Your message dated Thu, 16 Jul 2026 21:18:59 +0000
with message-id <[email protected]>
and subject line Bug#1142227: fixed in libxml-bare-perl 0.53-5
has caused the Debian Bug report #1142227,
regarding libxml-bare-perl: CVE-2026-13401 CVE-2026-57074
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142227: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142227
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libxml-bare-perl
Version: 0.53-4
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 0.53-2
Control: found -1 0.53-1

Hi,

The following vulnerabilities were published for libxml-bare-perl.

CVE-2026-13401[0]:
| XML::Bare versions through 0.53 for Perl will hang in an infinite
| loop when parsing malformed attributes.  The parserc_parse function
| never advances the attribute-parse state cursor on certain malformed
| attribute forms, looping forever.  Nameless attributes such as "<a
| ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this
| condition.


CVE-2026-57074[1]:
| XML::Bare versions through 0.53 for Perl have an unbounded character
| lookahead.  The parserc_parse function attempts to check for
| multicharacter strings such as "<![CDATA" or element terminators
| such as ">" without checking that the offsets are within the buffer.
| Truncated strings such as "<a/" can trigger an out-of-bounds read.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-13401
    https://www.cve.org/CVERecord?id=CVE-2026-13401
[1] https://security-tracker.debian.org/tracker/CVE-2026-57074
    https://www.cve.org/CVERecord?id=CVE-2026-57074

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: libxml-bare-perl
Source-Version: 0.53-5
Done: gregor herrmann <[email protected]>

We believe that the bug you reported is fixed in the latest version of
libxml-bare-perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
gregor herrmann <[email protected]> (supplier of updated libxml-bare-perl 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 16 Jul 2026 22:57:26 +0200
Source: libxml-bare-perl
Architecture: source
Version: 0.53-5
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <[email protected]>
Changed-By: gregor herrmann <[email protected]>
Closes: 1142227
Changes:
 libxml-bare-perl (0.53-5) unstable; urgency=medium
 .
   * Add patches to fix CVE-2026-13401 and CVE-2026-57074.
     (Closes: #1142227)
   * Update years of packaging copyright.
   * Declare compliance with Debian Policy 4.7.4.
   * Remove «Rules-Requires-Root: no», which is the current default.
   * Remove «Priority: optional», which is the current default.
Checksums-Sha1:
 b2f11a22d3222be9c7f71cbe5139fad5f7bfbfa3 2361 libxml-bare-perl_0.53-5.dsc
 b4c21832ad5686570ab43543ef4162b09f859f29 6788 
libxml-bare-perl_0.53-5.debian.tar.xz
Checksums-Sha256:
 270f08ed74dd2dcade139f715ca7faf8c19aaf665e2cf1cdf5d4b72e85f1503d 2361 
libxml-bare-perl_0.53-5.dsc
 6ffa29a6c79266c3de980595c566b10050b7c38a4b925b1cac0ef3b967524d43 6788 
libxml-bare-perl_0.53-5.debian.tar.xz
Files:
 27e9ef45e1596fb186bee26061e58cec 2361 perl optional libxml-bare-perl_0.53-5.dsc
 ac5487482f6b3505ac3bd3cd19bee8c2 6788 perl optional 
libxml-bare-perl_0.53-5.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmpZRwFfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qgacew/+PfTDCqMcYcu3ofHVI3AlPpv4PcrQDGWZdf3g+bJZVyq4sLK/xLGluk4g
CVzq02wLhxbGO4Y7VeUpgW2+zdX7lIITxIvxx8EeUPfE8Vnw7C9rXqae4L8cGmvr
+4/Npwcvoq+JQIDdDEFcJR9XegIrq1kR3SL5ToLt8fcV7XrT226KlSnmAB6Uozr+
/w2R/juyysf1VxtLmKO4lfyDpWdevl4U2DVuDJ9sb9ZTflKVydx4a3cJurxs+LCk
rGx8iDbsVFadFV5wbF4OZcrLFI6Q7qqWxXQACbAiDtRbVoXWQnANlo6vxutWyFEW
3EEqUctly+tpN2Yb36Slf4Z7STkhexkX+1XHRK50UXNVSgGnYFIn2x8niV1OOcVJ
m8G5rQjED7VzMUCreDUQS3iryLxeLZZDCazxpbZGEZBXxDCz81t9EKJWe6yU2ghq
QZjuScftEdmFBq3uKUXxfD3IIlN0wCQdRkH0b5xTMUisGgKOrQFHFcTXfsYZtlZc
m/uf4h3/DIRdeKw8JvvCkklTL0DTvN3kY/HtaOlVAMf+mnfF2jNjv7OYYHNyF8Tc
6ql2b1Cfu5hKgVkvi9Aj1lSdPscuVKSZ6Evt3K7IzeVgYw7XSlL7ERmMiRGMqtxF
Rrx3Uh7lE/Nu9dJ1kDBVowcE7FAwY0Nb8cJHln2jyAFxlJNosTQ=
=Cmw+
-----END PGP SIGNATURE-----

Attachment: pgpPL1jLS71EU.pgp
Description: PGP signature


--- End Message ---

Reply via email to