Discussion:
[Bug 837557] Re: fraudulent DigiNotar certificate issuance
Micah Gersten
2011-08-31 22:25:16 UTC
Permalink
** Also affects: ca-certificates (Ubuntu)
Importance: Undecided
Status: New

** Also affects: nss (Ubuntu)
Importance: Undecided
Status: New

** Also affects: qt4-x11 (Ubuntu)
Importance: Undecided
Status: New

** Changed in: ca-certificates (Ubuntu Natty)
Importance: Undecided => Medium

** Changed in: ca-certificates (Ubuntu Natty)
Status: New => In Progress

** Changed in: ca-certificates (Ubuntu Natty)
Assignee: (unassigned) => Micah Gersten (micahg)
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Micah Gersten
2011-08-31 22:34:09 UTC
Permalink
** Changed in: ca-certificates (Ubuntu Maverick)
Importance: Undecided => Medium

** Changed in: ca-certificates (Ubuntu Maverick)
Status: New => In Progress

** Changed in: ca-certificates (Ubuntu Maverick)
Assignee: (unassigned) => Micah Gersten (micahg)
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-08-31 22:34:31 UTC
Permalink
** Branch linked: lp:ubuntu/lucid-security/firefox

** Branch linked: lp:ubuntu/lucid-security/xulrunner-1.9.2

** Branch linked: lp:ubuntu/maverick-security/xulrunner-1.9.2

** Branch linked: lp:ubuntu/maverick-security/firefox

** Branch linked: lp:ubuntu/natty-security/firefox
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Anonymous
2011-09-01 00:04:21 UTC
Permalink
Also affects SeaMonkey (https://launchpad.net/ubuntu/+source/seamonkey).
Please update SeaMonkey to version 2.3.2 so that this problem can be
prevented there too. SeaMonkey version 2.3.2 erroneously identifies
itself as version 2.3.1 (see
https://bugzilla.mozilla.org/show_bug.cgi?id=683473). If you need to
check that it's really 2.3.2 and not 2.3.1, go to
https://www.diginotar.nl/ or to any other page signed by Diginotar.
Version 2.3.1 will display the page without complaining whereas 2.3.2
will complain that the site is insecure.

** Bug watch added: Mozilla Bugzilla #683473
https://bugzilla.mozilla.org/show_bug.cgi?id=683473
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-01 06:56:29 UTC
Permalink
** Branch linked: lp:thunderbird/beta
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Anonymous
2011-09-01 08:06:45 UTC
Permalink
As you might have seen at Mozilla's Bugzilla
(https://bugzilla.mozilla.org/show_bug.cgi?id=683449), the current Gecko
fixes block too much, so there will soon be another update to the
mentioned Gecko products, presumably requiring action in Ubuntu too.

** Bug watch added: Mozilla Bugzilla #683449
https://bugzilla.mozilla.org/show_bug.cgi?id=683449
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Olivier Mengué
2011-09-01 08:57:00 UTC
Permalink
The proposed workaround is only for Firefox.
What about other applications that may access Google services on a Ubuntu system?
Can we simply "sudo rm /etc/ssl/certs/DigiNotar_Root_CA.pem" ?
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Laurent Bigonville
2011-09-01 11:12:39 UTC
Permalink
debian has released ca-certificates version 20110502+nmu1 that fix this

** Bug watch added: Debian Bug tracker #639744
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=639744

** Also affects: ca-certificates (Debian) via
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=639744
Importance: Unknown
Status: Unknown
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Bug Watch Updater
2011-09-01 12:34:35 UTC
Permalink
** Changed in: ca-certificates (Debian)
Status: Unknown => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Micah Gersten
2011-09-01 14:42:27 UTC
Permalink
@Olivier Mengu?
I am working on updates for NSS and ca-certificates to address this system wide.

@Anonymous
Seamonkey is currently not in a good state, but I will try to get an update for it eventually. In the mean time, the NSS update should take care of this security issue for most use cases.

** Description changed:

+ NOTE: The Firefox update causes a regression for certain Dutch sites
+ which is being tracked in Bug #838322.
+
WORKAROUND (from blog post):
http://support.mozilla.com/en-US/kb/deleting-diginotar-ca-cert

-------------------------------------------------

http://blog.mozilla.com/security/2011/08/29/fraudulent-google-com-
certificate/
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Jamie Strandboge
2011-09-01 15:47:57 UTC
Permalink
[Updating] ca-certificates (20110502 [Ubuntu] < 20110502+nmu1 [Debian])
* Trying to add ca-certificates...
2011-09-01 15:47:52 INFO - <ca-certificates_20110502+nmu1.dsc: downloading from http://ftp.debian.org/debian/>
2011-09-01 15:47:52 INFO - <ca-certificates_20110502+nmu1.tar.gz: downloading from http://ftp.debian.org/debian/>
I: ca-certificates [main] -> ca-certificates_20110502 [main].


** Changed in: ca-certificates (Ubuntu Oneiric)
Status: New => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Jamie Strandboge
2011-09-01 15:48:29 UTC
Permalink
2011-09-01 15:48:25 INFO - <ca-certificates_20110502+nmu1.dsc: cached>
2011-09-01 15:48:25 INFO - <ca-certificates_20110502+nmu1.tar.gz: cached>
[Updating] ca-certificates (20110502 [Ubuntu] < 20110502+nmu1 [Debian])
* Trying to add ca-certificates...
I: ca-certificates [main] -> ca-certificates_20110502 [main].


** Changed in: nss (Ubuntu Oneiric)
Status: New => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Jamie Strandboge
2011-09-01 15:49:04 UTC
Permalink
2011-09-01 15:48:59 INFO - <ca-certificates_20110502+nmu1.dsc: cached>
2011-09-01 15:48:59 INFO - <ca-certificates_20110502+nmu1.tar.gz: cached>
[Updating] ca-certificates (20110502 [Ubuntu] < 20110502+nmu1 [Debian])
* Trying to add ca-certificates...
I: ca-certificates [main] -> ca-certificates_20110502 [main].


** Changed in: qt4-x11 (Ubuntu Oneiric)
Status: New => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Jamie Strandboge
2011-09-01 15:49:37 UTC
Permalink
2011-09-01 15:49:34 INFO - <ca-certificates_20110502+nmu1.dsc: cached>
2011-09-01 15:49:34 INFO - <ca-certificates_20110502+nmu1.tar.gz: cached>
[Updating] ca-certificates (20110502 [Ubuntu] < 20110502+nmu1 [Debian])
* Trying to add ca-certificates...
I: ca-certificates [main] -> ca-certificates_20110502 [main].


** Changed in: qt4-x11 (Ubuntu Oneiric)
Status: Fix Released => New

** Changed in: nss (Ubuntu Oneiric)
Status: Fix Released => New

** Changed in: ca-certificates (Ubuntu Oneiric)
Importance: Undecided => Medium

** Changed in: qt4-x11 (Ubuntu Maverick)
Status: New => Invalid

** Changed in: qt4-x11 (Ubuntu Natty)
Status: New => Invalid

** Changed in: qt4-x11 (Ubuntu Oneiric)
Status: New => Invalid

** Changed in: ca-certificates (Ubuntu Lucid)
Importance: Undecided => Medium

** Changed in: ca-certificates (Ubuntu Lucid)
Status: New => In Progress

** Changed in: ca-certificates (Ubuntu Lucid)
Assignee: (unassigned) => Micah Gersten (micahg)

** Changed in: ca-certificates (Ubuntu Oneiric)
Assignee: (unassigned) => Jamie Strandboge (jdstrand)

** Changed in: qt4-x11 (Ubuntu Lucid)
Status: New => Confirmed

** Changed in: nss (Ubuntu Lucid)
Status: New => Confirmed

** Changed in: nss (Ubuntu Maverick)
Status: New => Confirmed

** Changed in: nss (Ubuntu Natty)
Status: New => Confirmed

** Changed in: nss (Ubuntu Oneiric)
Status: New => Confirmed

** Changed in: nss (Ubuntu Lucid)
Importance: Undecided => Medium

** Changed in: nss (Ubuntu Maverick)
Importance: Undecided => Medium

** Changed in: nss (Ubuntu Natty)
Importance: Undecided => Medium

** Changed in: nss (Ubuntu Oneiric)
Importance: Undecided => Medium

** Changed in: qt4-x11 (Ubuntu Lucid)
Importance: Undecided => Medium

** Changed in: nss (Ubuntu Lucid)
Assignee: (unassigned) => Micah Gersten (micahg)

** Changed in: nss (Ubuntu Maverick)
Assignee: (unassigned) => Micah Gersten (micahg)

** Changed in: nss (Ubuntu Natty)
Assignee: (unassigned) => Micah Gersten (micahg)

** Changed in: nss (Ubuntu Oneiric)
Assignee: (unassigned) => Micah Gersten (micahg)
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Jamie Strandboge
2011-09-01 16:04:07 UTC
Permalink
** Changed in: nss (Ubuntu Oneiric)
Assignee: Micah Gersten (micahg) => (unassigned)
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Anonymous
2011-09-01 16:53:20 UTC
Permalink
** Also affects: seamonkey (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Jamie Strandboge
2011-09-01 17:03:17 UTC
Permalink
** Changed in: ca-certificates (Ubuntu Lucid)
Status: In Progress => Fix Committed

** Changed in: ca-certificates (Ubuntu Maverick)
Status: In Progress => Fix Committed

** Changed in: ca-certificates (Ubuntu Natty)
Status: In Progress => Fix Committed
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Jamie Strandboge
2011-09-01 17:08:21 UTC
Permalink
** Changed in: nss (Ubuntu Lucid)
Status: Confirmed => In Progress

** Changed in: nss (Ubuntu Maverick)
Status: Confirmed => In Progress

** Changed in: nss (Ubuntu Natty)
Status: Confirmed => In Progress

** Changed in: seamonkey (Ubuntu Lucid)
Status: New => Confirmed

** Changed in: seamonkey (Ubuntu Maverick)
Status: New => Confirmed

** Changed in: seamonkey (Ubuntu Natty)
Status: New => Confirmed

** Changed in: seamonkey (Ubuntu Oneiric)
Status: New => Confirmed
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Anonymous
2011-09-01 17:51:21 UTC
Permalink
** Also affects: chromium-browser (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-01 20:20:33 UTC
Permalink
** Changed in: chromium-browser (Ubuntu)
Status: New => Confirmed

** Changed in: chromium-browser (Ubuntu Lucid)
Status: New => Confirmed

** Changed in: chromium-browser (Ubuntu Maverick)
Status: New => Confirmed

** Changed in: chromium-browser (Ubuntu Natty)
Status: New => Confirmed
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Micah Gersten
2011-09-02 00:12:38 UTC
Permalink
UPDATE:
Unfortunately, the ca-certificates and NSS fixes available at the moment are only a partial fix that won't actually help very much. I'm currently waiting on fixes that should address this issue completely. I will be releasing Thunderbird in a few hours with the same fix that Firefox got which blocks the rogue certificates, but possibly causes a regression for certain Dutch sites (see Description of this bug).
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-02 05:26:41 UTC
Permalink
This bug was fixed in the package thunderbird - 3.1.13+build1+nobinonly-
0ubuntu0.10.10.1

---------------
thunderbird (3.1.13+build1+nobinonly-0ubuntu0.10.10.1) maverick-security; urgency=low

* New upstream release v3.1.13 (THUNDERBIRD_3_1_13_BUILD1)
- Distrust and disable DigiNotar Root CA due to fraudulent certificate
issuance (LP: #837557)
-- Micah Gersten <micahg at ubuntu.com> Wed, 31 Aug 2011 00:42:12 -0500

** Changed in: thunderbird (Ubuntu Maverick)
Status: In Progress => Fix Released

** Changed in: thunderbird (Ubuntu Natty)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-02 05:27:01 UTC
Permalink
This bug was fixed in the package thunderbird - 3.1.13+build1+nobinonly-
0ubuntu0.11.04.1

---------------
thunderbird (3.1.13+build1+nobinonly-0ubuntu0.11.04.1) natty-security; urgency=low

* New upstream release v3.1.13 (THUNDERBIRD_3_1_13_BUILD1)
- Distrust and disable DigiNotar Root CA due to fraudulent certificate
issuance (LP: #837557)
-- Micah Gersten <micahg at ubuntu.com> Wed, 31 Aug 2011 00:43:28 -0500
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-02 05:35:36 UTC
Permalink
This bug was fixed in the package thunderbird - 3.1.13+build1+nobinonly-
0ubuntu0.10.04.1

---------------
thunderbird (3.1.13+build1+nobinonly-0ubuntu0.10.04.1) lucid-security; urgency=low

* New upstream release v3.1.13 (THUNDERBIRD_3_1_13_BUILD1)
- Distrust and disable DigiNotar Root CA due to fraudulent certificate
issuance (LP: #837557)
-- Micah Gersten <micahg at ubuntu.com> Wed, 31 Aug 2011 00:30:47 -0500

** Changed in: thunderbird (Ubuntu Lucid)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-02 06:31:26 UTC
Permalink
** Branch linked: lp:ubuntu/lucid-security/thunderbird

** Branch linked: lp:ubuntu/maverick-security/thunderbird

** Branch linked: lp:ubuntu/natty-security/thunderbird
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Micah Gersten
2011-09-02 07:03:20 UTC
Permalink
** Description changed:

- NOTE: The Firefox update causes a regression for certain Dutch sites
- which is being tracked in Bug #838322.
+ NOTE: The Firefox update causes a regression for certain Dutch sites which is being tracked in Bug #838322.
+ NOTE #2: The current update for Thunderbird still shows the DigiNotar Root CA as trusted in the certificate manager. This is due to Thunderbird using the system version of NSS. In this initial update, Thunderbird will actively distrust any certificate signed by the DigiNotar Root CA. Future updates will properly show the root CA as distrusted in the certificate manager.

WORKAROUND (from blog post):
http://support.mozilla.com/en-US/kb/deleting-diginotar-ca-cert

-------------------------------------------------

http://blog.mozilla.com/security/2011/08/29/fraudulent-google-com-
certificate/
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Peter Hartmann
2011-09-02 15:18:02 UTC
Permalink
regarding the Qt bundle: I cannot find the DigiNotar root cert in there, the bundle is really old apparently.
(did:
cd src/network/ssl
csplit -s qt-ca-bundle.crt '/^$/' {*}
for i in $(ls ./xx*); do echo $i; openssl x509 -text -noout -in $i; done|grep -i 'subject:'|grep -i diginotar
... does not yield anything).
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-05 23:45:11 UTC
Permalink
This bug was fixed in the package thunderbird - 7.0~b2+build2+nobinonly-
0ubuntu1

---------------
thunderbird (7.0~b2+build2+nobinonly-0ubuntu1) oneiric; urgency=low

* New upstream release from the beta channel (THUNDERBIRD_7_0b2_BUILD2)
- LP: #837557 and LP: #838322

* Update globalmenu-extension to 2.0
- Only update a menu in realtime if it's parent is opening. For all other
times, just invalidate the menu. Avoids spamming dbus everytime
something changes in the menu
- When removing a menuitem from its parent, check that the index is
in-bounds. Should fix a frequent crash on startup, although it doesn't
explain how it gets in to that state in the first place
- Add the ability to turn on debugging without building Firefox with
debugging on
* Add upstream patch to only add ENABLE_JIT=1 to CXXFLAGS if any of trace/
method/yarr jit is enabled. Fixes a build failure on PPC
- add debian/patches/only-add-ENABLE_JIT-to-CXXFLAGS-if-jit-is-enabled.patch
- update debian/patches/series
* Add upstream patch to fix build failure with ENABLE_YARR_JIT=0
- add debian/patches/build-fix-for-no-ENABLE_YARR_JIT.patch
- update debian/patches/series
* Add upstream patch to work around a linker bug
- add debian/patches/compile-pldhash-as-C++.patch
- update debian/patches/series
* Don't pass an empty --mozilla-repo= argument to client.py when creating
the source tarball without a local cache, as it totally breaks. This is
why we've got rid of all this in nightly and aurora, so we can avoid
such bandaids in the first place
- update debian/mozclient/thunderbird.conf
* Messagingmenu fixes:
- Use the libunity5 ABI (LP: #839154)
- Don't use QueryInterface on objects where we can't guarantee they
implement a particular interface (LP: #826447)
* Make sure that thunderbird-gnome-support actually depends on libunity5
- update debian/rules
* Update eds extension to r84 from 0.3 branch
- fixes a shutdown crash
* Use the latest eds libs for the contacts integration
-- Chris Coulson <chris.coulson at canonical.com> Tue, 06 Sep 2011 00:19:41 +0100

** Changed in: thunderbird (Ubuntu Oneiric)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-06 00:22:27 UTC
Permalink
** Branch linked: lp:ubuntu/thunderbird
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-07 20:00:23 UTC
Permalink
** Branch linked: lp:~mozillateam/nss/nss.lucid
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-07 20:07:24 UTC
Permalink
** Branch linked: lp:~mozillateam/nss/nss.maverick
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-07 20:16:25 UTC
Permalink
** Branch linked: lp:~mozillateam/nss/nss.natty
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Micah Gersten
2011-09-07 21:55:54 UTC
Permalink
Just found out Qt 4.7 has a blacklist patch, so reopening tasks fro
maverick/natty/oneiric

** Changed in: qt4-x11 (Ubuntu Maverick)
Importance: Undecided => Medium

** Changed in: qt4-x11 (Ubuntu Maverick)
Status: Invalid => In Progress

** Changed in: qt4-x11 (Ubuntu Maverick)
Assignee: (unassigned) => Micah Gersten (micahg)

** Changed in: qt4-x11 (Ubuntu Natty)
Importance: Undecided => Medium

** Changed in: qt4-x11 (Ubuntu Natty)
Status: Invalid => In Progress

** Changed in: qt4-x11 (Ubuntu Natty)
Assignee: (unassigned) => Micah Gersten (micahg)

** Changed in: qt4-x11 (Ubuntu Oneiric)
Importance: Undecided => Medium

** Changed in: qt4-x11 (Ubuntu Oneiric)
Status: Invalid => Triaged

** Description changed:

NOTE: The Firefox update causes a regression for certain Dutch sites which is being tracked in Bug #838322.
NOTE #2: The current update for Thunderbird still shows the DigiNotar Root CA as trusted in the certificate manager. This is due to Thunderbird using the system version of NSS. In this initial update, Thunderbird will actively distrust any certificate signed by the DigiNotar Root CA. Future updates will properly show the root CA as distrusted in the certificate manager.

WORKAROUND (from blog post):
http://support.mozilla.com/en-US/kb/deleting-diginotar-ca-cert

-------------------------------------------------

http://blog.mozilla.com/security/2011/08/29/fraudulent-google-com-
certificate/
+
+ Qt 4.7 blog post: http://labs.qt.nokia.com/2011/09/07/what-the-
+ diginotar-security-breach-means-for-qt-users-continued/

** Description changed:

+ USN Information: This is being tracked in USN-1197-*
+
NOTE: The Firefox update causes a regression for certain Dutch sites which is being tracked in Bug #838322.
NOTE #2: The current update for Thunderbird still shows the DigiNotar Root CA as trusted in the certificate manager. This is due to Thunderbird using the system version of NSS. In this initial update, Thunderbird will actively distrust any certificate signed by the DigiNotar Root CA. Future updates will properly show the root CA as distrusted in the certificate manager.

WORKAROUND (from blog post):
http://support.mozilla.com/en-US/kb/deleting-diginotar-ca-cert

-------------------------------------------------

http://blog.mozilla.com/security/2011/08/29/fraudulent-google-com-
certificate/

Qt 4.7 blog post: http://labs.qt.nokia.com/2011/09/07/what-the-
diginotar-security-breach-means-for-qt-users-continued/
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Micah Gersten
2011-09-07 22:00:28 UTC
Permalink
Didier,
I was told you're doing a qt4-x11 upload, can you include the blacklist patch from the blog post in the Description of this bug?

** Changed in: qt4-x11 (Ubuntu Oneiric)
Assignee: (unassigned) => Didier Roche (didrocks)
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-08 09:34:23 UTC
Permalink
** Branch linked: lp:~kubuntu-packagers/kubuntu-packaging/qt
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
yamo
2011-09-08 08:35:54 UTC
Permalink
Hi,

For the very old Seamonkey 2.0 : http://support.mozilla.com/fr/kb
/supprimer-certificat-diginotar-ca
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-08 17:28:50 UTC
Permalink
This bug was fixed in the package nss -
3.12.9+ckbi-1.82-0ubuntu0.10.04.3

---------------
nss (3.12.9+ckbi-1.82-0ubuntu0.10.04.3) lucid-security; urgency=low

* SECURITY UPDATE: Add patch from Debian version 3.12.11-3 rebased against
3.12.9 to remove the DigiNotar certificates and actively distrust them;
Thanks to Mike Hommey from Debian for the original patch (LP: #837557)
- mozilla/security/nss/lib/ckfw/builtins/certdata.*:
Explicitely distrust various DigiNotar CAs:
- DigiNotar Root CA
- DigiNotar Services 1024 CA
- DigiNotar Cyber CA
- DigiNotar Cyber CA 2nd
- DigiNotar PKIoverheid
- DigiNotar PKIoverheid G2
- mozilla/security/nss/lib/ckfw/builtins/certdata.*:
Remove DigiNotar Root CA.
-- Micah Gersten <micahg at ubuntu.com> Wed, 07 Sep 2011 14:53:13 -0500

** Changed in: nss (Ubuntu Lucid)
Status: In Progress => Fix Released

** Changed in: nss (Ubuntu Maverick)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-08 17:28:56 UTC
Permalink
This bug was fixed in the package nss -
3.12.9+ckbi-1.82-0ubuntu0.10.10.3

---------------
nss (3.12.9+ckbi-1.82-0ubuntu0.10.10.3) maverick-security; urgency=low

* SECURITY UPDATE: Add patch from Debian version 3.12.11-3 rebased against
3.12.9 to remove the DigiNotar certificates and actively distrust them;
Thanks to Mike Hommey from Debian for the original patch (LP: #837557)
- mozilla/security/nss/lib/ckfw/builtins/certdata.*:
Explicitely distrust various DigiNotar CAs:
- DigiNotar Root CA
- DigiNotar Services 1024 CA
- DigiNotar Cyber CA
- DigiNotar Cyber CA 2nd
- DigiNotar PKIoverheid
- DigiNotar PKIoverheid G2
- mozilla/security/nss/lib/ckfw/builtins/certdata.*:
Remove DigiNotar Root CA.
-- Micah Gersten <micahg at ubuntu.com> Wed, 07 Sep 2011 14:55:24 -0500

** Changed in: nss (Ubuntu Natty)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-08 17:29:01 UTC
Permalink
This bug was fixed in the package nss - 3.12.9+ckbi-1.82-0ubuntu2.1

---------------
nss (3.12.9+ckbi-1.82-0ubuntu2.1) natty-security; urgency=low

* SECURITY UPDATE: Add patch from Debian version 3.12.11-3 rebased against
3.12.9 to remove the DigiNotar certificates and actively distrust them;
Thanks to Mike Hommey from Debian for the original patch (LP: #837557)
- mozilla/security/nss/lib/ckfw/builtins/certdata.*:
Explicitely distrust various DigiNotar CAs:
- DigiNotar Root CA
- DigiNotar Services 1024 CA
- DigiNotar Cyber CA
- DigiNotar Cyber CA 2nd
- DigiNotar PKIoverheid
- DigiNotar PKIoverheid G2
- mozilla/security/nss/lib/ckfw/builtins/certdata.*:
Remove DigiNotar Root CA.
-- Micah Gersten <micahg at ubuntu.com> Wed, 07 Sep 2011 15:15:37 -0500
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-08 18:13:23 UTC
Permalink
** Branch linked: lp:ubuntu/natty-security/nss

** Branch linked: lp:ubuntu/lucid-security/nss

** Branch linked: lp:ubuntu/maverick-security/nss
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-09 04:04:23 UTC
Permalink
This bug was fixed in the package ca-certificates -
20090814ubuntu0.10.04.1

---------------
ca-certificates (20090814ubuntu0.10.04.1) lucid-security; urgency=low

* SECURITY UPDATE: Blacklist "DigiNotar Root CA" due to fraudulent
certificate issuance (LP: #837557)
- update mozilla/blacklist.txt
-- Micah Gersten <micahg at ubuntu.com> Thu, 01 Sep 2011 11:38:01 -0500

** Changed in: ca-certificates (Ubuntu Lucid)
Status: Fix Committed => Fix Released

** Changed in: ca-certificates (Ubuntu Maverick)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-09 04:04:30 UTC
Permalink
This bug was fixed in the package ca-certificates -
20090814+nmu2ubuntu0.1

---------------
ca-certificates (20090814+nmu2ubuntu0.1) natty-security; urgency=low

* SECURITY UPDATE: Blacklist "DigiNotar Root CA" due to fraudulent
certificate issuance (LP: #837557)
- update mozilla/blacklist.txt
-- Micah Gersten <micahg at ubuntu.com> Thu, 01 Sep 2011 11:53:21 -0500
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-09 04:13:25 UTC
Permalink
** Branch linked: lp:ubuntu/lucid-security/ca-certificates

** Branch linked: lp:ubuntu/natty-security/ca-certificates

** Branch linked: lp:ubuntu/maverick-security/ca-certificates
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-09 04:04:27 UTC
Permalink
This bug was fixed in the package ca-certificates -
20090814ubuntu0.10.10.1

---------------
ca-certificates (20090814ubuntu0.10.10.1) maverick-security; urgency=low

* SECURITY UPDATE: Blacklist "DigiNotar Root CA" due to fraudulent
certificate issuance (LP: #837557)
- update mozilla/blacklist.txt
-- Micah Gersten <micahg at ubuntu.com> Thu, 01 Sep 2011 11:42:30 -0500

** Changed in: ca-certificates (Ubuntu Natty)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-09 10:30:16 UTC
Permalink
This bug was fixed in the package qt4-x11 - 4:4.7.4-0ubuntu1

---------------
qt4-x11 (4:4.7.4-0ubuntu1) oneiric; urgency=low

* New upstream release (LP: #839557, #785318)
* debian/patches/Add_support_for_QT_USE_DRAG_DISTANCE_env_var.patch,
debian/patches/a11y_qt_and_qml_backport.diff,
debian/patches/qtdebug_syslog.patch,
debian/patches/kubuntu_12_fix_stack_protector.diff,
debian/patches/kubuntu_28_xi2.1.patch:
- adapt to new upstream version
* Fix_GL_problems_on_stock_1.4_SGX_drivers.patch,
Fixed_missing_text_when_using_static_text_items_in_GL_2_engine.patch,
Prevent_recursion_when_creating_window_surface.patch,
kubuntu_24_large_qtreeview.diff,
kubuntu_27_dbus_signal_filter_passes_not_handled.diff:
- removed, part of the upstream tarball now
* debian/patches/kubuntu_15_appmenu.diff:
- updated to take a version closer to the upstreamed 4.8 one. Is compatible
with incoming appmenu-qt 0.2.2 (LP: #838115)
* debian/libqt4-declarative.install:
- libtcpserver.so has been renamed libqmldbg_tcp.so
* debian/control, debian/libqt4-declarative-shaders.install:
- add the new shaders package. Use the same suggests/recommends pattern
than other declarative-* plugins
* debian/patches/blacklist-diginotar-certs.diff:
- add DigiNotar securty breach blacklist (LP: #837557)
-- Didier Roche <didrocks at ubuntu.com> Thu, 08 Sep 2011 11:33:52 +0200

** Changed in: qt4-x11 (Ubuntu Oneiric)
Status: Triaged => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-09 11:57:22 UTC
Permalink
** Branch linked: lp:ubuntu/qt4-x11
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-09 18:05:17 UTC
Permalink
This bug was fixed in the package nss - 3.12.9+ckbi-1.82-0ubuntu5

---------------
nss (3.12.9+ckbi-1.82-0ubuntu5) oneiric; urgency=low

* SECURITY UPDATE: Add patch from Debian version 3.12.11-3 rebased against
3.12.9 to remove the DigiNotar certificates and actively distrust them;
Thanks to Mike Hommey from Debian for the original patch (LP: #837557)
- mozilla/security/nss/lib/ckfw/builtins/certdata.*:
Explicitely distrust various DigiNotar CAs:
- DigiNotar Root CA
- DigiNotar Services 1024 CA
- DigiNotar Cyber CA
- DigiNotar Cyber CA 2nd
- DigiNotar PKIoverheid
- DigiNotar PKIoverheid G2
- mozilla/security/nss/lib/ckfw/builtins/certdata.*:
Remove DigiNotar Root CA.
* Add a symlink from Linux2.6.mk to Linux3.0.mk; This is a temporary hack to
let NSS build on a 3.0.x kernel
- update debian/rules
-- Micah Gersten <micahg at ubuntu.com> Fri, 09 Sep 2011 11:57:13 -0500

** Changed in: nss (Ubuntu Oneiric)
Status: Confirmed => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-09 19:10:23 UTC
Permalink
** Branch linked: lp:ubuntu/nss
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Micah Gersten
2011-09-09 23:39:29 UTC
Permalink
Lucid, Maverick, and Natty builds of qt4-x11 will be available in
ubuntu-security-proposed in several hours for anyone who is interested

** Changed in: nss (Ubuntu Oneiric)
Assignee: (unassigned) => Micah Gersten (micahg)

** Changed in: qt4-x11 (Ubuntu Maverick)
Status: In Progress => Fix Committed

** Changed in: qt4-x11 (Ubuntu Natty)
Status: In Progress => Fix Committed
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Micah Gersten
2011-09-09 23:44:48 UTC
Permalink
While Lucid doesn't have the DigiNotar root CA, we can still blacklist
like we did for Comodo.

** Changed in: qt4-x11 (Ubuntu Lucid)
Status: Confirmed => Fix Committed

** Changed in: qt4-x11 (Ubuntu Lucid)
Assignee: (unassigned) => Micah Gersten (micahg)
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Gerrit Steenkamp
2011-09-19 12:26:48 UTC
Permalink
** Changed in: ca-certificates (Debian)
Importance: Unknown => Undecided

** Changed in: ca-certificates (Debian)
Status: Fix Released => New

** Changed in: ca-certificates (Debian)
Remote watch: Debian Bug tracker #639744 => None
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Micah Gersten
2011-09-19 16:31:11 UTC
Permalink
Please don't change bug watches without a comment.

** Changed in: ca-certificates (Debian)
Importance: Undecided => Unknown

** Changed in: ca-certificates (Debian)
Status: New => Unknown

** Changed in: ca-certificates (Debian)
Remote watch: None => Debian Bug tracker #639744
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Bug Watch Updater
2011-09-19 22:03:28 UTC
Permalink
** Changed in: ca-certificates (Debian)
Status: Unknown => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-21 22:56:28 UTC
Permalink
** Branch linked: lp:thunderbird/stable
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-22 16:03:40 UTC
Permalink
This bug was fixed in the package qt4-x11 - 4:4.6.2-0ubuntu5.3

---------------
qt4-x11 (4:4.6.2-0ubuntu5.3) lucid-security; urgency=low

* SECURITY UPDATE: Blacklist Diginotar root and intermediate certificates;
Fraudulent certificates were mis-issued that could allow an attacker to
monitor secure communication through a man-in-the-middle (MITM) attack
- add debian/patches/kubuntu_31_blacklist_ssl_certificates_part2.diff
- LP: #837557
-- Micah Gersten <micahg at ubuntu.com> Fri, 09 Sep 2011 18:36:48 -0500

** Changed in: qt4-x11 (Ubuntu Lucid)
Status: Fix Committed => Fix Released

** Changed in: qt4-x11 (Ubuntu Maverick)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-22 16:05:26 UTC
Permalink
This bug was fixed in the package qt4-x11 - 4:4.7.0-0ubuntu4.4

---------------
qt4-x11 (4:4.7.0-0ubuntu4.4) maverick-security; urgency=low

* SECURITY UPDATE: Blacklist Diginotar root and intermediate certificates;
Fraudulent certificates were mis-issued that could allow an attacker to
monitor secure communication through a man-in-the-middle (MITM) attack
- add debian/patches/kubuntu_31_blacklist_ssl_certificates_part2.diff
- LP: #837557
-- Micah Gersten <micahg at ubuntu.com> Fri, 09 Sep 2011 15:43:49 -0500

** Changed in: qt4-x11 (Ubuntu Natty)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-22 16:06:41 UTC
Permalink
This bug was fixed in the package qt4-x11 - 4:4.7.2-0ubuntu6.3

---------------
qt4-x11 (4:4.7.2-0ubuntu6.3) natty-security; urgency=low

* SECURITY UPDATE: Blacklist Diginotar root and intermediate certificates;
Fraudulent certificates were mis-issued that could allow an attacker to
monitor secure communication through a man-in-the-middle (MITM) attack
- add debian/patches/kubuntu_31_blacklist_ssl_certificates_part2.diff
- LP: #837557
-- Micah Gersten <micahg at ubuntu.com> Fri, 09 Sep 2011 18:27:52 -0500
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-22 17:16:24 UTC
Permalink
** Branch linked: lp:ubuntu/lucid-security/qt4-x11

** Branch linked: lp:ubuntu/maverick-security/qt4-x11

** Branch linked: lp:ubuntu/natty-security/qt4-x11
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2011-09-22 19:32:24 UTC
Permalink
** Branch linked: lp:firefox/stable
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Dmitry Shachnev
2011-10-05 12:23:13 UTC
Permalink
Fixed with the recent update to Chromium 14.

** Changed in: chromium-browser (Ubuntu Oneiric)
Status: Confirmed => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Dmitry Shachnev
2011-10-12 15:27:39 UTC
Permalink
** Changed in: chromium-browser (Ubuntu Lucid)
Status: Confirmed => Fix Committed

** Changed in: chromium-browser (Ubuntu Maverick)
Status: Confirmed => Fix Committed

** Changed in: chromium-browser (Ubuntu Natty)
Status: Confirmed => Fix Committed
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Micah Gersten
2011-10-12 21:44:54 UTC
Permalink
Fixed in 14.0.835.202~r103287-0ubuntu0.10.04.2

** Changed in: chromium-browser (Ubuntu Lucid)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Micah Gersten
2011-10-12 21:48:08 UTC
Permalink
Fixed in 14.0.835.202~r103287-0ubuntu0.10.10.1

** Changed in: chromium-browser (Ubuntu Maverick)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Micah Gersten
2011-10-17 06:25:03 UTC
Permalink
Fixed in 14.0.835.202~r103287-0ubuntu0.11.04.1

** Changed in: chromium-browser (Ubuntu Natty)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2012-02-17 23:04:20 UTC
Permalink
This bug was fixed in the package xulrunner-1.9.2 - 1.9.2.27+build1
+nobinonly-0ubuntu0.11.04.1

---------------
xulrunner-1.9.2 (1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1) natty-security; urgency=low

* SECURITY UPDATE: New upstream release v1.9.2.27 (FIREFOX_3_6_27_BUILD1)
See the following for more information:
- LP: #934073
- USN-1353-1
- USN-1251-1
- USN-1210-1
- LP: #838322
- LP: #837557
- USN-1184-1
- USN-1149-1
-- Jamie Strandboge <jamie at ubuntu.com> Fri, 17 Feb 2012 08:04:19 -0600

** Changed in: xulrunner-1.9.2 (Ubuntu Natty)
Status: Triaged => Fix Released
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Launchpad Bug Tracker
2012-02-17 23:25:21 UTC
Permalink
** Branch linked: lp:ubuntu/natty-security/xulrunner-1.9.2
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Jamie Strandboge
2012-04-13 15:44:53 UTC
Permalink
Thank you for reporting this bug to Ubuntu. maverick has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against maverick is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

** Changed in: seamonkey (Ubuntu Maverick)
Status: Confirmed => Won't Fix
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Jamie Strandboge
2012-11-02 11:49:07 UTC
Permalink
Thank you for reporting this bug to Ubuntu. natty has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against natty is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

** Changed in: seamonkey (Ubuntu Natty)
Status: Confirmed => Won't Fix
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Jamie Strandboge
2013-05-21 15:45:53 UTC
Permalink
Thank you for reporting this bug to Ubuntu. oneiric has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against oneiric is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

** Changed in: seamonkey (Ubuntu Oneiric)
Status: Confirmed => Won't Fix
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
Jamie Strandboge
2013-05-22 12:45:38 UTC
Permalink
** Changed in: seamonkey (Ubuntu Lucid)
Status: Confirmed => Won't Fix
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
lucianolove
2015-04-22 15:58:16 UTC
Permalink
** Branch unlinked: lp:~mozillateam/firefox/firefox.head
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
--
kubuntu-bugs mailing list
kubuntu-***@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/kubuntu-bugs
Justin Means
2015-05-12 17:24:17 UTC
Permalink
** Changed in: ca-certificates (Ubuntu)
Assignee: Jamie Strandboge (jdstrand) => (unassigned)
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
--
kubuntu-bugs mailing list
kubuntu-***@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/kubuntu-bugs
Nora Blob
2018-11-24 16:32:35 UTC
Permalink
Hello I observed this issue in:

No LSB modules are available.
Distributor ID: Ubuntu
Description: Ubuntu 17.10
Release: 17.10
Codename: artful

I also observed it in a local build from the gentoo repositories. I
attached the certs and will open issues at gentoo and mozilla.
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
--
kubuntu-bugs mailing list
kubuntu-***@lists.ubuntu.com
Nora Blob
2018-11-24 16:33:09 UTC
Permalink
** Attachment added: "certs.tar.bz2"
https://bugs.launchpad.net/ubuntu/+source/seamonkey/+bug/837557/+attachment/5215891/+files/certs.tar.bz2
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
--
kubuntu-bugs mailing list
kubuntu-***@lists.ubuntu.com
https://lists.ubu
Nora Blob
2018-11-24 16:34:01 UTC
Permalink
** Attachment added: "certs.tar.bz2.gpg"
https://bugs.launchpad.net/ubuntu/+source/seamonkey/+bug/837557/+attachment/5215892/+files/certs.tar.bz2.gpg
--
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to qt4-x11 in Ubuntu.
https://bugs.launchpad.net/bugs/837557

Title:
fraudulent DigiNotar certificate issuance

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/837557/+subscriptions
--
kubuntu-bugs mailing list
kubuntu-***@lists.ubuntu.com
https://l
Loading...