Your message dated Mon, 29 May 2017 13:47:28 +0000
with message-id <[email protected]>
and subject line Bug#863186: fixed in libtasn1-6 4.2-3+deb8u3
has caused the Debian Bug report #863186,
regarding libtasn1-6: CVE-2017-6891
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
863186: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863186
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libtasn1-6
Version: 4.2-3
Severity: important
Tags: security upstream patch fixed-upstream
Hi,
the following vulnerability was published for libtasn1-6.
CVE-2017-6891[0]:
| Two errors in the "asn1_find_node()" function (lib/parser_aux.c)
| within GnuTLS libtasn1 version 4.10 can be exploited to cause a
| stacked-based buffer overflow by tricking a user into processing a
| specially crafted assignments file via the e.g. asn1Coding utility.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2017-6891
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6891
[1]
https://git.savannah.gnu.org/gitweb/?p=libtasn1.git;a=commit;h=5520704d075802df25ce4ffccc010ba1641bd484
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: libtasn1-6
Source-Version: 4.2-3+deb8u3
We believe that the bug you reported is fixed in the latest version of
libtasn1-6, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thorsten Alteholz <[email protected]> (supplier of updated libtasn1-6 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 23 May 2017 19:01:02 +0200
Source: libtasn1-6
Binary: libtasn1-6-dev libtasn1-doc libtasn1-6-dbg libtasn1-6 libtasn1-bin
libtasn1-3-bin
Architecture: source amd64 all
Version: 4.2-3+deb8u3
Distribution: jessie-security
Urgency: high
Maintainer: Debian GnuTLS Maintainers <[email protected]>
Changed-By: Thorsten Alteholz <[email protected]>
Description:
libtasn1-3-bin - transitional libtasn1-3-bin package
libtasn1-6 - Manage ASN.1 structures (runtime)
libtasn1-6-dbg - Manage ASN.1 structures (debugging symbols)
libtasn1-6-dev - Manage ASN.1 structures (development)
libtasn1-bin - Manage ASN.1 structures (binaries)
libtasn1-doc - Manage ASN.1 structures (documentation)
Closes: 863186
Changes:
libtasn1-6 (4.2-3+deb8u3) jessie-security; urgency=high
.
* Non-maintainer upload by the Wheezy LTS Team.
* CVE-2017-6891 (Closes: #863186)
two errors in the "asn1_find_node()" function (lib/parser_aux.c)
can be exploited to cause a stacked-based buffer overflow.
Checksums-Sha1:
bd3e7ea36161f91550666aaef4c617032c5211be 2607 libtasn1-6_4.2-3+deb8u3.dsc
d2fe4bf12dbdc4d6765a04abbf8ddaf7e9163afa 1866192 libtasn1-6_4.2.orig.tar.gz
90e17e607492c8c508c54c6768dfd2ee68ab8cbb 59144
libtasn1-6_4.2-3+deb8u3.debian.tar.xz
4e88435ca76cf3298fd5202d1c6744c5653bdf8f 90824
libtasn1-6-dev_4.2-3+deb8u3_amd64.deb
b4495d21fdacea3f3a8777738f61c2cd450a2852 305278
libtasn1-doc_4.2-3+deb8u3_all.deb
27e377eba0abbd1e6b152d07daa06d82794d5f87 109254
libtasn1-6-dbg_4.2-3+deb8u3_amd64.deb
44245b5d3fab184f670cda413aee7ceb0729441b 49190
libtasn1-6_4.2-3+deb8u3_amd64.deb
80e2b99982d248dafeb03d76ab4f96df0d3257e3 23038
libtasn1-bin_4.2-3+deb8u3_amd64.deb
029e4f139e68640ffc80ac072a8876d93b9c086f 10108
libtasn1-3-bin_4.2-3+deb8u3_all.deb
Checksums-Sha256:
dee600f7bdacd1fa75d40a13425e6c81d36b979fd23aab468000a1bfc18706ba 2607
libtasn1-6_4.2-3+deb8u3.dsc
693b41cb36c2ac02d5990180b0712a79a591168e93d85f7fcbb75a0a0be4cdbb 1866192
libtasn1-6_4.2.orig.tar.gz
59ba69bafbe22542f58bc63eab30b70b5ce15673f8b7b8332c21b72e33572d28 59144
libtasn1-6_4.2-3+deb8u3.debian.tar.xz
89a2c0ffdf5c11cc2dce44aa4dbe9681d66c7d043d0be93bb461edbea0f77e5d 90824
libtasn1-6-dev_4.2-3+deb8u3_amd64.deb
f25d9141287e29e375364adae1bf35762191951117061eb02ea618622dac9007 305278
libtasn1-doc_4.2-3+deb8u3_all.deb
4729a31a12a20b2289dbd8e1bff8a973501d3c2003630b7fbc5cd19fb4556416 109254
libtasn1-6-dbg_4.2-3+deb8u3_amd64.deb
36e01f21f439ede1e6957110798375808303d2c6549236811844bf014add93d0 49190
libtasn1-6_4.2-3+deb8u3_amd64.deb
7d838e0dc2d2ec47445296156be84fc638d56653890ac90833e20903f90bf92d 23038
libtasn1-bin_4.2-3+deb8u3_amd64.deb
2f302ee7bf75e033590a465a46ffc378799dfcc53d17ae1646c425d51ead3faa 10108
libtasn1-3-bin_4.2-3+deb8u3_all.deb
Files:
d34302e885211d3425684b25d847a620 2607 libs standard libtasn1-6_4.2-3+deb8u3.dsc
414df906df421dee0a5cf7548788d153 1866192 libs standard
libtasn1-6_4.2.orig.tar.gz
bc54e843a173686b4f35e31adac3187b 59144 libs standard
libtasn1-6_4.2-3+deb8u3.debian.tar.xz
bc6dbf1ab81fe92a58a3d79307fcb66e 90824 libdevel optional
libtasn1-6-dev_4.2-3+deb8u3_amd64.deb
f26a2f27f46bdca1adaad8b6b505387d 305278 doc extra
libtasn1-doc_4.2-3+deb8u3_all.deb
6aaae6dd60151ed979be040c3d7f5ca9 109254 debug extra
libtasn1-6-dbg_4.2-3+deb8u3_amd64.deb
a499b50b82bf324aba2f937fd5b3f4ea 49190 libs standard
libtasn1-6_4.2-3+deb8u3_amd64.deb
85609be9b6a14b1f25355bae064a96f9 23038 devel extra
libtasn1-bin_4.2-3+deb8u3_amd64.deb
97c96b45604466f6123490babddb2a1c 10108 oldlibs extra
libtasn1-3-bin_4.2-3+deb8u3_all.deb
-----BEGIN PGP SIGNATURE-----
iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAlklVApfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh
bHRlaG9sei5kZQAKCRCW/KwNOHtYR81CEAChlNI1t8ONiI4XWUl8sjNbQDHXrm0M
utsBy7C737iHkh/ro6REl0VjkXXm2N+dUbYUFZMXetUBhFF10Y+kPp2wXRi/g8zV
TljaHctp2yOH7gkYE5Ca8GnIkF3pKFnAe80Dpwwks9NUJgqqQ1sphjuA4iMTB04D
amK9UV4NbCW/s3YyLBUiZsHeCAn65UKu0XgQX1Y4lPwAtVJCNHMu/Pyibvygckz+
Y6Ovq0snvQADquKjH0/P37LGi6Z5mPAHz3XD3DIPSC3le6jTRPP6pfg4Ct4gSKRD
vv/6ThE1axsS08U/tqRCA/E2n49x4Ef6jwAAhbo6sY4BROCa4xfvz26xz9Ex7BOo
UdtJase1nz+vfvRzeoWr8oqA8dRnvFiihRQmJi+1S4kd+/3AnPRksrdwLkRBY4Zy
QAU4zwBWkVWJxWfDOcDLaY0rgElniAms7gQeTaAbV5aP3sIHxC44SZln5Cz4YvlS
vc1vOw0gbYelLxXZiIPAgsdGEFrbPZkd83HeU8DjTfROtb1rPN2s2p/2zGqoLxFE
T4/F8AQBEDnI7wUG7JtbZXQL1AWahXgjYrcZw+ghE5VvuRtdUsmTUqYhqzWI4g9k
GXrqh8Ss67c1yQ6J8mDGcfOxpiZSJEEYKu4FGy2a/AJ0Ck39Qb6dx5KKzBKqranJ
e3WEXY12z6yg7A==
=f0vu
-----END PGP SIGNATURE-----
--- End Message ---