Your message dated Thu, 06 Nov 2008 21:17:03 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#504194: fixed in jhead 2.85-1
has caused the Debian Bug report #504194,
regarding CVE-2008-4640: insecure file handling
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)
--
504194: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504194
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
--- Begin Message ---
Package: jhead
Severity: grave
Tags: security
Hi,
the following CVE (Common Vulnerabilities & Exposures) ids were
published for jhead.
CVE-2008-4641[0]:
| The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and
| earlier allows attackers to execute arbitrary commands via shell
| metacharacters in unspecified input.
CVE-2008-4640[1]:
| The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and
| earlier allows local users to delete arbitrary files via vectors
| involving a modified input filename in which (1) a final "z" character
| is replaced by a "t" character or (2) a final "t" character is
| replaced by a "z" character.
If you fix the vulnerabilities please also make sure to include the
CVE ids in your changelog entry.
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4641
http://security-tracker.debian.net/tracker/CVE-2008-4641
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4640
http://security-tracker.debian.net/tracker/CVE-2008-4640
--
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
pgpLXQ2EFLg34.pgp
Description: PGP signature
--- End Message ---
--- Begin Message ---
Source: jhead
Source-Version: 2.85-1
We believe that the bug you reported is fixed in the latest version of
jhead, which is due to be installed in the Debian FTP archive:
jhead_2.85-1.diff.gz
to pool/main/j/jhead/jhead_2.85-1.diff.gz
jhead_2.85-1.dsc
to pool/main/j/jhead/jhead_2.85-1.dsc
jhead_2.85-1_amd64.deb
to pool/main/j/jhead/jhead_2.85-1_amd64.deb
jhead_2.85.orig.tar.gz
to pool/main/j/jhead/jhead_2.85.orig.tar.gz
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Ludovic Rousseau <[EMAIL PROTECTED]> (supplier of updated jhead package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Thu, 06 Nov 2008 21:51:09 +0100
Source: jhead
Binary: jhead
Architecture: source amd64
Version: 2.85-1
Distribution: unstable
Urgency: low
Maintainer: Ludovic Rousseau <[EMAIL PROTECTED]>
Changed-By: Ludovic Rousseau <[EMAIL PROTECTED]>
Description:
jhead - manipulate the non-image part of Exif compliant JPEG files
Closes: 504194
Changes:
jhead (2.85-1) unstable; urgency=low
.
* New upstream release
- Closes: #504194 "CVE-2008-4640: insecure file handling"
* debian/patches/11_jhead.c.dpatch: removed since included upstream
* debian/*: change from dpatch to quilt
Checksums-Sha1:
3d13991e53e2ad769a6ed81bdff7c3a7d7e08368 979 jhead_2.85-1.dsc
054758fe826de7b15d5869889b03feb4285c48d4 62525 jhead_2.85.orig.tar.gz
c82e1b28f16968520436dac5e6afb721794bdcf3 5768 jhead_2.85-1.diff.gz
1890180a73193afaf038331cd9881cdf1b16c269 43784 jhead_2.85-1_amd64.deb
Checksums-Sha256:
0c32c805dc32dc7108b3ee5216a8bbc219ff6b4cf6b6d56b23be104fa473edd8 979
jhead_2.85-1.dsc
9870104a2642a1ba2fd73251746816ae6fc1a65f0edec96e1aade735618fb56c 62525
jhead_2.85.orig.tar.gz
5588119f9caedb47eb43b21b84d82af26f043bbedb9cf6b64f4a6e9ae8502611 5768
jhead_2.85-1.diff.gz
4762ac3aceaee3cb7984fe850bad51ffd7d5a3f348ee386dd8af11f67d0d230c 43784
jhead_2.85-1_amd64.deb
Files:
ca84c6d19d095b171969bb45dddbd515 979 graphics optional jhead_2.85-1.dsc
15f77e412cf4174c7e8e2773901df9ae 62525 graphics optional jhead_2.85.orig.tar.gz
3b9f4cf4bdda3064f93cb4406a43d08e 5768 graphics optional jhead_2.85-1.diff.gz
903554679fde9ff58152bfd2db610440 43784 graphics optional jhead_2.85-1_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAkkTXKUACgkQP0qKj+B/HPn3FQCbBqMkcwO66fYWl9KlbnddrGDE
wAoAnRMU5dWaQFmF7enfgQic6En1sXNM
=Ni9p
-----END PGP SIGNATURE-----
--- End Message ---