Your message dated Mon, 25 Jan 2010 15:22:42 +0000
with message-id <[email protected]>
and subject line Bug#560953: fixed in smart 1.2-5
has caused the Debian Bug report #560953,
regarding CVE-2009-3560 and CVE-2009-3720 denial-of-services
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
560953: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560953
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
package: smart
severity: serious
tags: security
Hi,
The following CVE (Common Vulnerabilities & Exposures) ids were
published for expat. I have determined that this package embeds a
vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is
a mass bug filing (due to so many packages embedding expat), I have
not had time to determine whether the vulnerable code is actually
present in any of the binary packages derived from this source package.
Please determine whether this is the case. If the binary packages are
not affected, please feel free to close the bug with a message
containing the details of what you did to check.
CVE-2009-3560[0]:
| The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1,
| as used in the XML-Twig module for Perl, allows context-dependent
| attackers to cause a denial of service (application crash) via an XML
| document with malformed UTF-8 sequences that trigger a buffer
| over-read, related to the doProlog function in lib/xmlparse.c, a
| different vulnerability than CVE-2009-2625 and CVE-2009-3720.
CVE-2009-3720[1]:
| The updatePosition function in lib/xmltok_impl.c in libexpat in Expat
| 2.0.1, as used in Python, PyXML, w3c-libwww, and other software,
| allows context-dependent attackers to cause a denial of service
| (application crash) via an XML document with crafted UTF-8 sequences
| that trigger a buffer over-read, a different vulnerability than
| CVE-2009-2625.
These issues also affect old versions of expat, so this package in etch
and lenny is very likely affected. This is a low-severity security
issue, so DSAs will not be issued to correct these problems. However,
you can optionally submit a proposed-update to the release team for
inclusion in the next stable point releases. If you plan to do this,
please open new bugs and include the security tag so we are aware that
you are working on that.
For further information see [0],[1],[2],[3]. In particular, [2] and [3]
are links to the patches for CVE-2009-3560 and CVE-2009-3720
respectively. Note that the ideal solution would be to make use of the
system expat so only one package will need to be updated for future
security issues. Preferably in your update to unstable, alter your
package to make use of the system expat.
If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3560
http://security-tracker.debian.org/tracker/CVE-2009-3560
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3720
http://security-tracker.debian.org/tracker/CVE-2009-3720
[2]
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.165
[3]
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&r2=1.15&view=patch
--- End Message ---
--- Begin Message ---
Source: smart
Source-Version: 1.2-5
We believe that the bug you reported is fixed in the latest version of
smart, which is due to be installed in the Debian FTP archive:
python-smartpm_1.2-5_amd64.deb
to main/s/smart/python-smartpm_1.2-5_amd64.deb
smart_1.2-5.diff.gz
to main/s/smart/smart_1.2-5.diff.gz
smart_1.2-5.dsc
to main/s/smart/smart_1.2-5.dsc
smartpm-core_1.2-5_amd64.deb
to main/s/smart/smartpm-core_1.2-5_amd64.deb
smartpm_1.2-5_all.deb
to main/s/smart/smartpm_1.2-5_all.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Free Ekanayaka <[email protected]> (supplier of updated smart package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Mon, 25 Jan 2010 14:32:42 +0100
Source: smart
Binary: smartpm smartpm-core python-smartpm
Architecture: source all amd64
Version: 1.2-5
Distribution: unstable
Urgency: low
Maintainer: Michael Vogt <[email protected]>
Changed-By: Free Ekanayaka <[email protected]>
Description:
python-smartpm - Python library of the Smart Package Manager
smartpm - An alternative package manager that works with dpkg/rpm
smartpm-core - An alternative package manager that works with dpkg/rpm
Closes: 560953
Changes:
smart (1.2-5) unstable; urgency=low
.
* Add 06_CVE-2009-3720 patch (Closes: #560953)
* Switch from pycentral to pysupport
Checksums-Sha1:
de877cf2806902c1520b9131c8de074cd5272e33 1071 smart_1.2-5.dsc
d11f5aa5f66c280a62c041672ddd442a05b43073 10478 smart_1.2-5.diff.gz
5150a1331fa2dadf6685403e6650f2468b7a324b 59240 smartpm_1.2-5_all.deb
0ee294b0d2817727c0af10d8268ee42e2f2536b5 16068 smartpm-core_1.2-5_amd64.deb
c130a1a439636c29c6cebba3ccc25ae5840eb481 215578 python-smartpm_1.2-5_amd64.deb
Checksums-Sha256:
08f55a58194a8d8cd21f06e08e2b1a76727bf3f4433744adc6caf816322a64b7 1071
smart_1.2-5.dsc
fa27aa57031f1728e677abbad6194f20c15e42d26e5f88e52a2d71235e147a0f 10478
smart_1.2-5.diff.gz
3750865cc49f31cf03112e61bbdfbc860c7b22c37ce9604164a3ea6142a5ade5 59240
smartpm_1.2-5_all.deb
dfd281dbff5e25c8bf3f6af08b35836c7237e4bfc1143ff63b5d385ced2daa4b 16068
smartpm-core_1.2-5_amd64.deb
abe5fa3b40f642567269c9a141dfb23ac4c2339de285e918b108682ad7f6fde6 215578
python-smartpm_1.2-5_amd64.deb
Files:
a5cf1add7f79ea9e38af04a413a0a241 1071 admin optional smart_1.2-5.dsc
7ae2b18f30b2ef935e5c83f8769fd827 10478 admin optional smart_1.2-5.diff.gz
1eb52a702dfc77e1c586a4e7a115b19c 59240 admin optional smartpm_1.2-5_all.deb
bd2241e89a46ea3619947e370e9e1abb 16068 admin optional
smartpm-core_1.2-5_amd64.deb
5c576b3a80689968801d1ee004d755f6 215578 admin optional
python-smartpm_1.2-5_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEARECAAYFAktdoHcACgkQcanJGlcVnlnYrgCggVkyA0pwrQrzUwbATPQrFaFa
fx4AmwRmn56YOq42ddLMn36fULLQr8lT
=+IOQ
-----END PGP SIGNATURE-----
--- End Message ---