[Python-modules-team] Bug#781640: Downgrading bug severity

2015-07-09 Thread Daniele Tricoli
Hello Salvatore, On Tuesday 07 July 2015 14:07:31 Salvatore Bonaccorso wrote: > Thanks for this status update. (really appreciated!) Sorry for the additional delay! I completed the updated package and I already sent a requests for sponsor! I mentioned on debian/changelog the same link about the

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-07-07 Thread Salvatore Bonaccorso
Hi Daniele, On Tue, Jul 07, 2015 at 02:01:59PM +0200, Daniele Tricoli wrote: > Hello Salvatore, > > On Monday 06 July 2015 20:49:24 Salvatore Bonaccorso wrote: > > Increasing again the severity, since we have it fixed in > > jessie-security but not yet included as well for stretch. > > Thanks an

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-07-07 Thread Daniele Tricoli
Hello Salvatore, On Monday 06 July 2015 20:49:24 Salvatore Bonaccorso wrote: > Increasing again the severity, since we have it fixed in > jessie-security but not yet included as well for stretch. Thanks and sorry for the delay and the missed deadline, but I had some important stuff to take care

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-07-06 Thread Salvatore Bonaccorso
Control: severity -1 serious Hi On Wed, Jul 01, 2015 at 08:17:05AM +0200, Salvatore Bonaccorso wrote: > Hey Daniele, > > On Wed, Jun 24, 2015 at 12:23:19AM +0200, Daniele Tricoli wrote: > > On Saturday 20 June 2015 15:38:44 Alessandro Ghedini wrote: > > > I just released the DSA for jessie. > >

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-06-30 Thread Salvatore Bonaccorso
Hey Daniele, On Wed, Jun 24, 2015 at 12:23:19AM +0200, Daniele Tricoli wrote: > On Saturday 20 June 2015 15:38:44 Alessandro Ghedini wrote: > > I just released the DSA for jessie. > > Many thanks! > > > What's the status for the unstable > > upload? > > My plan is to have it uploaded by the end

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-06-23 Thread Daniele Tricoli
On Saturday 20 June 2015 15:38:44 Alessandro Ghedini wrote: > I just released the DSA for jessie. Many thanks! > What's the status for the unstable > upload? My plan is to have it uploaded by the end of this week. Kind regards, -- Daniele Tricoli 'Eriol' https://mornie.org signature.asc De

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-06-20 Thread Alessandro Ghedini
On Thu, Jun 18, 2015 at 09:17:40PM +0200, Daniele Tricoli wrote: > On Wednesday 17 June 2015 22:49:24 Moritz Mühlenhoff wrote: > > Any feedback from your sponsor? > > Sorry I was a bit busy so I finalized the package only now. :( > > Already sent an RFS and Piotr is usually very fast, so it shoul

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-06-18 Thread Daniele Tricoli
On Wednesday 17 June 2015 22:49:24 Moritz Mühlenhoff wrote: > Any feedback from your sponsor? Sorry I was a bit busy so I finalized the package only now. :( Already sent an RFS and Piotr is usually very fast, so it should be uploaded soon. Kind regards, -- Daniele Tricoli 'Eriol' https://mo

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-06-17 Thread Moritz Mühlenhoff
On Fri, Jun 05, 2015 at 12:17:56PM +0200, Moritz Mühlenhoff wrote: > On Fri, Jun 05, 2015 at 03:58:23AM +0200, Daniele Tricoli wrote: > > Hello, > > > > On Sunday 31 May 2015 12:00:17 Moritz Mühlenhoff wrote: > > > What's the status? > > > > Sorry for the delay! I cherry picked and adapted the pa

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-06-05 Thread Moritz Mühlenhoff
On Fri, Jun 05, 2015 at 03:58:23AM +0200, Daniele Tricoli wrote: > Hello, > > On Sunday 31 May 2015 12:00:17 Moritz Mühlenhoff wrote: > > What's the status? > > Sorry for the delay! I cherry picked and adapted the patch for pyjwt > version in Jessie. I worked on this branch: > https://anonscm.deb

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-06-04 Thread Daniele Tricoli
Hello, On Sunday 31 May 2015 12:00:17 Moritz Mühlenhoff wrote: > What's the status? Sorry for the delay! I cherry picked and adapted the patch for pyjwt version in Jessie. I worked on this branch: https://anonscm.debian.org/viewvc/python-modules/packages/pyjwt/branches/0.2.1/ The package build f

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-05-31 Thread Moritz Mühlenhoff
On Mon, Apr 13, 2015 at 04:25:24PM +0200, Daniele Tricoli wrote: > On Saturday 11 April 2015 14:50:19 Luke Faraone wrote: > > However, the package is vulnerable to the other issue: > > > > - If the secretKey was expected to be a RSA public key, but the attacker > > changed the header to indicate a

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-04-13 Thread Daniele Tricoli
On Saturday 11 April 2015 14:50:19 Luke Faraone wrote: > However, the package is vulnerable to the other issue: > > - If the secretKey was expected to be a RSA public key, but the attacker > changed the header to indicate a signature algorithm of HMAC, the RSA > public key would be used as the sig

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-04-11 Thread Luke Faraone
On 11 April 2015 at 13:37, Daniele Tricoli wrote: > On Thursday 09 April 2015 09:19:03 Thomas Goirand wrote: > > If the package isn't vulnerable, shouldn't this bug report be closed? If > > that's the case, then I'll let you close it. In the mean while, I'll > > downgrade the severity to normal,

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-04-11 Thread Daniele Tricoli
Hello, sorry for the delay and thanks Thomas: I had forgotten to subscribe to pyjwt : ( On Thursday 09 April 2015 09:19:03 Thomas Goirand wrote: > If the package isn't vulnerable, shouldn't this bug report be closed? If > that's the case, then I'll let you close it. In the mean while, I'll > do

[Python-modules-team] Bug#781640: Downgrading bug severity

2015-04-09 Thread Thomas Goirand
Hi Luke, If the package isn't vulnerable, shouldn't this bug report be closed? If that's the case, then I'll let you close it. In the mean while, I'll downgrade the severity to normal, in order to not remove the package (and its rev-dependencies) from testing. Cheers, Thomas Goirand (zigo)