Your message dated Fri, 12 Dec 2008 09:02:04 +0000
with message-id <[email protected]>
and subject line Bug#508473: fixed in drupal6 6.6-1.1
has caused the Debian Bug report #508473,
regarding drupal6: Please update to upstream version 6.7
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
508473: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508473
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: drupal6
Version: 6.6-1
Severity: grave
Tags: security
Justification: user security hole

Drupal 6.7 was released today in response to a cross site request
forgeries. Malicious users may cause the superuser (user 1) to execute
old updates that may damage the database. This is described in the
Drupal advisory SA-2008-073 - http://drupal.org/node/345441

-- System Information:
Debian Release: 5.0
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.26-1-vserver-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash



--- End Message ---
--- Begin Message ---
Source: drupal6
Source-Version: 6.6-1.1

We believe that the bug you reported is fixed in the latest version of
drupal6, which is due to be installed in the Debian FTP archive:

drupal6_6.6-1.1.diff.gz
  to pool/main/d/drupal6/drupal6_6.6-1.1.diff.gz
drupal6_6.6-1.1.dsc
  to pool/main/d/drupal6/drupal6_6.6-1.1.dsc
drupal6_6.6-1.1_all.deb
  to pool/main/d/drupal6/drupal6_6.6-1.1_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Patrick Schoenfeld <[email protected]> (supplier of updated drupal6 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Fri, 12 Dec 2008 09:30:28 +0100
Source: drupal6
Binary: drupal6
Architecture: source all
Version: 6.6-1.1
Distribution: unstable
Urgency: high
Maintainer: Luigi Gangitano <[email protected]>
Changed-By: Patrick Schoenfeld <[email protected]>
Description: 
 drupal6    - a fully-featured content management framework
Closes: 508473
Changes: 
 drupal6 (6.6-1.1) unstable; urgency=high
 .
   * Non-maintainer upload.
   * Urgency high because this fixes a security issue
   * Include upstream patch for SA-2008-073, to fix a security issue:
     The update system is vulnerable to Cross site request forgeries. Malicious
     users may cause the superuser (user 1) to execute old updates that may
     damage the database.
     (Closes: #508473)
Checksums-Sha1: 
 eb56e7c097d354a00c561d21341cdd69cd50ba36 1116 drupal6_6.6-1.1.dsc
 95608cb8308d70f6ef3c6e4203057e13e6149741 16897 drupal6_6.6-1.1.diff.gz
 bd724d95ba8ca3b7cb5b9d562029fcc30390e1d2 1075112 drupal6_6.6-1.1_all.deb
Checksums-Sha256: 
 5c0053644df1828963e2bcf0a05f8d644fe3158ee6a4afd8ffa9058ece447d5d 1116 
drupal6_6.6-1.1.dsc
 fb98b366ed8c30ce1e19fc3d044d4354ec07417acd408675158a12f1ffa4f2b0 16897 
drupal6_6.6-1.1.diff.gz
 f68b4e2cf8b1c6e63e6e361e0074d8f328d62f4ede500a9cb015158391352eac 1075112 
drupal6_6.6-1.1_all.deb
Files: 
 7a5ab826cba6c6a592db031d59cc8893 1116 web extra drupal6_6.6-1.1.dsc
 f8894914a54069536dc2c83707b9ab99 16897 web extra drupal6_6.6-1.1.diff.gz
 1b354423160c575b7ead1213e6efd183 1075112 web extra drupal6_6.6-1.1_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAklCJzAACgkQbdB4RPTVesrvOgCggQVX6xLiFPoWOYA8VSuXRYSf
PwsAnRthJPSAilzLnCM5cWWh2jOOTbn5
=lvP7
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to