfsg-1.debian.tar.xz
 16eebfdc4d620764f75a49d8404ce957 7101 web - 
nodejs_6.11.1~dfsg-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJGBAEBCAAwFiEEA8Tnq7iA9SQwbkgVZhHAXt0583QFAlltPQISHGthcG91ZXJA
bWVsaXgub3JnAAoJEGYRwF7dOfN0O34QAL8RSuAYXjhdIAHStuxJdm7j3j32AAsE
xDqAoHrs8+PY/iLq7/aDleAAGNxKRvHzL34kEOWCT7XffpCkVkuPpwFoPsIsbMFp
IlYxtWxQideMkJJJfg+Uza2h36saLMBJcLPUiHvLzjc7MRDy5HUV/qEVaWEeFNas
8nAbK7wsCYyQYfITeWJ77yfAsm9d5URrd/K9+0ITJ9kvKiDTJksoQUKZlWY8t1+4
SrvGfBYsup67dZZCLwn2nk2jWVBA4qmztmbYV0s8FLA617kzWp5i6gYH+oRNI3Xs
yIP2bVgjFe6r3UI0cA1vvANvrP0RTjq5XyvP6PH16sHHgKzb8X0BBDzVb6Dm0YOQ
rxTOFWrrmXapAN9fNOIA3sZPtyJ+QbFnRYkdDeqoq2BfiPx2FEl+9qcF6IAF4nsf
GcrGIBXkz8XBJfYZOZEUCX4m4WCkUpHmvywVofQEYvcYbfsy1CfA9nq/sKiXpWaP
9DMQhAP6Y2L5Ft9svBaQsEc/nI+G2ITEwFBwUsdE9OotTciMWgl68w/Ws10Frfpe
PKjFjuZ0cZusoeuR7tC/fVrwn82JYPj/2X8xXVmTGD9p0NpQtz3SYS9mnmEOQB4B
9qpsYpns6CDMO1bML5QA1EuUVALKATmyM9xJ1vmz+43PnWADVRilbXU18xFe5qTh
IeQwtozs6+k6
=YCIO
-----END PGP SIGNATURE-----

--- End Message ---
-- 
Pkg-javascript-devel mailing list
Pkg-javascript-devel@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to