Your message dated Tue, 02 Jan 2018 10:06:10 +0000
with message-id <[email protected]>
and subject line Bug#862450: fixed in libxml2 2.9.4+dfsg1-6.1
has caused the Debian Bug report #862450,
regarding libxml2: CVE-2017-8872: Out-of-bounds read in htmlParseTryOrFinish
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
862450: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862450
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libxml2
Version: 2.9.4+dfsg1-2.2
Severity: important
Tags: security upstream
Forwarded: https://bugzilla.gnome.org/show_bug.cgi?id=775200
Hi,
the following vulnerability was published for libxml2.
CVE-2017-8872[0]:
| The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4
| allows attackers to cause a denial of service (buffer over-read) or
| information disclosure.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2017-8872
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8872
[1] https://bugzilla.gnome.org/show_bug.cgi?id=775200
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: libxml2
Source-Version: 2.9.4+dfsg1-6.1
We believe that the bug you reported is fixed in the latest version of
libxml2, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated libxml2 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 02 Jan 2018 08:59:03 +0100
Source: libxml2
Binary: libxml2 libxml2-utils libxml2-dev libxml2-dbg libxml2-doc
python-libxml2 python-libxml2-dbg python3-libxml2 python3-libxml2-dbg
Architecture: source
Version: 2.9.4+dfsg1-6.1
Distribution: unstable
Urgency: medium
Maintainer: Debian XML/SGML Group <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 862450
Description:
libxml2 - GNOME XML library
libxml2-dbg - Debugging symbols for the GNOME XML library
libxml2-dev - Development files for the GNOME XML library
libxml2-doc - Documentation for the GNOME XML library
libxml2-utils - XML utilities
python-libxml2 - Python bindings for the GNOME XML library
python-libxml2-dbg - Python bindings for the GNOME XML library (debug
extension)
python3-libxml2 - Python3 bindings for the GNOME XML library
python3-libxml2-dbg - Python3 bindings for the GNOME XML library (debug
extension)
Changes:
libxml2 (2.9.4+dfsg1-6.1) unstable; urgency=medium
.
* Non-maintainer upload.
* Out-of-bounds read in htmlParseTryOrFinish (CVE-2017-8872)
(Closes: #862450)
Checksums-Sha1:
460ab48dfab257d37c6fe7c0f46b7eab14aa857b 3139 libxml2_2.9.4+dfsg1-6.1.dsc
edda624b958bcd83bdb867c3ee4078e83fcd945f 36064
libxml2_2.9.4+dfsg1-6.1.debian.tar.xz
Checksums-Sha256:
80781c59c3fe24ed81efe58d2512c20a3cdbc9c862bee87cbd17f8241c2efab2 3139
libxml2_2.9.4+dfsg1-6.1.dsc
bd4ee9a9e0c5c3c78902e4c12482fdbbcd4da0b0d1c3c41680bb8b5304116ca2 36064
libxml2_2.9.4+dfsg1-6.1.debian.tar.xz
Files:
682ad195365b7c16319dd7df2c3783da 3139 libs optional libxml2_2.9.4+dfsg1-6.1.dsc
5b473576146728ef155f675a55e51427 36064 libs optional
libxml2_2.9.4+dfsg1-6.1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlpLQqRfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89E/bQQAI3ese573EHH2mIjPixT5WSh3zyLwddd
SptHol9LNla9hGOGx5YAFWPVnnUX6J1rIuJWHEPs+RqQGbvxiMNdUERRQN8vMg6n
lj6QHeWwyl04LIEFS68LHaXHn0zTuQQJXUQ9UimdSJIxwJlncAihL7OsXR6RMGGS
3V0OLUq2BFs0mnU7Eok3spWDJDud9mXPrfzJ9Hfrahi6n70Unhic8tCmHCFbJ/Jw
ccTCFiZA2l5eUMgipTsFfNsxFJAjxQUYYhnISNa3Wd3vCamVBQjyJwS4rClBHBWa
N2/rLkSoTIyQ2Soaw6Mxo92VG0YsQElqAxRSRSh8zGWXDAnueAm2/l7wa8igYZWx
jYnTPx146vPxPBiowTVyxrprs/vkJ/cbJEz/Bv69IjzB4zYpyED4qeHT7XAkjUrj
t/gLqtXjRCHRCEUsN6IIcj15yQRncZKli/5Ukvp25N+7L+ZIDeO3+pD/hQk4pCN1
WMz7ElSBe596ni2tuvEU/atf2k/ihPBK/9awHhZ2LPPkfo5cBGuK2VKwxTAMaryM
3Ol49oRsUSBXXBTFNiLl7nYuiavQzFMKy2VYQv0RGkQg4QNM7x3vnTIpZztVJXaj
sHkCpCr3B4aBEy5jAXP8efQz8hTkW2sYvUOVk1NMCfQVRZuddnScHbHXSX0Me+nA
0bjIpVlcQ5wp
=eosY
-----END PGP SIGNATURE-----
--- End Message ---