Your message dated Fri, 02 Aug 2019 17:37:03 +0000
with message-id <[email protected]>
and subject line Bug#932145: fixed in jhead 1:3.03-2
has caused the Debian Bug report #932145,
regarding jhead: CVE-2019-1010301
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
932145: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=932145
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: jhead
Version: 1:3.03-1
Severity: important
Tags: security upstream

Hi,

The following vulnerability was published for jhead.

CVE-2019-1010301[0]:
| jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of
| service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The
| attack vector is: Open a specially crafted JPEG file.

The issue has been reported to a downstream bugzilla at [1], could you
try your luck contacting upstream? The issue is reproducible with the
provided POC.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-1010301
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010301
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1679952

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: jhead
Source-Version: 1:3.03-2

We believe that the bug you reported is fixed in the latest version of
jhead, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ludovic Rousseau <[email protected]> (supplier of updated jhead package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Fri, 02 Aug 2019 18:24:02 +0200
Source: jhead
Binary: jhead jhead-dbgsym
Architecture: source amd64
Version: 1:3.03-2
Distribution: unstable
Urgency: medium
Maintainer: Ludovic Rousseau <[email protected]>
Changed-By: Ludovic Rousseau <[email protected]>
Description:
 jhead      - manipulate the non-image part of Exif compliant JPEG files
Closes: 932145 932146
Changes:
 jhead (1:3.03-2) unstable; urgency=medium
 .
   * d/p/36_CVE-2019-1010301 Fix "CVE-2019-1010301" (Closes: #932145)
   * d/p/37_CVE-2019-1010302 Fix "CVE-2019-1010302" (Closes: #932146)
Checksums-Sha1:
 8eef83410a587d307cef197c6d8bb1f92a9ce91b 1815 jhead_3.03-2.dsc
 6cb4cf77576d27568155991fc363fcff99878465 8792 jhead_3.03-2.debian.tar.xz
 2c1b5b6bcd6fc7d06ce69068e5dc2b03482b428b 78232 jhead-dbgsym_3.03-2_amd64.deb
 2e335f2cee3512b82098fcbfbe898d75dc6280d2 5761 jhead_3.03-2_amd64.buildinfo
 92db11f09be9ed1389a3192a5d29d13388e4e748 50608 jhead_3.03-2_amd64.deb
Checksums-Sha256:
 053f3b7d948c4f468d50a61f43aba39f8f8947343b4c1a0590e4f2ad6996df57 1815 
jhead_3.03-2.dsc
 33370ed0a44d9682a5efd0071ef30a1219d2ab179566f724e66c5a0d03a2137d 8792 
jhead_3.03-2.debian.tar.xz
 456d95823b507b472642e04f9a4b9bbf7fbef98ceb804c7de1fee3b633b564f7 78232 
jhead-dbgsym_3.03-2_amd64.deb
 69d5624d659068592a743473c3b827e97438b50fa05ec64347244d6c88a0cfcb 5761 
jhead_3.03-2_amd64.buildinfo
 86eb85495b788ea481a7b4f77ba88e6bd73527b5c71ba56d514206eacf6e5763 50608 
jhead_3.03-2_amd64.deb
Files:
 427f65cf8282e4911c6a176d8a9f3689 1815 graphics optional jhead_3.03-2.dsc
 67f5f5e1928182d3b368cb0f1f9bd6cd 8792 graphics optional 
jhead_3.03-2.debian.tar.xz
 9fd45559cf945ff2e4bde31c3d07b799 78232 debug optional 
jhead-dbgsym_3.03-2_amd64.deb
 c9308c910f8c70fa25d27675bd84a9dc 5761 graphics optional 
jhead_3.03-2_amd64.buildinfo
 4be441620c79ff3c701e173f8fe3ee63 50608 graphics optional jhead_3.03-2_amd64.deb

-----BEGIN PGP SIGNATURE-----

iQJIBAEBCAAyFiEE9eEbn/6REUb0HZU9eKG03+j5xX4FAl1EbUcUHHJvdXNzZWF1
QGRlYmlhbi5vcmcACgkQeKG03+j5xX7Wew/7B1AY7f4272XulTM/2XCcuQoHQ8YK
9qnvBbMmDoxpXISTYFM7L+yceUshhKVn+tO3gTThWVW/4om0R/n3h5mD2ic0stX0
BPZJG+kpHvaEwK+wpSRc26baLMVzu5tgvA9E15Re+OP/uEylFiX8CIbe4G+kIMWk
WalKlCRuZJ0v7RtPCQQ1m45zP6FGW2gXqSNC5jyhshkAsUT6svHZWIYe4SbwFeWx
BdbY4c2Dh86rzyo3fLgXVeBS1ZN87EERz4P52pdKPLEANyBdYlLMHe71bsmHqE0t
kI1DdTCNC4iuz7prE+DCmVOEeC9Ex0DK+8X0QV55HVmYKJeaXlF4RF/dwgiNAK4l
4bmycq3YMM9pgS2E3nniGOazmNCJvsnlvcA/uI8gu81Uj4Npcw4Otw6i4kz6PtmQ
L93w1s7LiXV8o/IPAYmF88AuTv9OWFyq3yAb2XKAActtY2eFVDMeOBt/1yDF3XNN
fbcn+jLJ+AWVszT3n+/0zb/v3/6Ce7ocb1+zS7i1s9KkTgV0z64sndD9Moew7wi0
cGDepr5vqhwtwrsmiui3QuQrP3+GfguNJQIzgPrnQSqlS8N91CQ5Ob/P/O4FQ9SY
sVAG+hC9JS0ny1w/0otknzNLNwQbeBtoSeJbJHR5FZ20iC2PkVI7XjL74RiEXYoo
pt6jWuZQlZgvk6A=
=aSoA
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to