From debbugs-submit-bounces@debbugs.gnu.org Sun Mar 14 17:33:56 2021 Received: (at submit) by debbugs.gnu.org; 14 Mar 2021 21:33:56 +0000 Received: from localhost ([127.0.0.1]:34326 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lLYN2-0002u5-4p for submit@debbugs.gnu.org; Sun, 14 Mar 2021 17:33:56 -0400 Received: from lists.gnu.org ([209.51.188.17]:45696) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lLYN0-0002tx-7q for submit@debbugs.gnu.org; Sun, 14 Mar 2021 17:33:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:55408) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lLYMz-0004kv-0C for bug-guix@gnu.org; Sun, 14 Mar 2021 17:33:53 -0400 Received: from world.peace.net ([64.112.178.59]:55700) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lLYMv-00025n-UD for bug-guix@gnu.org; Sun, 14 Mar 2021 17:33:52 -0400 Received: from mhw by world.peace.net with esmtpsa (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1lLYMu-0000vM-Cy; Sun, 14 Mar 2021 17:33:48 -0400 From: Mark H Weaver To: bug-guix@gnu.org Subject: Zabbix packages vulnerable to CVE-2021-27927 References: <023956d907028d228057db658970dd5075440ad7.camel@zaclys.net> Date: Sun, 14 Mar 2021 17:32:18 -0400 Message-ID: <87ft0xs9oi.fsf@netris.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="=-=-=" Received-SPF: pass client-ip=64.112.178.59; envelope-from=mhw@netris.org; helo=world.peace.net X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.3 (-) X-Debbugs-Envelope-To: submit Cc: =?utf-8?Q?L=C3=A9o?= Le Bouter X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.3 (--) --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable I'm forwarding this to bug-guix@gnu.org so that it won't be forgotten. Mark -------------------- Start of forwarded message -------------------- Subject: Zabbix packages vulnerable to CVE-2021-27927 From: L=C3=A9o Le Bouter To: guix-devel@gnu.org Date: Wed, 03 Mar 2021 21:08:54 +0100 --=-=-= Content-Type: multipart/signed; boundary="==-=-=" --==-=-= Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Would be nice to update, it's a CSRF so not very high severity but still. See https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-27927 --==-=-= Content-Type: application/pgp-signature; name=signature.asc Content-Transfer-Encoding: base64 Content-Description: This is a digitally signed message part LS0tLS1CRUdJTiBQR1AgU0lHTkFUVVJFLS0tLS0KCmlRSXpCQUFCQ2dBZEZpRUVGSXZMaTlnTCt4 YXgzZzZSUmFpeDZHdk5FS1lGQW1BLzdOWUFDZ2tRUmFpeDZHdk4KRUtiLzRCQUFqdmZrR0RHbVdz R0RIWDBHZG5qTGVkeVBpK3NMNDU0QWIwcytxQXJJblpQOWE5ZWY2NlM3MERNawpQYk1uZ2JuNi8v QktHNkRuUVhXQ0Ribk5wdnZCQzlNbW9kZHN3SCtWRERNWlN0am1lZlJBcGJ4ODVBTlk1SkNFCmJS bmowOVZYdEJqcGNxWjJNNGFUTW1zS2dzcFdseDZjYkhsWFkvdGRnc2F5TVd2TDBJZHpnR2NlRzhj RGozYmkKM3N6eElvOGdpb0d5TmxKV2RnN1d4ZGR1R0FTUm9yOG1zSTVkZSsrYmJaclhwSUdWZXE2 TWhRUHpQYkJOUDR4NwpmSmlFRlJjd1ZIempUckx2SndxdzNpTUJaRllSTGphKytSOCtBVmhSNDly SWZqV1lmUEsyRi9OdWU2Q1V5SGlsClcvNjNKNWthVjZKdXRpck5oSHN6cE9GZ05yUktPMU1QdUps aGtKbkxaTTVRakNySVhJclZ4TGo3U1kvaVZhWGUKaGRvZi94K1Fsbi95OVFYMUFVd3h2SXhscmUw dVMyeEZua3NFRlU1aU53bnJORzVtem1OM2ZuTHM0NEl1SGxkSQpLKzNZZUM2YXRMOWhkVHV3SzNy aG1MZFRBc080ek1PaTgrSm9SOERnUU1ubUhyV1FNcnlKQ1B4RTFjTEd3YktMCmxVcmFkeUcrVEtv Ky85SFNjR3k5VXd4STdmK3FZYURnczZkVG81TGl4WWQ1ejlTTXN4TkxFV1NudjJ4TnBzdDcKUTBQ M201Y1FzY1RyMW9ZZjZCL1A5bUJHK2ZyMGFVN2Iva1d3V0F0MnZYdWNQa1N5cGdReE1CcEhyUFRk S2F3RgpBMDljRFZBU1pKVnF2ZW1rcnh2VDdnMkRjZ1NDQzZ3RzB0MjhYSXluQ3NYNVcvSkNqNlE9 Cj1xczByCi0tLS0tRU5EIFBHUCBTSUdOQVRVUkUtLS0tLQo= --==-=-=-- --=-=-= Content-Type: text/plain -------------------- End of forwarded message -------------------- --=-=-=-- From debbugs-submit-bounces@debbugs.gnu.org Mon Mar 15 09:43:22 2021 Received: (at control) by debbugs.gnu.org; 15 Mar 2021 13:43:22 +0000 Received: from localhost ([127.0.0.1]:35095 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lLnVB-0007De-Js for submit@debbugs.gnu.org; Mon, 15 Mar 2021 09:43:22 -0400 Received: from eggs.gnu.org ([209.51.188.92]:51422) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lLnVA-0007DB-1q for control@debbugs.gnu.org; Mon, 15 Mar 2021 09:43:21 -0400 Received: from fencepost.gnu.org ([2001:470:142:3::e]:40719) by eggs.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1lLnV4-0005DC-Rr for control@debbugs.gnu.org; Mon, 15 Mar 2021 09:43:14 -0400 Received: from [2a01:e0a:1d:7270:af76:b9b:ca24:c465] (port=45750 helo=ribbon) by fencepost.gnu.org with esmtpsa (TLS1.2:RSA_AES_256_CBC_SHA1:256) (Exim 4.82) (envelope-from ) id 1lLnV4-0002Rz-AJ for control@debbugs.gnu.org; Mon, 15 Mar 2021 09:43:14 -0400 Date: Mon, 15 Mar 2021 14:43:13 +0100 Message-Id: <87mtv4h6ry.fsf@gnu.org> To: control@debbugs.gnu.org From: =?utf-8?Q?Ludovic_Court=C3=A8s?= Subject: control message for bug #47141 MIME-version: 1.0 Content-type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: control X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.7 (-) tags 47141 + security quit From debbugs-submit-bounces@debbugs.gnu.org Wed Mar 24 00:06:33 2021 Received: (at control) by debbugs.gnu.org; 24 Mar 2021 04:06:33 +0000 Received: from localhost ([127.0.0.1]:33694 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lOumu-0005lF-Sj for submit@debbugs.gnu.org; Wed, 24 Mar 2021 00:06:33 -0400 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:54559) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lOumu-0005l0-0L for control@debbugs.gnu.org; Wed, 24 Mar 2021 00:06:32 -0400 Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.nyi.internal (Postfix) with ESMTP id 00DAB5C00A6; Wed, 24 Mar 2021 00:06:27 -0400 (EDT) Received: from mailfrontend1 ([10.202.2.162]) by compute3.internal (MEProxy); Wed, 24 Mar 2021 00:06:27 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name; h=date:from:to:message-id:mime-version:content-type; s=mesmtp; bh=cUzHWhlGR3wC+bHCNkVYv1pLnZKlAmeM2w5IIOGJO/Q=; b=hYoywwDcb45H +FnMoujfkLjlL2O862lHA5gu19YnLcGkyedy4g2r+8zkuxkV/0wCDl3ZYARsyaoQ gncttRvwfOB0FMOE2wn2BZGKsMDDR2NHFRvDuLmgLVE9W73e+f1eYRNLEHxLS4t2 q5jQWE6lWCJQQtJYSFhL1sFjiC5+NHU= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-type:date:from:message-id :mime-version:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm2; bh=cUzHWhlGR3wC+bHCNkVYv1pLnZKlAmeM2w5IIOGJO /Q=; b=oBY0abGUV0V94XVxdUGYaDcNx44jbdINXGMiVoENwErL1yEyiGyJbPQDK KgbgNvQpHxuXtUvKddIOXBy+bW7zjdDZ6pCHF1UvgbbVyy7zARHXbgQJjqfnkoCp ZyzdR6eTojVI18aQnLJahMvztuvcnJvvpZ3JTPK5cXLzOGKf87Wa1h8WokpQfozP 1NG4H8Sc6HYjzRVTP+1Q0xA/mhIJKoETs8nKC9USahQ11JAQbaqB1Cpn6Y8s9xG7 U/fZIKBTlgGmSup44lnPYSzJwJd7bhKfPY19kMaWM7TtSioka1WU9C9wWYCuy6Z+ nmVqk+OOVCF+IbVpUS0FVk6RCNd4Q== X-ME-Sender: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrudegjedgieejucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucfgmhhpthihuchsuhgsjhgvtghtucdluddtmdenuc fjughrpeffhffvkfggtggusehttdertddttddvnecuhfhrohhmpefnvghoucfhrghmuhhl rghrihcuoehlvghosehfrghmuhhlrghrihdrnhgrmhgvqeenucggtffrrghtthgvrhhnpe fhjeeigfefvedvfeetheegledtkeevuddtgedtudeiteehteegvdefffduffefffenucfk phepuddttddruddurdduieelrdduudeknecuvehluhhsthgvrhfuihiivgeptdenucfrrg hrrghmpehmrghilhhfrhhomheplhgvohesfhgrmhhulhgrrhhirdhnrghmvg X-ME-Proxy: Received: from localhost (pool-100-11-169-118.phlapa.fios.verizon.net [100.11.169.118]) by mail.messagingengine.com (Postfix) with ESMTPA id C6F7224041D for ; Wed, 24 Mar 2021 00:06:26 -0400 (EDT) Date: Wed, 24 Mar 2021 00:06:25 -0400 From: Leo Famulari To: control@debbugs.gnu.org Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline X-Spam-Score: 2.3 (++) X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: block 47297 with 47140 block 47297 with 47141 block 47297 with 47142 block 47297 with 47143 block 47297 with 47144 Content analysis details: (2.3 points, 10.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3) [66.111.4.25 listed in wl.mailspike.net] -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at https://www.dnswl.org/, low trust [66.111.4.25 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record -0.0 SPF_HELO_PASS SPF: HELO matches SPF record 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders 1.8 MISSING_SUBJECT Missing Subject: header 0.2 NO_SUBJECT Extra score for no subject 1.0 BODY_EMPTY No body text in message X-Debbugs-Envelope-To: control X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: block 47297 with 47140 block 47297 with 47141 block 47297 with 47142 block 47297 with 47143 block 47297 with 47144 Content analysis details: (1.3 points, 10.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3) [66.111.4.25 listed in wl.mailspike.net] -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at https://www.dnswl.org/, low trust [66.111.4.25 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record -0.0 SPF_HELO_PASS SPF: HELO matches SPF record 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders -1.0 MAILING_LIST_MULTI Multiple indicators imply a widely-seen list manager 1.8 MISSING_SUBJECT Missing Subject: header 0.2 NO_SUBJECT Extra score for no subject 1.0 BODY_EMPTY No body text in message block 47297 with 47140 block 47297 with 47141 block 47297 with 47142 block 47297 with 47143 block 47297 with 47144 From debbugs-submit-bounces@debbugs.gnu.org Sat Apr 03 20:40:44 2021 Received: (at 47141-done) by debbugs.gnu.org; 4 Apr 2021 00:40:44 +0000 Received: from localhost ([127.0.0.1]:34647 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lSqom-00021T-94 for submit@debbugs.gnu.org; Sat, 03 Apr 2021 20:40:44 -0400 Received: from mail.zaclys.net ([178.33.93.72]:56485) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lSqoj-00021A-Dr for 47141-done@debbugs.gnu.org; Sat, 03 Apr 2021 20:40:42 -0400 Received: from [192.168.1.115] (lsl43-1_migr-78-195-19-20.fbx.proxad.net [78.195.19.20] (may be forged)) (authenticated bits=0) by mail.zaclys.net (8.14.7/8.14.7) with ESMTP id 1340eYGK051427 (version=TLSv1/SSLv3 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for <47141-done@debbugs.gnu.org>; Sun, 4 Apr 2021 02:40:35 +0200 DMARC-Filter: OpenDMARC Filter v1.3.2 mail.zaclys.net 1340eYGK051427 Authentication-Results: mail.zaclys.net; dmarc=fail (p=reject dis=none) header.from=zaclys.net Authentication-Results: mail.zaclys.net; spf=fail smtp.mailfrom=lle-bout@zaclys.net DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zaclys.net; s=default; t=1617496835; bh=jGpxU4UX9t4OgGrKcuSUu0moE9qdPjEFpXJms/DhOJs=; h=Subject:From:To:Date:From; b=gQAV4rsFh14Ko8uwnlZb7Cs8ZdAHOdRpXRs6r6+l48OPY9wpgd5WpObOKxqP9ZnkJ 5i9esgmnBgvpWRuoAJZEk334/sC3d/z38D0mejuMwPZUMXO1TejXlkfSJ6RFURRW1m BI/oZm5qwwLZgIoF1T4ZvbKK9ILFuktnrNlmxjEA= Message-ID: <45008b466d58f9ea78365ad64fd9000ae9fe0132.camel@zaclys.net> Subject: Zabbix packages vulnerable to CVE-2021-27927 From: =?ISO-8859-1?Q?L=E9o?= Le Bouter To: 47141-done@debbugs.gnu.org Date: Sun, 04 Apr 2021 02:40:30 +0200 Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-Bzg/o3vMV5aw9vL2naPJ" User-Agent: Evolution 3.34.2 MIME-Version: 1.0 X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: 47141-done X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --=-Bzg/o3vMV5aw9vL2naPJ Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Fixed in dda88cda120d75f7d139e54367c0d76e574091dc --=-Bzg/o3vMV5aw9vL2naPJ Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEFIvLi9gL+xax3g6RRaix6GvNEKYFAmBpCv4ACgkQRaix6GvN EKbmEw/+KP2Rq5vuf2v3nNStl4aqh7BO+6UJj/tIPNteOQGROrkbP2YeolA/XaF1 uo+3M8WbNZEiyPCqih3burHGBKh1oTWcwzTGe7fedPOyBn7caKleh/ryrR1ku2Mx cywCjRHtnxf+fCEOr3LSidfz+EHCNiDxmFzMzdi5UqxPon6O+4Pke/bIJOugGhVH 9BvWh6h6Yp15kpO7cPlMHCD8tEu0QDsaKccsEoHU5ivewuU3toQYSsvdzJVjbDPS 31rau/irk55XgJmvWOffTCcYTTJ/q2kgmTPUBSiCH5P2VZ2ZJI9Kqmi0Xz68OK84 QgRDWJ9mOfLgc6tB1l2gGdRcCggbK1jZNvjUXWfVcasswwghuUnY8nQGVtF3JIyD 9jrIVbcXu+cwd1CvDodTMYQhA11UaDIIQYExh0z1q2T3XhKY7MSL2B48pSR32C2O rui+AXooW1N739BLYNzb+dPJdyTgvVGyW8R2D8VMntLrlHwDyAtut1E7JwUOatEs vyP+l+irL66n+to7YFPUqLYkJN7X+Euae80t5ykYvFP6KBaAt/QXJrDfOhsOYRZS 4oeo2jr986ChVA8JgxdvnwTmpM+fNl01OhctjZOzqri9mqChlA4Z5vJg75FVDDGk g1c/LxYJ/AvQiVHU+Xinjz+nuxJ/y8pi/KCvviYc0Xi9P0/+aSE= =jrIu -----END PGP SIGNATURE----- --=-Bzg/o3vMV5aw9vL2naPJ-- From unknown Fri Aug 15 17:22:45 2025 Received: (at fakecontrol) by fakecontrolmessage; To: internal_control@debbugs.gnu.org From: Debbugs Internal Request Subject: Internal Control Message-Id: bug archived. Date: Sun, 02 May 2021 11:24:04 +0000 User-Agent: Fakemail v42.6.9 # This is a fake control message. # # The action: # bug archived. thanks # This fakemail brought to you by your local debbugs # administrator