Your message dated Mon, 30 Sep 2019 21:32:43 +0000
with message-id <[email protected]>
and subject line Bug#931246: fixed in flightcrew 0.7.2+dfsg-9+deb9u1
has caused the Debian Bug report #931246,
regarding flightcrew: CVE-2019-13032
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
931246: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931246
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: flightcrew
Version: 0.7.2+dfsg-13
Severity: important
Tags: security upstream
Forwarded: https://github.com/Sigil-Ebook/flightcrew/issues/53
Control: found -1 0.7.2+dfsg-9

Hi,

The following vulnerability was published for flightcrew.

CVE-2019-13032[0]:
| An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL
| pointer dereference occurs in GetRelativePathToNcx() or
| GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to
| xc::XMLUri::isValidURI(). This affects third-party software (not
| Sigil) that uses FlightCrew as a library.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-13032
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13032
[1] https://github.com/Sigil-Ebook/flightcrew/issues/53

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: flightcrew
Source-Version: 0.7.2+dfsg-9+deb9u1

We believe that the bug you reported is fixed in the latest version of
flightcrew, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Francois Mazen <[email protected]> (supplier of updated flightcrew package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 10 Sep 2019 15:34:26 +0200
Source: flightcrew
Binary: flightcrew libflightcrew0v5 libflightcrew-dev
Architecture: source
Version: 0.7.2+dfsg-9+deb9u1
Distribution: stretch
Urgency: medium
Maintainer: Mattia Rizzolo <[email protected]>
Changed-By: Francois Mazen <[email protected]>
Description:
 flightcrew - C++ epub validator
 libflightcrew-dev - C++ library development filesfor epub validation
 libflightcrew0v5 - C++ library for epub validation
Closes: 931246
Changes:
 flightcrew (0.7.2+dfsg-9+deb9u1) stretch; urgency=medium
 .
   * Fix CVE-2019-13241 for stretch release.
   * Fix CVE-2019-13032 for stretch release.  Closes: #931246
Checksums-Sha1:
 9d07b62696cb0ee6d37de6155987365986c4edc7 2235 
flightcrew_0.7.2+dfsg-9+deb9u1.dsc
 39fb1a5ceecf98e4c3282d17bdf1864e31ec04c0 13452 
flightcrew_0.7.2+dfsg-9+deb9u1.debian.tar.xz
 90bed37423f87387f232dc107f6d16472edbde4b 15441 
flightcrew_0.7.2+dfsg-9+deb9u1_amd64.buildinfo
Checksums-Sha256:
 f6d3277fcecc60ca561924b626044833b003b9350c7904225b43f11cf97d3284 2235 
flightcrew_0.7.2+dfsg-9+deb9u1.dsc
 44d1e368ea216ddd695f2506e6991b78192fb1ef632cb49537622584ce686842 13452 
flightcrew_0.7.2+dfsg-9+deb9u1.debian.tar.xz
 347fa2f4ce43857c556bd8f80afd02ffbf94e5e7a609d4cadab1b3de1b99c3e1 15441 
flightcrew_0.7.2+dfsg-9+deb9u1_amd64.buildinfo
Files:
 f63064e84d141609e16e94483f139686 2235 text extra 
flightcrew_0.7.2+dfsg-9+deb9u1.dsc
 c4c7c9fe844bccafa2b988c19ab45d20 13452 text extra 
flightcrew_0.7.2+dfsg-9+deb9u1.debian.tar.xz
 2784ca7fa3e56efeedf895c77f286cb6 15441 text extra 
flightcrew_0.7.2+dfsg-9+deb9u1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEi3hoeGwz5cZMTQpICBa54Yx2K60FAl2HnVoACgkQCBa54Yx2
K633uBAAgcc/AaAdf6fPtPBELKcPGB+sIxq21qtj/At7N9rDNVMi97pmvgf96e4v
M37qjfZVJiXONbB7lPACkpugCvLltg2Pic/DyQExD0qfF6nFtsDuG8xQslLFRse3
fsRNj6GUJf1VQJFR3KGi3IiPEhDPIiffEPZr7qcwDVvdZGLP975mTsWy72SGGz7W
KCkZ8O1vN0viJebu5a1c49MzMD8dBVfsbKLHIRk822wOwA21NxVCk4mGFYK9qBo+
fpdHb0pLkKgxvWRmHC1irS44Ta4pZE8IQDxhpcbN5eor6x+0KP7Vkj47ck1/wdE/
rjQDRFmGvSq1XACV1gboarLgKi78aUcLzIN+BigggztL9QSzlN7pLGIu/ubTwWSO
TlPcSmQtIPx923F/MMX3Xx+lNV07u4xw2jIiIp3mwjPNdZU1wx4sndA/589+1Sdf
rqRn8ZTwyGrGX/hxIx6Spu7xCPfeyM/ZNKCou9/bB3roE4qggnaEUW1tokx9dwmO
g2fNp0pLNGHqJYYUoOe69KJG1kOaWZGI35AzRAYH9lU+z1bFQXT3fjHuThChK3c2
lRKFqdYQZDe6U2g0zEnDRqzqEkPo00Bu+nJO8k4zv1nIyGRoJUwdlTp0ykV57ItV
b15ay8vp2jKovWS7GAShy4i5O4KrTB6tTIhGxeV1wSh4omytzC4=
=Uetz
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to