Your message dated Wed, 18 Aug 2021 15:03:56 +0000
with message-id <[email protected]>
and subject line Bug#991860: fixed in hivex 1.3.21-1
has caused the Debian Bug report #991860,
regarding hivex: CVE-2021-3622
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
991860: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=991860
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: hivex
Version: 1.3.20-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for hivex.

CVE-2021-3622[0]:
| stack overflow due to recursive call of _get_children()

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2021-3622
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3622
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1975489
[2] 
https://github.com/libguestfs/hivex/commit/771728218dac2fbf6997a7e53225e75a4c6b7255
[3] https://listman.redhat.com/archives/libguestfs/2021-August/msg00002.html

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: hivex
Source-Version: 1.3.21-1
Done: Hilko Bengen <[email protected]>

We believe that the bug you reported is fixed in the latest version of
hivex, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Hilko Bengen <[email protected]> (supplier of updated hivex package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 18 Aug 2021 16:44:03 +0200
Source: hivex
Architecture: source
Version: 1.3.21-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Libvirt Maintainers 
<[email protected]>
Changed-By: Hilko Bengen <[email protected]>
Closes: 991860
Changes:
 hivex (1.3.21-1) unstable; urgency=medium
 .
   * New upstream version 1.3.21
   * Includes fix for CVE-2021-3622 (Closes: #991860)
Checksums-Sha1:
 f24e2d9d05a308e077fe437ae39eb6fd3c35cd4c 2486 hivex_1.3.21-1.dsc
 3d39d9210e92d809fc3d1e692ff27ee7e9fb0b4c 1729723 hivex_1.3.21.orig.tar.gz
 394f993dd29c3d5a444da7755784d53dbfae5e0d 7064 hivex_1.3.21-1.debian.tar.xz
 ac48dbdbd93af7c703890238ea40137440d2eee1 14151 hivex_1.3.21-1_source.buildinfo
Checksums-Sha256:
 5b4ac444bb2ca37d7a710f7a0b55db7505205a6e64c7a98a7dc85b2713b9c7be 2486 
hivex_1.3.21-1.dsc
 9ace3ef4a2ff2ca50a99be068b60fb1fdbc9eab8af53e345e97ce75ba4b63b56 1729723 
hivex_1.3.21.orig.tar.gz
 95890f01f460bb30b9023b12264dc578914673f0807ed37573065383dac5cb1a 7064 
hivex_1.3.21-1.debian.tar.xz
 41e7dda9bee278321bb2bf8b5a070432221a880077fe1353460407390695fb6f 14151 
hivex_1.3.21-1_source.buildinfo
Files:
 c75b890888442b7d4241abf95d5d0fe3 2486 libs optional hivex_1.3.21-1.dsc
 1b9168c6454ba21c469990d90e4b93b5 1729723 libs optional hivex_1.3.21.orig.tar.gz
 5f43d843f6ad02feb04c7ec40f4e1c3f 7064 libs optional 
hivex_1.3.21-1.debian.tar.xz
 a0d8fa53983fd3e4899fd9ac67d7387a 14151 libs optional 
hivex_1.3.21-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEErnMQVUQqHZbPTUx4dbcQY1whOn4FAmEdHRsACgkQdbcQY1wh
On45yBAAqdtQYxxpyUNblMF7ats4EAnw+xZ90fxpUiwAhBscDdY/iOvYoKJjHRzb
byMOPZKtft355eMPsZ55vgo+MgkG83w2bONIXb0QUPv8JQd6Eh9EbgmtTYeSvP8c
2kyLWef0sPF9fQPmwmnXH+ivhodGxtUP6PF4YRUF+jpNxKelbNBf9VQ73MM5CGis
64by3INyYvd0LXBuIU+DpBFEzW8qBs6FRv0L0tge+IDiITCw7rypQAvb/Gs7XzMx
ZxliuX17jXFupnbE/DshYsVagQ//eFd83yJXr6inDHDAKYafTzdQ2TOKeNvhP8IU
p1XqiutVp2+oJG3Heu6GEERzn3KpduUgwc6bRjeqB4jQWgNEXTEOfYc9ufqRwSxr
Qn1+G7I/clfo5mxBmhNxoVsiKMBbEtrM8AYH09U+hu1CW7BnKAHQJlHN405eRzy/
CYxPMdJ70rGUIE4EpM1c0acAJTtHf4/5QbnRn6kgKvMc4PX6Zaj6odjbaJJSXwBE
HXKQHfACkqGo2Nk7UBSGtsO/yLnjwh2oyLBnCh/feWa9/rZ6TN8mJvrlRPDVQ1WH
A1RwYbHt1btd01TYP0kci4VYGW+al04df/cbsyzEFnrMfd72VwMOxHtbSN5/vwyM
xw63ZNANl/BlYr8AtX1A8x68ZQDnc6Ns9lcJz2TIdJlaTNwFUz4=
=6dvE
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to