Your message dated Fri, 17 Feb 2023 23:34:12 +0000
with message-id <[email protected]>
and subject line Bug#1031525: fixed in c-ares 1.18.1-2
has caused the Debian Bug report #1031525,
regarding c-ares: CVE-2022-4904
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1031525: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1031525
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: c-ares
Version: 1.18.1-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/c-ares/c-ares/pull/497
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: fixed -1 1.19.0-1
Hi,
The following vulnerability was published for c-ares.
CVE-2022-4904[0]:
| buffer overflow in config_sortlist() due to missing string length check
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2022-4904
https://www.cve.org/CVERecord?id=CVE-2022-4904
[1] https://github.com/c-ares/c-ares/pull/497
[2]
https://github.com/c-ares/c-ares/commit/9903253c347f9e0bffd285ae3829aef251cc852d
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: c-ares
Source-Version: 1.18.1-2
Done: Gregor Jasny <[email protected]>
We believe that the bug you reported is fixed in the latest version of
c-ares, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Gregor Jasny <[email protected]> (supplier of updated c-ares package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Fri, 17 Feb 2023 23:34:35 +0100
Source: c-ares
Architecture: source
Version: 1.18.1-2
Distribution: unstable
Urgency: medium
Maintainer: Gregor Jasny <[email protected]>
Changed-By: Gregor Jasny <[email protected]>
Closes: 1031525
Changes:
c-ares (1.18.1-2) unstable; urgency=medium
.
* Add str len check in config_sortlist to avoid stack overflow
(CVE-2022-4904) (Closes: #1031525)
Checksums-Sha1:
ad5350fcf03f90a428d0b82538d231e0480cdae0 2143 c-ares_1.18.1-2.dsc
665b5db4cc152b9c0f8ebf57773db749b9501d51 9360 c-ares_1.18.1-2.debian.tar.xz
4983f7cf796ff6bc7c08cf2db5c39f9eba4db828 7985 c-ares_1.18.1-2_amd64.buildinfo
Checksums-Sha256:
77374b808ed5807c4c9d5c145e28950bb114340a8e71fff0422a569d22213a8c 2143
c-ares_1.18.1-2.dsc
a6c4397aceb1f20381ce084be577e70562f3a1a5176e96d1fe9ab469a5794c8f 9360
c-ares_1.18.1-2.debian.tar.xz
dfdda45e1bbbdc8046a938d004c1e885737b492ed5614106dd9cb72cdd16f2e4 7985
c-ares_1.18.1-2_amd64.buildinfo
Files:
8f62d8d494ba607d163e8f53791becf4 2143 libs optional c-ares_1.18.1-2.dsc
ccab7e57e3a8694d3e9f7ddd682a27f9 9360 libs optional
c-ares_1.18.1-2.debian.tar.xz
675440b3fc04f37e449c470ba2e5d5d0 7985 libs optional
c-ares_1.18.1-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJKBAEBCAA0FiEEBdAWnCbkFZNBgSnfGZpk+t+1AP8FAmPwA3MWHGdqYXNueUBn
b29nbGVtYWlsLmNvbQAKCRAZmmT637UA//6cEADWYhRQ3a7gcDz8JupTFW0rgiUF
EVt9hJwQxHLwfv7EPwllz1QvEiHYuUB54TNj+u0FMIcaUxGykgamYdZmUaIp4AOr
4srjjKt+TSVwv5YrBLXwxdAD5LYhmzt2lPd+IExe5gD86N9Hv9lWwozSsOeUvTZ/
SbfF2pU2cRZI0llPg6rauMOI4Ra7hRKYrK89e5AXq6jRNPwKUvNdinCsHYwq4BTU
srIYtXz+0UtxRs64zenEdMJUuJLwzGsKJBxDq2FdqfRxd+ZA2Yx5KbeQm8W7aY3t
zzgYaAonO1u/g8lgX7v/orIrJk/koizLwzpkcCFNrEof+TE9nRK9n7r9d/3/8E6U
z2EiF+8ieg1gioO2XC5SqhMp+rr1ow1m2KlJBrs/+Zhd5l1jLBHX5TXJ72nvdIaE
L2lHK6pO6NrCIPgC0fftSAE3xOjVhsqjcIuhN7M/kGIQap3qGfI2tHQBEHkETzfL
LPedldorW8Evgs3yX2Lv44564R7gjpO0b1K6VKQv+RL+rqKEyef2FB/v2lsLcVxX
8cpXIeyh0JPhcpjqV2gyaI5sm5l0QMwbVIL0l9yu74HBpAACLV3YVr6qn5QiNapN
QSVnbvFC097RexaptRw56PmmY1S58FNS9aI71L/SEyqHiU8MRU1VqOPRf2c8eklO
G+u5Rh0ujjnpBCkH3Q==
=+eTz
-----END PGP SIGNATURE-----
--- End Message ---