Your message dated Wed, 15 Jun 2016 15:16:52 +0200
with message-id <[email protected]>
and subject line Re: Bug#827377: file: CVE-2015-8865: file_check_mem()
misbehaves on some input
has caused the Debian Bug report #827377,
regarding file: CVE-2015-8865: file_check_mem() misbehaves on some input
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
827377: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=827377
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: src:file
Version: 1:5.22+15-2
Severity: important
According to
<URL: https://security-tracker.debian.org/tracker/CVE-2015-8865 >, the
file package in Jessie have an open security hole. The description look
like this:
The file_check_mem function in funcs.c in file before 5.23, as used in
the Fileinfo component in PHP before 5.5.34, 5.6.x before 5.6.20, and
7.x before 7.0.5, mishandles continuation-level jumps, which allows
context-dependent attackers to cause a denial of service (buffer
overflow and application crash) or possibly execute arbitrary code via
a crafted magic file.
The problem was fixed in Wheezy (DLA-460-1), but is not listed as fixed
in Jessie. Is there problem still around in Jessie? If not, would you
be willing to upload a update to Jessie?
As the problem is said to be fixed in version 5.23, it is no longer
present in Stretch and Sid.
--
Happy hacking
Petter Reinholdtsen
--- End Message ---
--- Begin Message ---
Version: 1:5.23-1
This issue is fixed in a recent package and only unsolved in Jessie.
--
Happy hacking
Petter Reinholdtsen
--- End Message ---