Your message dated Sun, 28 May 2017 17:03:35 +0000
with message-id <[email protected]>
and subject line Bug#863186: fixed in libtasn1-6 4.10-1.1
has caused the Debian Bug report #863186,
regarding libtasn1-6: CVE-2017-6891
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
863186: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863186
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libtasn1-6
Version: 4.2-3
Severity: important
Tags: security upstream patch fixed-upstream

Hi,

the following vulnerability was published for libtasn1-6.

CVE-2017-6891[0]:
| Two errors in the "asn1_find_node()" function (lib/parser_aux.c)
| within GnuTLS libtasn1 version 4.10 can be exploited to cause a
| stacked-based buffer overflow by tricking a user into processing a
| specially crafted assignments file via the e.g. asn1Coding utility.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-6891
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6891
[1] 
https://git.savannah.gnu.org/gitweb/?p=libtasn1.git;a=commit;h=5520704d075802df25ce4ffccc010ba1641bd484

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: libtasn1-6
Source-Version: 4.10-1.1

We believe that the bug you reported is fixed in the latest version of
libtasn1-6, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated libtasn1-6 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 25 May 2017 10:25:56 +0200
Source: libtasn1-6
Binary: libtasn1-6-dev libtasn1-doc libtasn1-6 libtasn1-bin libtasn1-3-bin
Architecture: all source
Version: 4.10-1.1
Distribution: unstable
Urgency: medium
Maintainer: Debian GnuTLS Maintainers <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 863186
Description: 
 libtasn1-3-bin - transitional libtasn1-3-bin package
 libtasn1-6 - Manage ASN.1 structures (runtime)
 libtasn1-6-dev - Manage ASN.1 structures (development)
 libtasn1-bin - Manage ASN.1 structures (binaries)
 libtasn1-doc - Manage ASN.1 structures (documentation)
Changes:
 libtasn1-6 (4.10-1.1) unstable; urgency=medium
 .
   * Non-maintainer upload.
   * asn1_find_node: added safety check on asn1_find_node() (CVE-2017-6891)
     (Closes: #863186)
Checksums-Sha1: 
 0abdf466267ebdab8f19bd83203bb8fa5d3660af 2586 libtasn1-6_4.10-1.1.dsc
 d901e81f3d552be26f13f5811606b743f1b4f24c 58400 
libtasn1-6_4.10-1.1.debian.tar.xz
 25cccadaf153cf9a04056155e39bb52d5db1733c 18162 libtasn1-3-bin_4.10-1.1_all.deb
 9baff143c0369a6b1e54bfee694f6ef005241657 315412 libtasn1-doc_4.10-1.1_all.deb
Checksums-Sha256: 
 1ace0b64d79a7c79d00d9f7719ce56c5274fbfd253681f01b303badb09242c1b 2586 
libtasn1-6_4.10-1.1.dsc
 275f7e74697ca1ef085dab5e41fe82d0c9ee898d4f6f4cd2873b09099850e939 58400 
libtasn1-6_4.10-1.1.debian.tar.xz
 adb106edcc4e37888451391c93a5b5a8d164eef3ad31b5b0f06623900489d53c 18162 
libtasn1-3-bin_4.10-1.1_all.deb
 88cd69b193552e3f823535c3a79afd6f5dfce55195f31770f8e432c046fbaaa0 315412 
libtasn1-doc_4.10-1.1_all.deb
Files: 
 4ab385b11a417d6a9fead1ba189f7433 2586 libs standard libtasn1-6_4.10-1.1.dsc
 1cefc4fb68676d72837aad4114a3234f 58400 libs standard 
libtasn1-6_4.10-1.1.debian.tar.xz
 25d5b68a99bdf7e4167853e02c4bf7bf 18162 oldlibs extra 
libtasn1-3-bin_4.10-1.1_all.deb
 83cb1fd3a80a991410f85985e54f49a2 315412 doc extra libtasn1-doc_4.10-1.1_all.deb

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlkml9lfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89Ed+kQAJkR7qw/FtknpglN7/0wEtWiUhoRgt+g
kmc00VJUqEqf4bL/B0gqk9VNIf5BJD5V/xG6+hxfQro2OQ+yJfFuswVF5PT28St9
NzzLG7jOIeGJcoDEW44jhZO4mqW/lb0X+eOOlsYC0nOrxdQVygI+i1mUaSGTKEmB
Lg4qOm1BT6Ii5xB62iC1OT0rFjoG/lOMLTMN5HIfOl38Z9svmZJ6cVTQkBdTBipE
reiF1FwqSH4dc0Ih0nr2z7kBIfvpWRlhqI2H3XQiyX5T7b5ld6CW6DmqBtKGgrLs
CH3Ka+JC2CwEM1Pjypof72GnPuGZKKkE+Yh+dFuG6sG2ZPuKt/qseRE5KvuHjAjJ
WeuG4j/f25sy0yEw/UlLCmrSvzUqO3guhZa38HfTDQiB900NU2BSacpoFNFaj+lE
i86ZGvVlYbNeFB/AAgSVpbyvPJYJwTsmPZ0OwybIM2rJW2n3tuKXjMdW1M3yV+kA
V9u4/pSiwy/3amUnsrbVhN1pL1zHPchhQVtOFBEHxKOSaAnOasgs4H6FMuMGXoXK
ffwGyLH6ONOqIu1AWViCNL4Utwf/dg3YzBrbaO+8ic7s1GFsKavJ8M8zDed110XK
4S8qkXwnQylWoU34mPs3HpFT4/LJCZNAMQBx6vlbBA/2uhi3icrhEe7C1B9wBV9y
cneoVoWLcUUz
=Fm33
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to