Your message dated Sun, 22 Sep 2019 20:33:27 +0000
with message-id <[email protected]>
and subject line Bug#939394: fixed in expat 2.2.6-2+deb10u1
has caused the Debian Bug report #939394,
regarding expat: CVE-2019-15903
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
939394: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=939394
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: expat
Version: 2.2.7-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/libexpat/libexpat/issues/317

Hi,

The following vulnerability was published for expat.

CVE-2019-15903[0]:
| In libexpat before 2.2.8, crafted XML input could fool the parser into
| changing from DTD parsing to document parsing too early; a consecutive
| call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then
| resulted in a heap-based buffer over-read.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-15903
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15903
[1] https://github.com/libexpat/libexpat/issues/317
[2] https://github.com/libexpat/libexpat/pull/318
[3] 
https://github.com/libexpat/libexpat/commit/c20b758c332d9a13afbbb276d30db1d183a85d43

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: expat
Source-Version: 2.2.6-2+deb10u1

We believe that the bug you reported is fixed in the latest version of
expat, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated expat package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 19 Sep 2019 23:13:41 +0200
Source: expat
Architecture: source
Version: 2.2.6-2+deb10u1
Distribution: buster-security
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 939394
Changes:
 expat (2.2.6-2+deb10u1) buster-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * xmlparse.c: Deny internal entities closing the doctype (CVE-2019-15903)
     (Closes: #939394)
Package-Type: udeb
Checksums-Sha1: 
 04ce99daa242fb8577ad2804801caf4103f68597 2136 expat_2.2.6-2+deb10u1.dsc
 87a4efb7434b84581e20b91e6dddbf1e8d32364a 8275473 expat_2.2.6.orig.tar.gz
 5bd516a4e748131a41e343ca027db4cbbbeac3d0 12032 
expat_2.2.6-2+deb10u1.debian.tar.xz
Checksums-Sha256: 
 a32a035c9883b70ddf739eaacaa5c790ec5bf3027ba61eefdbc0cdf634aa4d96 2136 
expat_2.2.6-2+deb10u1.dsc
 574499cba22a599393e28d99ecfa1e7fc85be7d6651d543045244d5b561cb7ff 8275473 
expat_2.2.6.orig.tar.gz
 15e75199a33c4e902788410f37e784c1082906e703c8619c4cfc715a0191e02b 12032 
expat_2.2.6-2+deb10u1.debian.tar.xz
Files: 
 23a3166c3e5eb769790935320673ec1a 2136 text optional expat_2.2.6-2+deb10u1.dsc
 b6ccd2705cf8e732707eb4132a1c4dbc 8275473 text optional expat_2.2.6.orig.tar.gz
 f5d7025d41dc7caf0df7e708b625523f 12032 text optional 
expat_2.2.6-2+deb10u1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl2D8OlfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EyQgQAJQt/5Z8RkuWb7tXb36hEHyVx1ysIXEG
LBkFh5CxYuysLJCw99kADf81tohWjXag+KVCpKvoEB7kpDEc3yi6dikY3ZCA6QaC
AZXi1pHF7es+OK/lydAnAC5QOg+c2VqjVZOA6gul0Yo78C93xy20VonZIecimY4g
j1hTCXSjW7P6ZuN4BGqW0+0ODWtskLo3MKdS9KXQSkPDnA52hOtiFGeBKh6Sz30M
0JAtryzVF7oerVw3aqQOAXoU2mV99i59aHzjFf1PpDvE5we6XXGqlE4ts+l1JSKA
P4mJG9SgzeVSPsmwAd1xRi6EjwYD2CyFgwl5cZqkXVQS85nBjLIpa/HG+VGeyikC
x1VHx6I3ODt46cm22CK36VCL0DHn67E5b5K3o7UXkno52J58dlQOnJh1rUHrvLiX
qYEsxUvWcGgl/wRIRskDqNc3GScieUVMS7sf1am39v62i/J+phpU7PcujSkCPzAe
YMs425/mvsu+u46+Mr+uFK486izt9+w6yCsuRDhX/ur+JynG8ypQiktbBBBCkT4+
OkSRF9eDYXKn5L87vNqX9RtR6L/zUypAZkus7GPo50UKwiYg7L2h0UlIW6zJ6dLB
EV2iVZH7It/dxAUEFZrNMCpDw8VbNXDurREdbCjxpHSo4Rx4/IyuNgDzWk0g6FzG
iayQNb/ghRxZ
=Oq8+
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to