Bug#908055: docker.io: CVE-2017-14992

2018-09-05 Thread Shengjing Zhu
On Thu, Sep 6, 2018 at 9:40 AM Arnaud Rebillout wrote: > > > On 09/05/2018 10:22 PM, Shengjing Zhu wrote: > > Dear docker.io maintainer, > > > > I'm not sure why the Built-Using field in docker.io doesn't contain > > golang-github-vbatts-tar-split. Maybe dh-golang can't deal with the > >

Bug#908055: docker.io: CVE-2017-14992

2018-09-05 Thread Arnaud Rebillout
On 09/05/2018 10:22 PM, Shengjing Zhu wrote: > Dear docker.io maintainer, > > I'm not sure why the Built-Using field in docker.io doesn't contain > golang-github-vbatts-tar-split. Maybe dh-golang can't deal with the > docker.io repo. Not sure it's whose bug... Built-Using is supposed to reflect

Bug#908055: docker.io: CVE-2017-14992

2018-09-05 Thread Shengjing Zhu
Dear docker.io maintainer, I'm not sure why the Built-Using field in docker.io doesn't contain golang-github-vbatts-tar-split. Maybe dh-golang can't deal with the docker.io repo. Not sure it's whose bug... Since the version in unstable/testing is not uploaded with source-only, so the buildd

Bug#908055: docker.io: CVE-2017-14992

2018-09-05 Thread Antoine Beaupre
Package: docker.io X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Control: clone -1 -2 Control: reassign -2 golang-github-vbatts-tar-split Hi, The following vulnerability was published for docker.io. CVE-2017-14992[0]: | Lack of content verification in Docker-CE (Also