Your message dated Tue, 23 Dec 2014 09:19:59 +0000
with message-id <[email protected]>
and subject line Bug#773148: fixed in file 1:5.21+15-1
has caused the Debian Bug report #773148,
regarding file: CVE-2014-8116 / CVE-2014-8117 recursion issues
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
773148: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773148
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
package: src:file
severity: important
version: 5.04-5
control: tag -1 patch

A couple recursion issues were discovered in file that could lead to
denial-of-service potentially:
https://www.freebsd.org/security/advisories/FreeBSD-SA-14:28.file.asc

Patches included in the freebsd advisory.

Best wishes,
Mike

--- End Message ---
--- Begin Message ---
Source: file
Source-Version: 1:5.21+15-1

We believe that the bug you reported is fixed in the latest version of
file, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Christoph Biedl <[email protected]> (supplier of updated file 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 21 Dec 2014 23:21:37 +0100
Source: file
Binary: file file-dbg libmagic1 libmagic-dev python-magic python3-magic
Architecture: source armhf all
Version: 1:5.21+15-1
Distribution: unstable
Urgency: high
Maintainer: Christoph Biedl <[email protected]>
Changed-By: Christoph Biedl <[email protected]>
Description:
 file       - Determines file type using "magic" numbers
 file-dbg   - Determines file type using "magic" numbers (debug)
 libmagic-dev - File type determination library using "magic" numbers 
(developmen
 libmagic1  - File type determination library using "magic" numbers
 python-magic - File type determination library using "magic" numbers (Python 
bin
 python3-magic - File type determination library using "magic" numbers (Python 
3 b
Closes: 773148
Changes:
 file (1:5.21+15-1) unstable; urgency=high
 .
   * Fixes a security issue, urgency set to high
   * New upstream version 5.21
     - Limit number of elf program and sections processing
     - Reduce the number of recursion levels
       Closes: #773148 (CVE-2014-8116, CVE-2014-8117)
   * Use upstream commit FILE5_21-15-ge7e96a9 to include all recent
     fixes.
Checksums-Sha1:
 97e67e9ae6bac318bb7f2596704e1bf3e6514ee1 2071 file_5.21+15-1.dsc
 efdf8cbc23d2fdbfc71bbf7cb11886f17f0a8dd5 568776 file_5.21+15.orig.tar.xz
 56271ed775cd4f1f6c67a50d4c7c8218fe060c7b 28932 file_5.21+15-1.debian.tar.xz
 464a94f3e88351563c27c4a429a83d54c507eb7f 59428 file_5.21+15-1_armhf.deb
 ae3207166b3ca95c1bbabc6d699a8b1bb22ed444 187226 file-dbg_5.21+15-1_armhf.deb
 e627413889c31c3e0ea68f7e51e8f1dbafab5840 244242 libmagic1_5.21+15-1_armhf.deb
 ac8cc08ee46ea5bb322ddd3185d96f457cd65899 105254 
libmagic-dev_5.21+15-1_armhf.deb
 0243c06eedd6324fdebb08586f423950976805f0 44740 python-magic_5.21+15-1_all.deb
 1e2f213fbc0005cd52c5da50177d23bad7f732bd 44804 python3-magic_5.21+15-1_all.deb
Checksums-Sha256:
 dcac7a841eb88d9f1e75bcaffd9fbcd12819db42b4cf248c0e5dc47dcfbc18e3 2071 
file_5.21+15-1.dsc
 c373b214c82f2339c8baf2825279acff1e4bbab45aee28c86c898c353d13a600 568776 
file_5.21+15.orig.tar.xz
 81bf4bc2455d693f30647ffffd364d4504e78c6b5f17da6f7ae248c6cf35b458 28932 
file_5.21+15-1.debian.tar.xz
 556b6518e8d7746ebdc371fb8b80181e4b53eb820cef658a4566430ac4bd1a9c 59428 
file_5.21+15-1_armhf.deb
 590d97ec8f8563b85db844f9e5f7b66cc9e8cc120ff4d03a33bc53939e61d7d9 187226 
file-dbg_5.21+15-1_armhf.deb
 2362ef1617cc2510ca2d2eee7355359679c2009b585ad6bea71b08ef99251660 244242 
libmagic1_5.21+15-1_armhf.deb
 9b7f17ccd3f14b97b1ec110e6d4d30ee08b9446ac606ae89d12df93412175e32 105254 
libmagic-dev_5.21+15-1_armhf.deb
 38be20ceceee18b778dee435ecd66f4332818c36820fa3e083c3e242de23a427 44740 
python-magic_5.21+15-1_all.deb
 595746ec053376a51fd565b8f532f8a82b71597587d99797aa4716c8aadbaf6e 44804 
python3-magic_5.21+15-1_all.deb
Files:
 32092a9c0bb719dda7b72d789574ca4d 2071 utils standard file_5.21+15-1.dsc
 66c714236085fd7df39d0a6e162de73e 568776 utils standard file_5.21+15.orig.tar.xz
 454103dbe01066515ad049d1d9094528 28932 utils standard 
file_5.21+15-1.debian.tar.xz
 07e71593d39fc04123bd6b17c7fdbac8 59428 utils standard file_5.21+15-1_armhf.deb
 de5e3d52535434553051dd652d12c7e3 187226 debug extra 
file-dbg_5.21+15-1_armhf.deb
 8ac936fce461f7ee49c2706dd59dc853 244242 libs standard 
libmagic1_5.21+15-1_armhf.deb
 e9497ab595e3dc3dcb8462b6c6dbd1b7 105254 libdevel optional 
libmagic-dev_5.21+15-1_armhf.deb
 6adcbb530bf468f15e7757286681ec03 44740 python optional 
python-magic_5.21+15-1_all.deb
 6a8d8db1d34611269b0f6b007493c8b6 44804 python optional 
python3-magic_5.21+15-1_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBCgAGBQJUmReCAAoJEMQsWOtZFJL9bRUQALvGMKpsa4KynomNj7YIhglM
0xiftzsMTUmf3uYuNV7jIY0MkDoygNzmcPRQdywvnNjKOeustFro1aFgIBXifi89
kZgJ+FeK4I9mudfNSvsru+A8Jf6tquPRAYMo4IY6cviMIpGB2W/jGzdBdEu4BFmw
cYJk/bM8JB64B+krSqxIXDav78Ss5zkLJ3EyWL/Qdiso8EHN7kN+NSFYgcLzpYfy
EiA1wNvjtoLuTifE+tYtmmcLeuDZQu5TynvbGnjuIvs1Y7tzG0VUxS6n+6zK2+RB
yq55TaJuvf7MIjEaYl/gozt1vBDDhAN44HVxZvGa2GSTu75bBDdUVOAEbaeLdYWd
JzUqCVnw8IRmXTGwy6J/SyoeaiIE/kE+B42ALJAMZk+x9Bdd7c3IXWPvmTce0Tf8
dhvD2IPZ8Xc0attnr6Gsly4wohyeS+mpa3mbpMMuIY0rsVLrXZr1OAMMfcMdK9N4
zzRSmYsxvBagGrcG7YsZILUrl2qDcnjiwwLDBhAtiMbWJ/ekKmqlKeFEv8dO5zMt
HHou0rVUMG17mHUw5ANNp+pMfB7TLZHkFypL+hiCnfYk9XBcdcBsO5t9sigwwgu0
CV0ZVEz5BmFhRgPa2/CaSUIvt7sCUTMBnOlByXqFfY8iQTVWtzLeq4jEF1vLQ7ff
iqL5x4l7ucj611eRfh92
=X9SW
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to