Your message dated Thu, 15 Mar 2012 04:17:57 +0000
with message-id <e1s828t-0006k4...@franck.debian.org>
and subject line Bug#664023: fixed in gnash 0.8.10-5
has caused the Debian Bug report #664023,
regarding [CVE-2012-1175] gnash integer overflow
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
664023: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=664023
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: gnash
Severity: grave
Tags: security patch

The following vulnerability had been reported against gnash: 
http://www.openwall.com/lists/oss-security/2012/03/14/5

The patch can be found in the report.

Please use CVE-2012-1175 for this issue and check if the stable version 
(0.8.8-5) is affected. If it's the case, can you prepare and patch for it? I 
can 
take care of the DSA.

Cheers,
luciano

Attachment: signature.asc
Description: This is a digitally signed message part.


--- End Message ---
--- Begin Message ---
Source: gnash
Source-Version: 0.8.10-5

We believe that the bug you reported is fixed in the latest version of
gnash, which is due to be installed in the Debian FTP archive:

browser-plugin-gnash_0.8.10-5_amd64.deb
  to main/g/gnash/browser-plugin-gnash_0.8.10-5_amd64.deb
gnash-common-opengl_0.8.10-5_all.deb
  to main/g/gnash/gnash-common-opengl_0.8.10-5_all.deb
gnash-common_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-common_0.8.10-5_amd64.deb
gnash-cygnal_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-cygnal_0.8.10-5_amd64.deb
gnash-dbg_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-dbg_0.8.10-5_amd64.deb
gnash-dev_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-dev_0.8.10-5_amd64.deb
gnash-doc_0.8.10-5_all.deb
  to main/g/gnash/gnash-doc_0.8.10-5_all.deb
gnash-ext-fileio_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-ext-fileio_0.8.10-5_amd64.deb
gnash-ext-lirc_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-ext-lirc_0.8.10-5_amd64.deb
gnash-ext-mysql_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-ext-mysql_0.8.10-5_amd64.deb
gnash-opengl_0.8.10-5_all.deb
  to main/g/gnash/gnash-opengl_0.8.10-5_all.deb
gnash-tools_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-tools_0.8.10-5_amd64.deb
gnash_0.8.10-5.debian.tar.gz
  to main/g/gnash/gnash_0.8.10-5.debian.tar.gz
gnash_0.8.10-5.dsc
  to main/g/gnash/gnash_0.8.10-5.dsc
gnash_0.8.10-5_amd64.deb
  to main/g/gnash/gnash_0.8.10-5_amd64.deb
klash-opengl_0.8.10-5_all.deb
  to main/g/gnash/klash-opengl_0.8.10-5_all.deb
klash_0.8.10-5_amd64.deb
  to main/g/gnash/klash_0.8.10-5_amd64.deb
konqueror-plugin-gnash_0.8.10-5_amd64.deb
  to main/g/gnash/konqueror-plugin-gnash_0.8.10-5_amd64.deb
mozilla-plugin-gnash_0.8.10-5_all.deb
  to main/g/gnash/mozilla-plugin-gnash_0.8.10-5_all.deb
python-gtk-gnash_0.8.10-5_amd64.deb
  to main/g/gnash/python-gtk-gnash_0.8.10-5_amd64.deb
swfdec-gnome_0.8.10-5_all.deb
  to main/g/gnash/swfdec-gnome_0.8.10-5_all.deb
swfdec-mozilla_0.8.10-5_all.deb
  to main/g/gnash/swfdec-mozilla_0.8.10-5_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 664...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Gabriele Giacone <1o5g4...@gmail.com> (supplier of updated gnash package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 15 Mar 2012 03:04:37 +0100
Source: gnash
Binary: gnash-common gnash klash gnash-tools gnash-cygnal browser-plugin-gnash 
konqueror-plugin-gnash python-gtk-gnash gnash-ext-fileio gnash-ext-mysql 
gnash-ext-lirc gnash-dev gnash-dbg gnash-doc gnash-common-opengl gnash-opengl 
klash-opengl swfdec-mozilla swfdec-gnome mozilla-plugin-gnash
Architecture: source amd64 all
Version: 0.8.10-5
Distribution: unstable
Urgency: low
Maintainer: Debian Flash Team <pkg-flash-de...@lists.alioth.debian.org>
Changed-By: Gabriele Giacone <1o5g4...@gmail.com>
Description: 
 browser-plugin-gnash - GNU Shockwave Flash (SWF) player - Plugin for Mozilla 
and derivat
 gnash      - GNU Shockwave Flash (SWF) player
 gnash-common - GNU Shockwave Flash (SWF) player - Common files/libraries
 gnash-common-opengl - dummy package for gnash-common-opengl removal
 gnash-cygnal - GNU Shockwave Flash (SWF) player - Media server
 gnash-dbg  - GNU Shockwave Flash (SWF) player - Debug symbols
 gnash-dev  - GNU Shockwave Flash (SWF) player - Development files
 gnash-doc  - GNU Shockwave Flash (SWF) player - API documentation
 gnash-ext-fileio - GNU Shockwave Flash (SWF) player - Fileio extension
 gnash-ext-lirc - GNU Shockwave Flash (SWF) player - LIRC extension
 gnash-ext-mysql - GNU Shockwave Flash (SWF) player - MySQL extension
 gnash-opengl - dummy package for gnash-opengl removal
 gnash-tools - GNU Shockwave Flash (SWF) player - Command-line Tools
 klash      - GNU Shockwave Flash (SWF) player - Standalone player for KDE
 klash-opengl - dummy package for klash-opengl removal
 konqueror-plugin-gnash - GNU Shockwave Flash (SWF) player - Plugin for 
Konqueror
 mozilla-plugin-gnash - dummy package for renaming to browser-plugin-gnash
 python-gtk-gnash - GNU Shockwave Flash (SWF) player - Python bindings
 swfdec-gnome - dummy package for transition to Gnash
 swfdec-mozilla - dummy package for transition to browser-plugin-gnash
Closes: 664023
Changes: 
 gnash (0.8.10-5) unstable; urgency=low
 .
   * Fix CVE-2012-1175 (Closes: #664023).
Checksums-Sha1: 
 91df36cfc71f8e412b7a19a9a6e8a5bd27634a2f 3210 gnash_0.8.10-5.dsc
 13516033495a39690b87e575a3e853f8791c4f48 35499 gnash_0.8.10-5.debian.tar.gz
 af4b5453d6300ba2f956180adf0800d363a5b74a 2794282 
gnash-common_0.8.10-5_amd64.deb
 7e420639f25527abaaf32111876a069da28919c8 233364 gnash_0.8.10-5_amd64.deb
 a26d80f20735ae4e79a83c6178c0b13b2347835f 225766 klash_0.8.10-5_amd64.deb
 9880a591abfd01e9f6d790c0b1bbc4f7ec5781b4 178184 gnash-tools_0.8.10-5_amd64.deb
 df3eae16dcf97963e4564ac46d392d7315598aa3 744886 gnash-cygnal_0.8.10-5_amd64.deb
 2e79f5d1ee038a9b1c50a0ccb804def0d420d674 142318 
browser-plugin-gnash_0.8.10-5_amd64.deb
 e8a1bebf5d9fe3794259b1e895ea4d5ee7e62b06 57000 
konqueror-plugin-gnash_0.8.10-5_amd64.deb
 7269324d71693d5d3b8c315acd419cef784ca4a1 97146 
python-gtk-gnash_0.8.10-5_amd64.deb
 86ee3d56b6e074c3f2fbca44d03f034ddadd6400 68960 
gnash-ext-fileio_0.8.10-5_amd64.deb
 20fb2e18d8a428192d75d3e2c6c1b08a61d88266 72152 
gnash-ext-mysql_0.8.10-5_amd64.deb
 ce455c964da45af10cda5c7ae8ffc94a5fa19a2b 62758 
gnash-ext-lirc_0.8.10-5_amd64.deb
 adfcc7d60e53aa9e67835c4bf34f2d3b17750724 261548 gnash-dev_0.8.10-5_amd64.deb
 c638a1442411e3681da413e1780e326815bc7e16 63246656 gnash-dbg_0.8.10-5_amd64.deb
 6d102b02fe0636efe9b0ec8e9db83733eb96d710 5131730 gnash-doc_0.8.10-5_all.deb
 be7e4cda0c933fd8929f41e36478e06a47abb63c 27106 
gnash-common-opengl_0.8.10-5_all.deb
 98a4ea2cdace90e4b5c89f9191b57d5741dae93c 27098 gnash-opengl_0.8.10-5_all.deb
 0ddb7668a9303e1cdfd7d3845f9b63ced41649aa 27100 klash-opengl_0.8.10-5_all.deb
 1c4ef95779b73a565767d90cc2e50b52755301fd 27122 swfdec-mozilla_0.8.10-5_all.deb
 cfa314f5466a56eb15a53a537257cb43155c6f1b 27106 
mozilla-plugin-gnash_0.8.10-5_all.deb
 d3f4c0d34868c5f7d28ead60062136434df037bc 27114 swfdec-gnome_0.8.10-5_all.deb
Checksums-Sha256: 
 cbc3153c9877e25cbafc62b08aac16820372f096830a3adff7b901079ca28605 3210 
gnash_0.8.10-5.dsc
 e092daa62bac5c874b6a008a2c296554dffbe58b98efa5b30b1cf47e490e9e96 35499 
gnash_0.8.10-5.debian.tar.gz
 403a3cbc6e57347fb6bd46c270e4fc36d39832973c8abb3f00c51634bb751ed2 2794282 
gnash-common_0.8.10-5_amd64.deb
 279889592981fc17b53aab8654df8e4fe7d0ea0f961071a173aeb6e588dfb143 233364 
gnash_0.8.10-5_amd64.deb
 95b177c975448f7eb22cf4033b8f7873918a4100856b0771eeda61ec9a314675 225766 
klash_0.8.10-5_amd64.deb
 d1fc0eae96f42f95aeb418ce459bcef26223fef695057798130b02199d2c27e0 178184 
gnash-tools_0.8.10-5_amd64.deb
 4c242ec49058d3da763f465e6de31b03a2b3a6ba7b67e738c36c4b81ae39bf61 744886 
gnash-cygnal_0.8.10-5_amd64.deb
 3a49a0de90bdbcce5d85481f04fd989adf37170241e1c7fdbf07bc34ef715304 142318 
browser-plugin-gnash_0.8.10-5_amd64.deb
 76b0f09e79c9d5013acd0d6e9f6ba16009f4ac7393d16709637139f768c7518c 57000 
konqueror-plugin-gnash_0.8.10-5_amd64.deb
 4ec6090814760c20442db1615ec39cd1cb4bf6816641c6934148838ca6d888e8 97146 
python-gtk-gnash_0.8.10-5_amd64.deb
 636e9c1fd8ed1c0f870a46a3843f1a2d02d634fd9a99724631b4ae81c985435d 68960 
gnash-ext-fileio_0.8.10-5_amd64.deb
 6920b98852ad062a67b2688667569d9e1a2006c7dc4cdc9d2ae47c3ff97e695c 72152 
gnash-ext-mysql_0.8.10-5_amd64.deb
 ecb10cf23d5a5db1ef6adef07a8537e1c4b3f71807ba5cfd048309aa1fe61d81 62758 
gnash-ext-lirc_0.8.10-5_amd64.deb
 0625920f1482c58fa3b363818610d8c3bbd5562d8ef203d04623b7c78c117d13 261548 
gnash-dev_0.8.10-5_amd64.deb
 5e32d7b9205e7a64637d571d4b73032794e77160ff41023995f1c358b05a32b8 63246656 
gnash-dbg_0.8.10-5_amd64.deb
 9e70a0443eec517d51d2d3e903c64497bb24a359bf3fcff8c5800629f591d719 5131730 
gnash-doc_0.8.10-5_all.deb
 0126c89074d59aef741598c0fe28426b1b9f7e369cd2d78eb7e850674aefcbfd 27106 
gnash-common-opengl_0.8.10-5_all.deb
 fe93a328aad1d9680fddc90d854c45c0a9d5cfdafa6597d7e93dd52f658a9e12 27098 
gnash-opengl_0.8.10-5_all.deb
 56d3c7b1635d416c5c7adc5c02fc0fc55fffe1ffebae3a3c7a3ea09dc174f511 27100 
klash-opengl_0.8.10-5_all.deb
 f1c35eea8d4a9daf75aba0913add72ef74c3ea0e3e1289a1f5bca7a4bfc2d6ee 27122 
swfdec-mozilla_0.8.10-5_all.deb
 501dc20f66e51fc6b10e5e340619612c44b6cc77c62910012611715ea03e9d7a 27106 
mozilla-plugin-gnash_0.8.10-5_all.deb
 afb2f08e46b2a3d64db985ad5f6ea270aa8aab7bfd4ec8c8f51d93bec9c3095b 27114 
swfdec-gnome_0.8.10-5_all.deb
Files: 
 df0ac3f885ae0ab195f3a55ac9fbf6f3 3210 video optional gnash_0.8.10-5.dsc
 3953682331973d0731311bfdefee5624 35499 video optional 
gnash_0.8.10-5.debian.tar.gz
 27765ada92a11b5eceebf2fc9d93df03 2794282 video optional 
gnash-common_0.8.10-5_amd64.deb
 b75c02176ba93ce0c5490ce447cef6df 233364 video optional gnash_0.8.10-5_amd64.deb
 e8dadca8f04faecf715dcebf422a7a40 225766 video optional klash_0.8.10-5_amd64.deb
 d3deedb65566f4f01f323517e86bf876 178184 video optional 
gnash-tools_0.8.10-5_amd64.deb
 75ee7f5b9ee26cfea1d48ee4f1b66897 744886 video optional 
gnash-cygnal_0.8.10-5_amd64.deb
 bb0a79cf6fc03ab5f8438cd2ee5a66b8 142318 video optional 
browser-plugin-gnash_0.8.10-5_amd64.deb
 cc0138cc5ea8524ae1fc419adfcbae81 57000 video optional 
konqueror-plugin-gnash_0.8.10-5_amd64.deb
 36b0cda50a82f9ac7116f0b90a9db6f0 97146 python optional 
python-gtk-gnash_0.8.10-5_amd64.deb
 3f00ed3b0236784b8e80a877cb89900c 68960 video optional 
gnash-ext-fileio_0.8.10-5_amd64.deb
 dbc977b3509f2a012609b130706fd982 72152 video optional 
gnash-ext-mysql_0.8.10-5_amd64.deb
 e8d1634ecbeb8cb5d6faef9462e9991e 62758 video optional 
gnash-ext-lirc_0.8.10-5_amd64.deb
 10114e3ff253cb4d7394f79348351783 261548 libdevel optional 
gnash-dev_0.8.10-5_amd64.deb
 3e8c1b58a86fcd1febb31a1e283d7877 63246656 debug extra 
gnash-dbg_0.8.10-5_amd64.deb
 77554b3e65abf428eba69e59a75bab24 5131730 doc optional 
gnash-doc_0.8.10-5_all.deb
 8f33d90423737366a27334fd33518d57 27106 oldlibs extra 
gnash-common-opengl_0.8.10-5_all.deb
 7cfea63ef93e6a68b9e6f696f1256e21 27098 oldlibs extra 
gnash-opengl_0.8.10-5_all.deb
 f76fe20a7ae37ef94a4b6920757a5952 27100 oldlibs extra 
klash-opengl_0.8.10-5_all.deb
 297fffac180107a745db6b4fbd5902cb 27122 oldlibs extra 
swfdec-mozilla_0.8.10-5_all.deb
 9999d107ac82df34bd06e40d1c22914c 27106 oldlibs extra 
mozilla-plugin-gnash_0.8.10-5_all.deb
 33f10a419786ae64e9385c698b3a5dd1 27114 oldlibs extra 
swfdec-gnome_0.8.10-5_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAk9hZH8ACgkQp3cdCbVcnCuviACeIY+mQrjh+VM14bjUY688dAsu
XNgAoIUJrd4WEbsg7aW8Sq2WnToYk9bu
=HuxS
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to