Your message dated Tue, 28 Mar 2017 18:03:48 +0000
with message-id <[email protected]>
and subject line Bug#858546: fixed in libxslt 1.1.29-2.1
has caused the Debian Bug report #858546,
regarding CVE-2017-5029: Integer overflow in xsltAddTextString
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
858546: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=858546
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libxslt
Severity: important
Tags: security patch
Hi,
the following vulnerability was published for libxslt. The issue can be
exploited to trigger an out of bounds write on 64-bit systems.
CVE-2017-5029[0]:
Integer overflow in xsltAddTextString
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
Upstream has committed a patch here:
https://git.gnome.org/browse/libxslt/commit/?id=08ab2774b870de1c7b5a48693df75e8154addae5
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2017-5029
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5029
Please adjust the affected versions in the BTS as needed.
--
Raphaël Hertzog ◈ Debian Developer
Support Debian LTS: https://www.freexian.com/services/debian-lts.html
Learn to master Debian: https://debian-handbook.info/get/
--- End Message ---
--- Begin Message ---
Source: libxslt
Source-Version: 1.1.29-2.1
We believe that the bug you reported is fixed in the latest version of
libxslt, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated libxslt package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 26 Mar 2017 19:44:01 +0200
Source: libxslt
Binary: libxslt1.1 libxslt1-dev libxslt1-dbg xsltproc python-libxslt1
python-libxslt1-dbg
Architecture: source
Version: 1.1.29-2.1
Distribution: unstable
Urgency: high
Maintainer: Debian XML/SGML Group <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 858546
Description:
libxslt1-dbg - XSLT 1.0 processing library - debugging symbols
libxslt1-dev - XSLT 1.0 processing library - development kit
libxslt1.1 - XSLT 1.0 processing library - runtime library
python-libxslt1 - Python bindings for libxslt1
python-libxslt1-dbg - Python bindings for libxslt1 (debug extension)
xsltproc - XSLT 1.0 command line processor
Changes:
libxslt (1.1.29-2.1) unstable; urgency=high
.
* Non-maintainer upload.
* Check for integer overflow in xsltAddTextString (CVE-2017-5029)
(Closes: #858546)
Checksums-Sha1:
4306ce120f020510fa7dd457353ea5890a01daa5 2535 libxslt_1.1.29-2.1.dsc
3951962a90bb54ee21f56b130287b0510f192a1b 28548 libxslt_1.1.29-2.1.debian.tar.xz
Checksums-Sha256:
8823c0cb209943fb1a3f6761b9a1b3c49c0348da3aa7a67ff9e09760c0976410 2535
libxslt_1.1.29-2.1.dsc
93ef76669dae1bdfdd5f60418e29ccda60c7b693b67d0da81e7d12ffb6d25085 28548
libxslt_1.1.29-2.1.debian.tar.xz
Files:
497c9817c9d8758e46a3aa8e2f577536 2535 text optional libxslt_1.1.29-2.1.dsc
1ec61a61983c71cc2a34b8bc348b02ee 28548 text optional
libxslt_1.1.29-2.1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAljX/tpfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89ERGcP/069NxPjhkV2ZyYbcnl04qH+U01mm5I+
MZnv9Ho42r+na6zpp8Ex1jTJHELbq6SwG3ADtZKGMuHhuuL7T/bPa7ivdKpyeEYn
wuUacx6CIEWr+oyFJiuBuQw9MlJy3JuHBH06G8gIltxJj8dvuFUrvCnVwRWL63jJ
QYZtGLBLiF/RcFXdF0rl/jBl2TVXVGgYGKz3/O1GkPUknKJm9bf7UYj/hxqjGu/9
DSNBSKNxgGRKoi8JmiYCP0shRv7qzRX+IU0FEtlWb3dUfkRLFJSL5PGG17pCnuOM
Y0p3f30SXs9VNr6aDGAC0Kd7oVShAEgnaliwa4iAe/iJYxF2rwpGKshHBxVx16yo
qyiFHi4SASmVCfUhgI0cvCSQjlnW6ythFe1Y2uHywVa44/lL0Udh1m0s494CrUKy
JS+ypUvI3D15yxm4uQkID3JROt5EH2mLvyWp+z2spURa665Bqqi/NxrcaN4pOivZ
PQhaV0AlUMUZTbRhegtwCVIUnP4HkV8YYPZ05vdNtYNNFAowdX/RMQtOG1m4e8bf
LvkAp26rWdhBckFG2tTIOkZuSWHhjGhJDkIfaGrth9RzzSt9nhmkkS+/Gg0IOhki
QfT5qxtAlobGMaQ5jc8Ro5OHibmmcA1h6m4y6qjnSc2qq/PSYocqUPsO9GHsz1zG
mqp97sRW3iR4
=X5Od
-----END PGP SIGNATURE-----
--- End Message ---