Your message dated Sun, 09 Aug 2026 10:48:49 +0000
with message-id <[email protected]>
and subject line Bug#1143970: fixed in libcrypt-openssl-pkcs12-perl 1.98-1
has caused the Debian Bug report #1143970,
regarding libcrypt-openssl-pkcs12-perl: CVE-2026-17510
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1143970: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143970
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libcrypt-openssl-pkcs12-perl
Version: 1.97-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for libcrypt-openssl-pkcs12-perl.

CVE-2026-17510[0]:
| Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL
| pointer dereference in print_attribute via a zero length BMPSTRING
| attribute.  print_attribute() sizes the destination buffer for a
| BMPSTRING attribute from its declared byte length with
| `Renew(*attribute, length, char)`. A zero length attribute makes
| that a zero size reallocation, which Perl implements as a free
| returning NULL, so the buffer pointer becomes NULL, the following
| `strncpy` copies nothing, and the caller dereferences NULL in the
| `strlen()` it passes to `newSVpvn()`. A zero length BMPSTRING is
| even length, so the ASN.1 decoder accepts it and the value reaches
| this code. The UTF8STRING, OCTET STRING and BIT STRING arms size on
| `length + 1` or `length * 4 + 1` and are unaffected.  Any caller
| that passes an untrusted PKCS#12 file to info_as_hash() can crash
| the process. info() prints attribute values directly without sizing
| a buffer and is unaffected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-17510
    https://www.cve.org/CVERecord?id=CVE-2026-17510
[1] https://lists.security.metacpan.org/cve-announce/msg/42524422/

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: libcrypt-openssl-pkcs12-perl
Source-Version: 1.98-1
Done: gregor herrmann <[email protected]>

We believe that the bug you reported is fixed in the latest version of
libcrypt-openssl-pkcs12-perl, which is due to be installed in the Debian FTP 
archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
gregor herrmann <[email protected]> (supplier of updated 
libcrypt-openssl-pkcs12-perl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 09 Aug 2026 12:35:51 +0200
Source: libcrypt-openssl-pkcs12-perl
Architecture: source
Version: 1.98-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <[email protected]>
Changed-By: gregor herrmann <[email protected]>
Closes: 1143970
Changes:
 libcrypt-openssl-pkcs12-perl (1.98-1) unstable; urgency=medium
 .
   * Team upload.
   * Import upstream version 1.98.
     - Security: fix NULL pointer dereference in `print_attribute()`'s
       `V_ASN1_BMPSTRING` branch.
       CVE-2026-17510
     (Closes: #1143970)
   * Upstream TODO file is gone.
Checksums-Sha1:
 d6033ca809fcde48f68d4c01a6e79c1fdcb86416 2736 
libcrypt-openssl-pkcs12-perl_1.98-1.dsc
 a6272a9fec8c4d5e5254249a3a750c6b79e7fade 234890 
libcrypt-openssl-pkcs12-perl_1.98.orig.tar.gz
 7dc05193d7a1b9c887633f2fd66a0cf312cdaefe 3384 
libcrypt-openssl-pkcs12-perl_1.98-1.debian.tar.xz
 cf9aba98a16eb0e7140dcc5d2f8779c60e3c78da 333892 
libcrypt-openssl-pkcs12-perl_1.98-1.git.tar.xz
 fc3ec2d2d77bbf038f4d9f1520c4ba9bad7237a8 17632 
libcrypt-openssl-pkcs12-perl_1.98-1_source.buildinfo
Checksums-Sha256:
 bd0c0fe811ee67020e447c1661707550455c414584103d67fd402ac86825d61c 2736 
libcrypt-openssl-pkcs12-perl_1.98-1.dsc
 b3b93dbbb61f8b39ba355ff6f393d233fabbf963678b137787c19ef1275657cb 234890 
libcrypt-openssl-pkcs12-perl_1.98.orig.tar.gz
 9c6a62fbb421001f4e4f3620ab6c2abc33b8f5275d8728a268a786cecb7db81e 3384 
libcrypt-openssl-pkcs12-perl_1.98-1.debian.tar.xz
 76b12c25dc76cab73c1ceb12c1f2e561d3d2f0e00fa5a769430a5a7e02b384b4 333892 
libcrypt-openssl-pkcs12-perl_1.98-1.git.tar.xz
 92f184271cc4acd2dd4c75fdb21f679497dff9f9e193e2afb08983a1f1231a79 17632 
libcrypt-openssl-pkcs12-perl_1.98-1_source.buildinfo
Files:
 c6179fbbddd4568ded80aa9829e90bc6 2736 perl optional 
libcrypt-openssl-pkcs12-perl_1.98-1.dsc
 3045d7f3b78c6de3e4939f6197b7753a 234890 perl optional 
libcrypt-openssl-pkcs12-perl_1.98.orig.tar.gz
 ee4dd777059ca7b121a419c36201fcb8 3384 perl optional 
libcrypt-openssl-pkcs12-perl_1.98-1.debian.tar.xz
 54fe7b271dc477fa86ab02667b27fa10 333892 perl None 
libcrypt-openssl-pkcs12-perl_1.98-1.git.tar.xz
 fdc2052cd8c5ed4302df1011bf8a0808 17632 perl optional 
libcrypt-openssl-pkcs12-perl_1.98-1_source.buildinfo
Git-Tag-Info: tag=a59f7699fc81b3bfa7d4694a6427ee7e8be7b6a6 
fp=d1e1316e93a760a8104d85fabb3a68018649aa06
Git-Tag-Tagger: gregor herrmann <[email protected]>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmp4WPMACgkQYG0ITkaD
wHkU9hAAsNrl6+ug+NRvvtOTPkwD4v65t1YjVPfGfHg1iwDecZlrWiL7PdElNH8r
Z6lc3QCY+mC1xvRbRzd73+8/ONUwccsYtILvZmnwmt3UpXHm9somFsy6aNZLLi+A
2Be5R3PkDV0LapCOxTAFEgP90RqND7k0oJauEKlvxuYmIRdR8iC7LbYWB/isYkVa
cdcDKAcF8uE/CmsJ+AvfprelSjIeCzc/itSw0aNVWHnoiQ874e2DHhu1FWxFfO95
pEbAQ1O+JkocLVmeSma8vZW4QrJUJ8OeFsnnBl68xDsMB9OfKxpYDQ/86bGJGJGy
LuxH03s3i66kgNCfKgMUyjXrJRnBfBfo19FK0t00M9mlVMPCUoBLiIsECmeNSN2C
cFEhUALbX19BOY42xJWXJzXIElRmUW/70wsmK8YKBrAjPsRbkQmoyh2nbFYGCsaO
OlPpOKzRNc2B5tuzcsbFC1iMEDfriqismbmnCJSezI/NpqImdqf2ifmKHNsPoxyO
H42V6sZnjK2vfAwhtrN3jEVyomStCwuzEUFsRxEktQPv6pot30ivL6mSd+1gmvys
lczZMT/tm3tTsjmMRzA0ztTqk58jg/f66Hr3grOd1UHYHHB6RBQ8pYkT6SvdF3pP
o6GCm+xqVdj2z/F1mO64Um9pqM0A6TGwyczu5V6jdPhO9G13beA=
=+iYw
-----END PGP SIGNATURE-----

Attachment: pgpOzscCOW70L.pgp
Description: PGP signature


--- End Message ---

Reply via email to