Your message dated Tue, 04 Aug 2026 15:51:38 +0000
with message-id <[email protected]>
and subject line Bug#1123961: fixed in netcdf-parallel 1:4.10.1-1
has caused the Debian Bug report #1123961,
regarding netcdf-parallel: CVE-2025-14932 CVE-2025-14933 CVE-2025-14934 
CVE-2025-14935 CVE-2025-14936
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1123961: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1123961
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: netcdf
Version: 1:4.9.3-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: clone -1 -2
Control: reassign -2 src:netcdf-parallel 1:4.9.3-2 
Control: retitle -2 netcdf-parallel: CVE-2025-14932 CVE-2025-14933 
CVE-2025-14934 CVE-2025-14935 CVE-2025-14936

Hi,

The following vulnerabilities were published for netcdf.

The set of reports oginate from ZDI reports and it not very clear if
the issues will get fixed and have not found public upstream
references where they track those. So this might be a first step at
all to track these properly as well for us downstream. For now the CVE
entries just refernce to the published ZDI reports.

CVE-2025-14932[0]:
| NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow Remote
| Code Execution Vulnerability. This vulnerability allows remote
| attackers to execute arbitrary code on affected installations of NSF
| Unidata NetCDF-C. User interaction is required to exploit this
| vulnerability in that the target must visit a malicious page or open
| a malicious file.  The specific flaw exists within the parsing of
| time units. The issue results from the lack of proper validation of
| the length of user-supplied data prior to copying it to a fixed-
| length stack-based buffer. An attacker can leverage this
| vulnerability to execute code in the context of the current user.
| Was ZDI-CAN-27273.


CVE-2025-14933[1]:
| NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code
| Execution Vulnerability. This vulnerability allows remote attackers
| to execute arbitrary code on affected installations of NSF Unidata
| NetCDF-C. User interaction is required to exploit this vulnerability
| in that the target must visit a malicious page or open a malicious
| file.  The specific flaw exists within the parsing of NC variables.
| The issue results from the lack of proper validation of user-
| supplied data, which can result in an integer overflow before
| allocating a buffer. An attacker can leverage this vulnerability to
| execute code in the context of the current user. Was ZDI-CAN-27266.


CVE-2025-14934[2]:
| NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow
| Remote Code Execution Vulnerability. This vulnerability allows
| remote attackers to execute arbitrary code on affected installations
| of NSF Unidata NetCDF-C. User interaction is required to exploit
| this vulnerability in that the target must visit a malicious page or
| open a malicious file.  The specific flaw exists within the parsing
| of variable names. The issue results from the lack of proper
| validation of the length of user-supplied data prior to copying it
| to a fixed-length stack-based buffer. An attacker can leverage this
| vulnerability to execute code in the context of the current user.
| Was ZDI-CAN-27267.


CVE-2025-14935[3]:
| NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow
| Remote Code Execution Vulnerability. This vulnerability allows
| remote attackers to execute arbitrary code on affected installations
| of NSF Unidata NetCDF-C. User interaction is required to exploit
| this vulnerability in that the target must visit a malicious page or
| open a malicious file.  The specific flaw exists within the parsing
| of dimension names. The issue results from the lack of proper
| validation of the length of user-supplied data prior to copying it
| to a fixed-length heap-based buffer. An attacker can leverage this
| vulnerability to execute code in the context of the current user.
| Was ZDI-CAN-27168.


CVE-2025-14936[4]:
| NSF Unidata NetCDF-C Attribute Name Stack-based Buffer Overflow
| Remote Code Execution Vulnerability. This vulnerability allows
| remote attackers to execute arbitrary code on affected installations
| of NSF Unidata NetCDF-C. User interaction is required to exploit
| this vulnerability in that the target must visit a malicious page or
| open a malicious file.  The specific flaw exists within the parsing
| of attribute names. The issue results from the lack of proper
| validation of the length of user-supplied data prior to copying it
| to a fixed-length stack-based buffer. An attacker can leverage this
| vulnerability to execute code in the context of the current user.
| Was ZDI-CAN-27269.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-14932
    https://www.cve.org/CVERecord?id=CVE-2025-14932
[1] https://security-tracker.debian.org/tracker/CVE-2025-14933
    https://www.cve.org/CVERecord?id=CVE-2025-14933
[2] https://security-tracker.debian.org/tracker/CVE-2025-14934
    https://www.cve.org/CVERecord?id=CVE-2025-14934
[3] https://security-tracker.debian.org/tracker/CVE-2025-14935
    https://www.cve.org/CVERecord?id=CVE-2025-14935
[4] https://security-tracker.debian.org/tracker/CVE-2025-14936
    https://www.cve.org/CVERecord?id=CVE-2025-14936

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: netcdf-parallel
Source-Version: 1:4.10.1-1
Done: Alastair McKinstry <[email protected]>

We believe that the bug you reported is fixed in the latest version of
netcdf-parallel, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Alastair McKinstry <[email protected]> (supplier of updated netcdf-parallel 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 02 Aug 2026 13:52:47 +0100
Source: netcdf-parallel
Architecture: source
Version: 1:4.10.1-1
Distribution: unstable
Urgency: medium
Maintainer: Alastair McKinstry <[email protected]>
Changed-By: Alastair McKinstry <[email protected]>
Closes: 977545 1003943 1036168 1123961
Changes:
 netcdf-parallel (1:4.10.1-1) unstable; urgency=medium
 .
   * New upstream release. Closes: #1123961
     Refresh patches
     Fixes: CVE-2025-14932, CVE-2025-14933, CVE-2025-14934,
            CVE-2025-14935, CVE-2025-14936
   * Update d/copyright
   * Update symbols files
   * Fix include path in pkgconfig files. Closes: #1036168, #977545, #1003943
   * d/rules: Ensure repeat builds works
Checksums-Sha1:
 0f99c7cce014952f439846ea92914c7592479530 2637 netcdf-parallel_4.10.1-1.dsc
 fb5b487f66ae12d81979c6fb558ef6deb7034633 25714348 
netcdf-parallel_4.10.1.orig.tar.gz
 f5915a5989ee9fee42ad22db6ab9e671539bfefd 54756 
netcdf-parallel_4.10.1-1.debian.tar.xz
 d85c8fcf867751a66827c54519e4441b786fb9f9 13947 
netcdf-parallel_4.10.1-1_arm64.buildinfo
Checksums-Sha256:
 5dc8e3ad3808261dba7a76e2319f5867e893c596d4074e33da559964c66f951e 2637 
netcdf-parallel_4.10.1-1.dsc
 33c27231c478c3b35da7c7758fbdd02da1fe407abcb16ddfe195f69d164f930d 25714348 
netcdf-parallel_4.10.1.orig.tar.gz
 a34745b6eb5675b96481ce44c37180c04b672ebe35d66c405e4fb332de0003a9 54756 
netcdf-parallel_4.10.1-1.debian.tar.xz
 c0443a580c291d5db09121fea8595b7e41cadf9d6cd305dbfd9c612dcffe17d3 13947 
netcdf-parallel_4.10.1-1_arm64.buildinfo
Files:
 bcfca3a1febce62b2fb9cc26899fd0a4 2637 science optional 
netcdf-parallel_4.10.1-1.dsc
 9d56028b4032c67cd63b3cc5ae3e6b5f 25714348 science optional 
netcdf-parallel_4.10.1.orig.tar.gz
 ebe18278fd69c93a0d8b988a6ede4507 54756 science optional 
netcdf-parallel_4.10.1-1.debian.tar.xz
 a5566a083551f839e520ffb084e03118 13947 science optional 
netcdf-parallel_4.10.1-1_arm64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEgjg86RZbNHx4cIGiy+a7Tl2a06UFAmpyA7oACgkQy+a7Tl2a
06VS2w/+IMxRnAun0ccjtmKIba7AaieiTCb648gcB6SyULpBuAhyLYVh29P7+ife
eBTs8JyXV2gMAPV5370uIKxKt4nu/Bx73SaiFlUc6zZVgLshbRsMdt5PWkuf/oN4
h+gq+I/UGVv1yt6Clm7XqwP6Pgy2fRFTw7A0cG7aDH/Dk1MiSgyw4/lhB5KzUcki
FkwM2lHQxPw/uAbkTy7CsuW0iM1e6Z/61gq5StxLcMqRyeK58+C3c/bqEpy4B+IK
hmUOAAC8xPY0GSEAif/vXxmvBYpiTs5GwdpGvLtmAxQJ1JA0EoT6Gljwfxo6z/6q
gudGRiDF3KdJ+c1tFPxonJFfCzhVvgH6RHszoPwohhBucUgJOM/3p9WXMj07TRAe
6itzgTTIlrFHQb982JDL8XIN2+G09XD5pu2ZjqyUzXv1kS0IHd56756O2kLKjYHa
cBLkELUlnV9RQtHOSpB3R62R7gxiLbZDa/uEvwx3f/eOgrzcyrECe5tglg/rkVDv
jCv2p5tltZqOsYCUvBmaDfl1uffpUziM5gUuek7dxXn1G9FPgt4kqA+1S34Qkd8S
LVMO2oxjtTl1D1SMLvCpNgUBa0JG23LfunWNKrXp8gAYRd3T7F9ZgOw8PJ+bWJbl
wsnsGPwKbjFpoG2XCBwiupNzLrGW0UamvX4ZcYfRZtdVEv1tItU=
=/RUZ
-----END PGP SIGNATURE-----

Attachment: pgpk62pwaW2dN.pgp
Description: PGP signature


--- End Message ---

Reply via email to