Your message dated Thu, 29 Jul 2010 04:47:21 +0000
with message-id <[email protected]>
and subject line Bug#560942: fixed in xmlrpc-c 1.06.27-1.1
has caused the Debian Bug report #560942,
regarding CVE-2009-3560 and CVE-2009-3720 denial-of-services
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
560942: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560942
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
package: xmlrpc-c
severity: serious
tags: security

Hi,

The following CVE (Common Vulnerabilities & Exposures) ids were
published for expat.  I have determined that this package embeds a
vulnerable copy of xmlparse.c and xmltok_impl.c.  However, since this is
a mass bug filing (due to so many packages embedding expat), I have
not had time to determine whether the vulnerable code is actually
present in any of the binary packages derived from this source package.
Please determine whether this is the case. If the binary packages are
not affected, please feel free to close the bug with a message
containing the details of what you did to check.

CVE-2009-3560[0]:
| The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1,
| as used in the XML-Twig module for Perl, allows context-dependent
| attackers to cause a denial of service (application crash) via an XML
| document with malformed UTF-8 sequences that trigger a buffer
| over-read, related to the doProlog function in lib/xmlparse.c, a
| different vulnerability than CVE-2009-2625 and CVE-2009-3720.

CVE-2009-3720[1]:
| The updatePosition function in lib/xmltok_impl.c in libexpat in Expat
| 2.0.1, as used in Python, PyXML, w3c-libwww, and other software,
| allows context-dependent attackers to cause a denial of service
| (application crash) via an XML document with crafted UTF-8 sequences
| that trigger a buffer over-read, a different vulnerability than
| CVE-2009-2625.

These issues also affect old versions of expat, so this package in etch
and lenny is very likely affected.  This is a low-severity security
issue, so DSAs will not be issued to correct these problems.  However,
you can optionally submit a proposed-update to the release team for
inclusion in the next stable point releases.  If you plan to do this, 
please open new bugs and include the security tag so we are aware that
you are working on that.

For further information see [0],[1],[2],[3].  In particular, [2] and [3]
are links to the patches for CVE-2009-3560 and CVE-2009-3720
respectively. Note that the ideal solution would be to make use of the
system expat so only one package will need to be updated for future
security issues. Preferably in your update to unstable, alter your
package to make use of the system expat.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3560
    http://security-tracker.debian.org/tracker/CVE-2009-3560
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3720
    http://security-tracker.debian.org/tracker/CVE-2009-3720
[2]
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.165
[3]
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&r2=1.15&view=patch



--- End Message ---
--- Begin Message ---
Source: xmlrpc-c
Source-Version: 1.06.27-1.1

We believe that the bug you reported is fixed in the latest version of
xmlrpc-c, which is due to be installed in the Debian FTP archive:

libxmlrpc-c3-dev_1.06.27-1.1_i386.deb
  to main/x/xmlrpc-c/libxmlrpc-c3-dev_1.06.27-1.1_i386.deb
libxmlrpc-c3_1.06.27-1.1_i386.deb
  to main/x/xmlrpc-c/libxmlrpc-c3_1.06.27-1.1_i386.deb
xml-rpc-api2cpp_1.06.27-1.1_i386.deb
  to main/x/xmlrpc-c/xml-rpc-api2cpp_1.06.27-1.1_i386.deb
xml-rpc-api2txt_1.06.27-1.1_i386.deb
  to main/x/xmlrpc-c/xml-rpc-api2txt_1.06.27-1.1_i386.deb
xmlrpc-c_1.06.27-1.1.diff.gz
  to main/x/xmlrpc-c/xmlrpc-c_1.06.27-1.1.diff.gz
xmlrpc-c_1.06.27-1.1.dsc
  to main/x/xmlrpc-c/xmlrpc-c_1.06.27-1.1.dsc



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Moritz Muehlenhoff <[email protected]> (supplier of updated xmlrpc-c package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Wed, 28 Jul 2010 22:18:54 -0400
Source: xmlrpc-c
Binary: libxmlrpc-c3-dev libxmlrpc-c3 xml-rpc-api2cpp xml-rpc-api2txt
Architecture: source i386
Version: 1.06.27-1.1
Distribution: unstable
Urgency: medium
Maintainer: Sean Finney <[email protected]>
Changed-By: Moritz Muehlenhoff <[email protected]>
Description: 
 libxmlrpc-c3 - A lightweight RPC library based on XML and HTTP for C and C++
 libxmlrpc-c3-dev - A lightweight RPC library based on XML and HTTP for C and 
C++
 xml-rpc-api2cpp - Generate C++ wrapper classes for XML-RPC servers
 xml-rpc-api2txt - Dump an XML-RPC API as a text file
Closes: 560942
Changes: 
 xmlrpc-c (1.06.27-1.1) unstable; urgency=medium
 .
   * Non-maintainer upload.
   * Fix CVE-2009-3560 and CVE-2009-3720 (Closes: #560942)
Checksums-Sha1: 
 46140a45f4f796fab4a73de1218840cfb8ffafcd 1087 xmlrpc-c_1.06.27-1.1.dsc
 923e3a6b3131a755111c8029f80bf0a5d0106647 7251 xmlrpc-c_1.06.27-1.1.diff.gz
 276a19d84691d99bd3d8690d281d61ffdedb423d 361406 
libxmlrpc-c3-dev_1.06.27-1.1_i386.deb
 250b0e55666a094de4e6134bf28cf2ef57042f6e 244042 
libxmlrpc-c3_1.06.27-1.1_i386.deb
 9b134071fff0f9f127e282ac3d1c6c03bc66e593 30500 
xml-rpc-api2cpp_1.06.27-1.1_i386.deb
 6cbf97ab71294f09b6fb92eaa72701db4d17e883 8424 
xml-rpc-api2txt_1.06.27-1.1_i386.deb
Checksums-Sha256: 
 cc745290294ab491f0f60dedc6312320b21422e953ea74a85863c60ae2d36219 1087 
xmlrpc-c_1.06.27-1.1.dsc
 fc8b751226b88eb172a6fe7a08e21dc55d3913101aa0e75fbc01569031239e90 7251 
xmlrpc-c_1.06.27-1.1.diff.gz
 1dd0f43da2899e333749923e4fb65147f8a81ef14eeeb78b9eb1ae0a4a8f53d1 361406 
libxmlrpc-c3-dev_1.06.27-1.1_i386.deb
 6388b7c6218995ffe2f5be4e5e8574261f31b2682f8009a65e3e101cd9317611 244042 
libxmlrpc-c3_1.06.27-1.1_i386.deb
 9492b6c75661f08c7fd9413bcec1205f67ccbc00984d588f11f8aab4722a5a14 30500 
xml-rpc-api2cpp_1.06.27-1.1_i386.deb
 9ac45ed7a208457d9cb1dd71645ec3bc2dba777926253763de7e8c2ec0a04eac 8424 
xml-rpc-api2txt_1.06.27-1.1_i386.deb
Files: 
 61ce6912e75d334bfbdd60b6dd754d58 1087 libs optional xmlrpc-c_1.06.27-1.1.dsc
 321d69c24485c2421d7d39e94b915f5f 7251 libs optional 
xmlrpc-c_1.06.27-1.1.diff.gz
 4049df53c8ac541d8110d3dc5254909e 361406 libdevel optional 
libxmlrpc-c3-dev_1.06.27-1.1_i386.deb
 8028cbc1897f0772ec5896275acf171c 244042 libs optional 
libxmlrpc-c3_1.06.27-1.1_i386.deb
 b72a18b9bd47e8abd272212cf21ddbaf 30500 devel optional 
xml-rpc-api2cpp_1.06.27-1.1_i386.deb
 72c600972493fb088200c1ab0a381236 8424 devel optional 
xml-rpc-api2txt_1.06.27-1.1_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkxQ5sQACgkQXm3vHE4uyloclgCg7Bi5jDL5gyGmyWfFyMfSwLFD
niQAniOXi1I9qneg/p5/wAiaqD/N/5IR
=pvN3
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to