Your message dated Wed, 04 Sep 2019 20:42:28 +0000
with message-id <[email protected]>
and subject line Bug#939394: fixed in expat 2.2.7-2
has caused the Debian Bug report #939394,
regarding expat: CVE-2019-15903
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
939394: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=939394
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: expat
Version: 2.2.7-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/libexpat/libexpat/issues/317
Hi,
The following vulnerability was published for expat.
CVE-2019-15903[0]:
| In libexpat before 2.2.8, crafted XML input could fool the parser into
| changing from DTD parsing to document parsing too early; a consecutive
| call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then
| resulted in a heap-based buffer over-read.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2019-15903
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15903
[1] https://github.com/libexpat/libexpat/issues/317
[2] https://github.com/libexpat/libexpat/pull/318
[3]
https://github.com/libexpat/libexpat/commit/c20b758c332d9a13afbbb276d30db1d183a85d43
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: expat
Source-Version: 2.2.7-2
We believe that the bug you reported is fixed in the latest version of
expat, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <[email protected]> (supplier of updated expat package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 04 Sep 2019 18:01:00 +0000
Source: expat
Architecture: source
Version: 2.2.7-2
Distribution: unstable
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <[email protected]>
Changed-By: Laszlo Boszormenyi (GCS) <[email protected]>
Closes: 939394
Changes:
expat (2.2.7-2) unstable; urgency=high
.
* Fix CVE-2019-15903: deny internal entities closing the doctype
(closes: #939394).
Checksums-Sha1:
b943ad9fb8dde44a4a78c013e297cfc0242a7dd6 1949 expat_2.2.7-2.dsc
db656b265e6f4fcbdffb7582e7fae5dfa353268c 12852 expat_2.2.7-2.debian.tar.xz
Checksums-Sha256:
823f03964b62c0fd3d380e4001bc3aea35051cbcaf52d09ca19d5889b7bba1f8 1949
expat_2.2.7-2.dsc
9f427b1f23a95ded54f347d67dd527cb130b686bc190428dc95ed67a0100bc0a 12852
expat_2.2.7-2.debian.tar.xz
Files:
f2fd2e4fbe473805b0aedec2e508db02 1949 text optional expat_2.2.7-2.dsc
57ff079e1f82211b2b42dcc8e81349f8 12852 text optional
expat_2.2.7-2.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAl1wGb8ACgkQ3OMQ54ZM
yL9OXA//am0joYFxN/fIWKjATMsNEp/a75qdEhx5ETpLtK+uZjvBDkVCRo0mRdao
62OncqBccPgMVdS0K0Ky/w1QLFRBT3VvfWPuUcafoPVx6Rxxn9AkoO2a+m8+cLly
AdI3wY0jeYWNPIAQPqGfX18gcDF1KTkOpo/vpzKMSXhVDFDJHAQG6JhJMpIM2d2v
FStA+uzoiZkvb+d4s2uKXdC5VHm6ygCoKMoTIA85wGPOi1f/olq3aPzQucyEFARn
LjEuuUm6N6hkz7o3RKxgEXj3bKlG0Ew7pboZOluWgj4DVsTNS9K/KSKrWjOzikwJ
Va04B1wN0Mad2vH/Ai6cYpzzvSbZhoFqFJIVf1Im9jT/qgKI88Zk4+/PP1BAhJ9g
ZWxvclreDFW993j4UChch1RA3eOYcSuZQWjWRYQ3VLTZhwAeRQLTtRo59sC8mi4F
UZf4ualV8ivHpTcQs5shVAXnbV0Dna8dRl8eOWe+KdFb9LVuljj0E4eRsG7LlFEB
VV72Co2r1WEmG5Neu48rtY8Bh1bv7uEGJBLZ7ncxc4RxLl9USgogKLLWXJ/gaJZM
H/rmrQnbiojsHK55yL/aHMvPthdNV0TJmYaJpjs/aDDdijLnlW9kgrAQwrithxIc
vKnOBUhfAF/febubpwZs5JT6EI2rTSOo7b+D8AYZVnNLFA1itXo=
=MmsT
-----END PGP SIGNATURE-----
--- End Message ---