Please sync dar (universe) from Debian unstable (main)

Bug #138815 reported by Fridtjof Busse
256
Affects Status Importance Assigned to Milestone
dar (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

dar in gutsy is still 2.3.3, but 2.3.4 fixed a weakness in dar's built-in blowfish-cipher:
http://sourceforge.net/project/shownotes.php?release_id=519921&group_id=65612
Thus it would be nice to get dar >= 2.3.4 into gutsy.
Backporting the fix to feisty might be a good idea as well.

Revision history for this message
Chuck Short (zulcss) wrote :

I dont think this is a security bug, unotifying

Revision history for this message
Fridtjof Busse (fbusse-deactivatedaccount-deactivatedaccount) wrote :

Well, at least it makes deiphering encrypted archives a lot easier. It my not qualify as a severe veulnerability, but still it would be a good idea to fix this for gutsy. Debian already has dar 2.3.5.

Revision history for this message
Kees Cook (kees) wrote :

dar (2.3.5-1) unstable; urgency=low

  * New upstream release
  * Write errors no longer occur indefinitely (closes: #418538).

 -- Brian May <email address hidden> Thu, 30 Aug 2007 13:40:18 +1000

dar (2.3.4-1) unstable; urgency=low

  * New upstream version (closes: 433395).
  * Renders archives created with 2.3.3-1 unreadable.
  * Please see http://bugs.debian.org/433395 for work around.

 -- Brian May <email address hidden> Tue, 17 Jul 2007 09:53:54 +1000

I'd like to get a UVFe for this, and then we can sync it.

Revision history for this message
Scott Kitterman (kitterman) wrote :

Kees.

Assuming you'll mind it to make sure it works OK, Ack from me.

Revision history for this message
Sarah Kowalik (hobbsee-deactivatedaccount) wrote : Re: [Bug 138815] Re: Please bump dar to 2.3.5

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Fine by me too, but please check all rdepends.

 status confirmed

Kees Cook wrote:
> dar (2.3.5-1) unstable; urgency=low
>
> * New upstream release
> * Write errors no longer occur indefinitely (closes: #418538).
>
> -- Brian May <email address hidden> Thu, 30 Aug 2007 13:40:18 +1000
>
> dar (2.3.4-1) unstable; urgency=low
>
> * New upstream version (closes: 433395).
> * Renders archives created with 2.3.3-1 unreadable.
> * Please see http://bugs.debian.org/433395 for work around.
>
> -- Brian May <email address hidden> Tue, 17 Jul 2007 09:53:54 +1000
>
> I'd like to get a UVFe for this, and then we can sync it.
>
>
> ** This bug has been flagged as a security issue
>
> ** Summary changed:
>
> - Please bump dar to 2.3.5
> + Please sync dar (universe) from Debian unstable (main)
>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFG7q3p7/o1b30rzoURAlGgAJsFotfiTWlNzxwoImlxjlo1yJlwTgCePqTs
7/kZvDxMo06dejpeK+bzSME=
=phSn
-----END PGP SIGNATURE-----

Changed in dar:
status: New → Confirmed
Revision history for this message
Sarah Kowalik (hobbsee-deactivatedaccount) wrote :

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 unsubscribe motu-uvf
 subscribe ubuntu-archive
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFG7rB77/o1b30rzoURAj0zAKDXbe6qNV7wPnA/PLPVTmYBW6QONwCeMHSo
sfoonGq6YtNTM8WFV+VY4N8=
=e5EO
-----END PGP SIGNATURE-----

Revision history for this message
Sebastien Bacher (seb128) wrote :

[Updating] dar (2.3.3-1 [Ubuntu] < 2.3.5-1 [Debian])
 * Trying to add dar...
  - <dar_2.3.5-1.diff.gz: downloading from http://ftp.debian.org/debian/>
  - <dar_2.3.5-1.dsc: downloading from http://ftp.debian.org/debian/>
  - <dar_2.3.5.orig.tar.gz: downloading from http://ftp.debian.org/debian/>
I: dar [universe] -> dar_2.3.3-1 [universe].
I: dar [universe] -> libdar64-4_2.3.3-1 [universe].
I: dar [universe] -> dar-static_2.3.3-1 [universe].
I: dar [universe] -> libdar-dev_2.3.3-1 [universe].
I: dar [universe] -> dar-docs_2.3.3-1 [universe].

Changed in dar:
importance: Undecided → Wishlist
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.