Your message dated Sat, 19 Nov 2022 13:49:22 +0200
with message-id <Y3jCwmr1ANh36qta@localhost>
and subject line Bogus report against historic libsass version
has caused the Debian Bug report #870184,
regarding libsass: CVE-2017-11605
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
870184: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870184
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libsass
Version: 3.4.3-1
Severity: grave
Tags: security

Hi,

the following vulnerability was published for libass.

CVE-2017-11605[0]:
| There is a heap based buffer over-read in LibSass 3.4.5, related to
| address 0xb4803ea1. A crafted input will lead to a remote denial of
| service attack.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-11605
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11605
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1474019

This so far were only reported to the Red Hat bugzilla, can you check
if it is known to upstream and forward it to the issue tracker for
upstream?

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
https://security-tracker.debian.org/tracker/CVE-2017-11605

Bogus report against historic libsass version


cu
Adrian

--- End Message ---

Reply via email to