Your message dated Sat, 28 Sep 2019 18:36:41 +0000
with message-id <[email protected]>
and subject line Bug#939394: fixed in expat 2.2.0-2+deb9u3
has caused the Debian Bug report #939394,
regarding expat: CVE-2019-15903
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
939394: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=939394
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: expat
Version: 2.2.7-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/libexpat/libexpat/issues/317

Hi,

The following vulnerability was published for expat.

CVE-2019-15903[0]:
| In libexpat before 2.2.8, crafted XML input could fool the parser into
| changing from DTD parsing to document parsing too early; a consecutive
| call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then
| resulted in a heap-based buffer over-read.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-15903
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15903
[1] https://github.com/libexpat/libexpat/issues/317
[2] https://github.com/libexpat/libexpat/pull/318
[3] 
https://github.com/libexpat/libexpat/commit/c20b758c332d9a13afbbb276d30db1d183a85d43

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: expat
Source-Version: 2.2.0-2+deb9u3

We believe that the bug you reported is fixed in the latest version of
expat, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated expat package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 19 Sep 2019 23:43:05 +0200
Source: expat
Architecture: source
Version: 2.2.0-2+deb9u3
Distribution: stretch-security
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 939394
Changes:
 expat (2.2.0-2+deb9u3) stretch-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * xmlparse.c: Deny internal entities closing the doctype (CVE-2019-15903)
     (Closes: #939394)
Package-Type: udeb
Checksums-Sha1: 
 5720ef8b4dfa85543c2a94f63e387f303300d013 2450 expat_2.2.0-2+deb9u3.dsc
 54558515273d70b26a4daf5136bfa84902ec6c80 12608 
expat_2.2.0-2+deb9u3.debian.tar.xz
Checksums-Sha256: 
 11f83d0c9912cf287b53b72636dc8049656477d05bffd3ecf56c29709bfec33f 2450 
expat_2.2.0-2+deb9u3.dsc
 68800c47feebefea7318e767d6837b7c84ad875ab53d188e951d4859eddba241 12608 
expat_2.2.0-2+deb9u3.debian.tar.xz
Files: 
 27927dc07733a5b32dae3910ee6d2703 2450 text optional expat_2.2.0-2+deb9u3.dsc
 70693561b9a8a0a085ac9cf989eb5e25 12608 text optional 
expat_2.2.0-2+deb9u3.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl2EroJfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89ELTcP/RJoBGp58BKvwMES7rFVRpFRtSftq3DX
ayCSGK0JRGHOyPaaMfvPc+MDSB01ucP3ZOYagzNiyICfRs0FEXpcYuQvgWKCGNaz
Znn2lklqJBe/j8zowJgq6MRjFGKb06/Lv0RFv/Uket/xk9paXMMDb3wMrXU2UwFJ
SdHTzZAgyzBdYv7bEHt8QZcvmt42bN9WB8KdCpMUytEuxF9xoeo9xqRrCfOd2aXw
KSzSlNLBdpv46MuXE0U+u5Osr6dOqw6gcbBkE817kapm+MoNtdU9K5IgZlJ7B1Ve
fuUMWdBhrz0zmokDQHGSdI2UPLpVEM9+Or8B9qv7KOh+y0XPhmjczvEgTwV1CQ5a
IJ+HiOXUYvinkGKQIdTwI01u32pZMo9RKAEfL6/UMamaXp6mP4teFWcIfTvKecRM
v7NOCiDwT5FurSTA+ep0H2m8br7rvX6fnSZGyvpi1sNRjJ6IhVaT36gEaJGUZs/b
84RQvJRzgL04bp58B7cTGdssJ+VUn1cifw3+1JVv8DbUJ7CMwNhIc7qNyc039wCY
0aCMAmMYvxFbO/hA6o3yOfQ94dzTvdX+baqn/6s2UEbRkOnAwVdQaGy9G8zC0W4h
XvTwmv18qjSroow7KGDzoaCxcN7beCIvo5PPROvX3qyQi5zQTafmdZfZQbyTOQsI
3kpB3xkDq5cI
=Y0Jo
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to