Your message dated Wed, 05 Nov 2014 22:04:17 +0000
with message-id <e1xm8gb-000211...@franck.debian.org>
and subject line Bug#768191: fixed in konversation 1.5-2
has caused the Debian Bug report #768191,
regarding CVE-2014-8483: konversation: out-of-bounds read issue
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
768191: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=768191
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: konversation
Version: 1.5-1
Severity: important

Check for invalid input in encrypted buffers

The ECB Blowfish decryption function assumed that encrypted input would
always come in blocks of 12 characters, as specified. However, buggy
clients or annoying people may not adhere to that assumption, causing
the core to crash while trying to process the invalid base64 input.

(Description copied from http://bugs.quassel-irc.org/issues/1314)



-- System Information:
Debian Release: jessie/sid
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'testing'), (500, 'stable'), (110, 
'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.16-3-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages konversation depends on:
ii  kde-runtime        4:4.14.2-1
ii  kdepim-runtime     4:4.14.2-1
ii  konversation-data  1.5-1
ii  libc6              2.19-12
ii  libgcc1            1:4.9.1-19
ii  libkabc4           4:4.14.2-1
ii  libkde3support4    4:4.14.2-3
ii  libkdecore5        4:4.14.2-3
ii  libkdeui5          4:4.14.2-3
ii  libkemoticons4     4:4.14.2-3
ii  libkidletime4      4:4.14.2-3
ii  libkio5            4:4.14.2-3
ii  libknotifyconfig4  4:4.14.2-3
ii  libkparts4         4:4.14.2-3
ii  libkresources4     4:4.14.2-1
ii  libnepomuk4        4:4.14.2-3
ii  libnepomukutils4   4:4.14.2-3
ii  libphonon4         4:4.8.0-3
ii  libqca2            2.0.3-6
ii  libqt4-dbus        4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii  libqt4-network     4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii  libqt4-qt3support  4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii  libqt4-svg         4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii  libqt4-xml         4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii  libqtcore4         4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii  libqtgui4          4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii  libsolid4          4:4.14.2-3
ii  libsoprano4        2.9.4+dfsg-1.1
ii  libstdc++6         4.9.1-19
ii  phonon             4:4.8.0-3

konversation recommends no packages.

konversation suggests no packages.

-- no debconf information

--- End Message ---
--- Begin Message ---
Source: konversation
Source-Version: 1.5-2

We believe that the bug you reported is fixed in the latest version of
konversation, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 768...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Diane Trout <di...@ghic.org> (supplier of updated konversation package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 05 Nov 2014 22:47:53 +0100
Source: konversation
Binary: konversation konversation-data konversation-dbg
Architecture: source all
Version: 1.5-2
Distribution: unstable
Urgency: medium
Maintainer: Debian KDE Extras Team <pkg-kde-extras@lists.alioth.debian.org>
Changed-By: Diane Trout <di...@ghic.org>
Description:
 konversation - user friendly Internet Relay Chat (IRC) client for KDE
 konversation-data - data files for Konversation
 konversation-dbg - debugging symbols for Konversation
Closes: 768191
Changes:
 konversation (1.5-2) unstable; urgency=medium
 .
   * Backport fix for CVE-2014-8483 in cve-2014-8483.patch
     See https://security-tracker.debian.org/tracker/CVE-2014-8483
     (Closes: #768191)
Checksums-Sha1:
 7078a68fd4cff676cc1647aa1889b019532ba880 2239 konversation_1.5-2.dsc
 3464adc2a071d1c291e1670018e65134e7cf30e6 26604 konversation_1.5-2.debian.tar.xz
 0f5eb1a083204f3b2d9a34c283abc5e9c6717197 3029346 
konversation-data_1.5-2_all.deb
Checksums-Sha256:
 d39b8b4dd21c748ba13301c455fb4f6cc52bd8eeca6e030bd69e9ee873ccdae8 2239 
konversation_1.5-2.dsc
 6d7007a522cc183ae1526edefed96ff2890310586dcb8284cf0d002258373444 26604 
konversation_1.5-2.debian.tar.xz
 dc039b81bba3c64c88e69f2811b57ec74c474b0e9552f7649958b366499c7099 3029346 
konversation-data_1.5-2_all.deb
Files:
 12c9b181be45e67f7448a993b1fa1639 2239 net optional konversation_1.5-2.dsc
 8fd45454e9fc3efa67d1e4c2f1086c09 26604 net optional 
konversation_1.5-2.debian.tar.xz
 513c935d854110f91262cf3726145ae0 3029346 net optional 
konversation-data_1.5-2_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJUWp19AAoJEP4ixv2DE11Fn0UP/2oVNav+UF2moWDVxhSvBpe+
h3l3Hndu+AiuLuuQfsS6dBKZuhJL65+/wobmfKVs/9EaZpupWo3esHR7gWJIs2Os
5O2esZsRK8bGxzcCjoo/B+0E6drogcUGKZCUcccq24CLCjmir+cN9lsXb57ZU9i0
SALHRWrCBuhZkDFn65cyIBrVHNj/RmgpHUWr1fibcBTjgEE72RdWawmA9qbSg6gs
E7hQGTi/yRfNsFZ5m8tAGTjX9PbBdO09FfwmDY7YCGIwNUAwZxtGr0T2Sw2/jiLr
XDTuKEBU12oyBTcyfdI22kSwc4QktX9zgO28i5f52/tUkJuU3FM7sdF7PbRAC4sm
xtzgy0BQs8Wuwp/xniJK0Ae5hld6FsVwOgr/ifqSsF8bFkS5l8tWub0gqMAnSX9t
PYcRiea0vDguZ6vsbiQZKCzUzH6OFn0ut/KdfIu8NOEx5FCqsU16tj4uv4ZlJEIj
evtftbYVmn+TSo/6eHtZERITo9k1iCr0aWR0vsK3N855LvsEBn7sgSV2lYunoTqq
JH4aJbu57n46SMjoAU71Xeb57dgYhIBgdbz+QWIY+1SvO92A/FnP7p2ecvY8h7Fy
Dia9zcqKGVpaLN8NXKFMa4YuDYFfzx3SwPDIXLdj6wuYE4FVwMpQFsup3fl8jB0a
AZzaIz/vjVj4YqjWvJXW
=7jIo
-----END PGP SIGNATURE-----

--- End Message ---
_______________________________________________
pkg-kde-extras mailing list
pkg-kde-extras@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-kde-extras

Reply via email to