Your message dated Wed, 26 Aug 2026 13:19:09 +0000
with message-id <[email protected]>
and subject line Bug#1136010: fixed in binwalk 2.4.3+dfsg1-3
has caused the Debian Bug report #1136010,
regarding binwalk: CVE-2026-7179
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1136010: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136010
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: binwalk
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for binwalk.

CVE-2026-7179[0]:
| A security vulnerability has been detected in OSPG binwalk up to
| 2.4.3. This vulnerability affects the function
| read_null_terminated_string of the file
| src/binwalk/plugins/winceextract.py of the component WinCE
| Extraction Plugin. Such manipulation of the argument self.file_name
| leads to path traversal. The attack can only be performed from a
| local environment. The exploit has been disclosed publicly and may
| be used. The project maintainer confirms this issue: "I accept the
| existence of the Path Traversal vulnerability. However, as stated in
| the Github link, it reached EOL and as a result no actions should be
| expected." The GitHub repository mentions, that "[u]sers and
| contributors should migrate to binwalk v3." This vulnerability only
| affects products that are no longer supported by the maintainer.

https://github.com/dhabaleshwar/Open-Source-Vulnerabilities/blob/main/binwalk_path_traversal.md

This sounds like binwalk shouldn't be included in forky?



If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-7179
    https://www.cve.org/CVERecord?id=CVE-2026-7179

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: binwalk
Source-Version: 2.4.3+dfsg1-3
Done: Sven Geuer <[email protected]>

We believe that the bug you reported is fixed in the latest version of
binwalk, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sven Geuer <[email protected]> (supplier of updated binwalk package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 26 Aug 2026 14:53:07 +0200
Source: binwalk
Architecture: source
Version: 2.4.3+dfsg1-3
Distribution: unstable
Urgency: medium
Maintainer: Debian Security Tools <[email protected]>
Changed-By: Sven Geuer <[email protected]>
Closes: 1136010
Changes:
 binwalk (2.4.3+dfsg1-3) unstable; urgency=medium
 .
   * Team upload.
   * d/p/*: Add prevent-path-traversal-in-wince.patch fixing CVE-2026-7179;
     thanks to Fukui Daichi for providing the patch (Closes: #1136010).
   * d/watch: Update it to version 5 format.
   * d/control:
     - Drop 'Priority: optional'.
     - Drop 'Rules-Requires-Root: no'.
     - Bump Standards-Version to 4.7.4.
   * Bump debhelper-compat.
     - d/control:
       - Update debhelper-compat to 14.
       - Drop all ${*:Depends} substvar mentionings.
     - d/docs: Rename it to python3-binwalk.docs.
     - d/examples: Rename it to python3-binwalk.examples.
   * d/copyright: Add packaging copyrights.
Checksums-Sha1:
 a6484e6394fc9342ff62e1eb5f63114b74bf65a0 2221 binwalk_2.4.3+dfsg1-3.dsc
 940796f4eab0cca498c4b4a6e909e803f31a8be9 8828 
binwalk_2.4.3+dfsg1-3.debian.tar.xz
 97bac58bbcb4ca4bc7e90c77bf83e3490341a2a4 7029 
binwalk_2.4.3+dfsg1-3_amd64.buildinfo
Checksums-Sha256:
 5a8a9332f3f7c036c3308deed1d8c839cf17e4daf12ecba60510fed4d34f5157 2221 
binwalk_2.4.3+dfsg1-3.dsc
 17a9f758b7944995a0ccd1a6382c16880bceb61c2a60a6ed6809c35b9baf5fff 8828 
binwalk_2.4.3+dfsg1-3.debian.tar.xz
 50ee1697e1616a22b45740c0f4a808948eab760287688ead9f218a7e7f211d37 7029 
binwalk_2.4.3+dfsg1-3_amd64.buildinfo
Files:
 ddcdf42067e559c4086e019cfca90587 2221 devel optional binwalk_2.4.3+dfsg1-3.dsc
 6d99a4e8e4e1990846604bd15b0aa9b1 8828 devel optional 
binwalk_2.4.3+dfsg1-3.debian.tar.xz
 65bb74c578e2d62bb74ccecd6104dc6a 7029 devel optional 
binwalk_2.4.3+dfsg1-3_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJDBAEBCgAtFiEEPfXoqkP8n9/QhvGVrfUO2vit1YUFAmqO45gPHHNnZUBkZWJp
YW4ub3JnAAoJEK31Dtr4rdWFTyQP/3pfICgmITq3aIpSDG8dxvUhXWlNjCndApJy
5pZOHWJcCmhOSEE8qut6fxumjLP1wnXxF7gpn4YvyNEkHR8WVt0U4rg3mApWOGWs
XMl5t0wQw0RnBoqFSqwmGkeDmBkcSYQC1yiEDWa1GrV/RZplu1V4OU1fc0eqV4WI
hR+Fv8fixdWaiKaiOL9ylwhPu+xz/ItdOIIDZU2FoiZkLoeVV8Yjho5q6izC6cHI
H/62qHARdqJXGRJCEecVVRV74XsTMp3z3mYhFtcrzx4xSEMfXAdqZYVYb3Vc0mWh
3u0w9nsvGROKrHJl1AKb92qDjm5+hov5kwnkyTCsX1IueaDXnUC3iePow1DJrwUQ
w9UQxDUY3PtnAYcvVHUmUNCXPNmMrI8IF5JO6LdA43YMGjzNJf9mFqcVN2PnnbRm
jxgu871ckPEpdjfw/srSi++Lz3CjW+XIV0JCXhPuzliMUPaOQq3CtzWORCRmTFWk
mnKVeDhklkZaWsOinPG1cFJCzpNaoq9smVLyueRqOSDmRgY6s4xmpvIVC9dvpyH2
u1fEqmAvCMwt77WQLkYikhj+bXfNT0jd6IT/wcjVitw1Rs7x0J7F9hd2ZYzbtJrw
BuvvwC+eTDUuQ0I6jJx4QrlhBJ752WZe03aNJaJKOPR0UbUBUYIkb3G+Kn7PR2zk
EG6/CTej
=mPAY
-----END PGP SIGNATURE-----

Attachment: pgpGO_BAi4ohg.pgp
Description: PGP signature


--- End Message ---

Reply via email to