Your message dated Sun, 10 Mar 2024 16:37:49 +0000
with message-id <[email protected]>
and subject line Bug#1064996: fixed in azure-uamqp-python 1.6.8-2
has caused the Debian Bug report #1064996,
regarding azure-uamqp-python: CVE-2024-27099
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1064996: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1064996
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: azure-uamqp-python
Version: 1.6.8-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for azure-uamqp-python.

CVE-2024-27099[0]:
| The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud
| Services. When processing an incorrect `AMQP_VALUE` failed state,
| may cause a double free problem. This may cause a RCE. Update
| submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-27099
    https://www.cve.org/CVERecord?id=CVE-2024-27099
[1] 
https://github.com/Azure/azure-uamqp-c/security/advisories/GHSA-6rh4-fj44-v4jj

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: azure-uamqp-python
Source-Version: 1.6.8-2
Done: Michael R. Crusoe <[email protected]>

We believe that the bug you reported is fixed in the latest version of
azure-uamqp-python, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael R. Crusoe <[email protected]> (supplier of updated azure-uamqp-python 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 10 Mar 2024 17:09:57 +0100
Source: azure-uamqp-python
Architecture: source
Version: 1.6.8-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <[email protected]>
Changed-By: Michael R. Crusoe <[email protected]>
Closes: 1064996
Changes:
 azure-uamqp-python (1.6.8-2) unstable; urgency=medium
 .
   * Team upload.
   * d/patches/no-distutils: remove useage of distutils for Python 3.12.
   * d/patches: cherry-pick two patches from upstream's upstream to fix
     CVE-2024-25110 and CVE-2024-27099. Closes: #1064996, #1064996
Checksums-Sha1:
 c01ddb9fbea156e8f231ab070176126e261b9bd5 2313 azure-uamqp-python_1.6.8-2.dsc
 4d1f22164f6946170ae69e8c5311471a07385d20 6748 
azure-uamqp-python_1.6.8-2.debian.tar.xz
 ac3fd12445a21b22ee0c644cb1014272d6e93149 9550 
azure-uamqp-python_1.6.8-2_source.buildinfo
Checksums-Sha256:
 91503d3ad84b9642fef8bc5f87ed50c5ac63e43072c62f7f07caff0343f06e09 2313 
azure-uamqp-python_1.6.8-2.dsc
 857252bac6e1f6b02bb68190211fc18e36e3d8e77f022705c822309b4f028a6a 6748 
azure-uamqp-python_1.6.8-2.debian.tar.xz
 3dc053b6ccaf704188b26f7bd13e87cd426b8ed0f4684662a8d0999b3534d7de 9550 
azure-uamqp-python_1.6.8-2_source.buildinfo
Files:
 6e7e1e24d89761df1be51cd664fadcc1 2313 python optional 
azure-uamqp-python_1.6.8-2.dsc
 e211922dec9baad2bcefbba0d24eb33b 6748 python optional 
azure-uamqp-python_1.6.8-2.debian.tar.xz
 b5cb4439be805d5db0e4d711c6a59843 9550 python optional 
azure-uamqp-python_1.6.8-2_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEck1gkzcRPHEFUNdHPCZ2P2xn5uIFAmXt24MACgkQPCZ2P2xn
5uKnvA/+JkaiOt8gZ0k5vgeEfPlMTUfX4u8m56tHBitcAaya+7X63IEL7FzrQVRi
AOZbro7kJ6RIoBtKUNat5jo6VabGCXNRHX5GS+AN1nHhFtWh8AiEwW95U9xatP4f
OfdC8mBo9ScuWWHJdvb7nJ1nSF2YDMqFhMFMRm+3XI1ADN4ZHVlZUX7+8E/sUdV/
V54KJoGVZQ5l+QlORQXUprhpdDLzfRYPO/ddb4nVsV2yxewR2NdcP8ADPtKtR1H9
laOK19FkZZASsPAyLj+zVV2mUabGDPkDK8RupZpaB8neBhuAecUddhUQynYOC3Mt
G6TqyryLuGYZwG6A3r9uKBi10TMsNVS7RMsYVcVbW57TtSBtdvxrCVete66ovp3Y
HJUtKXZiH2TNutDz4+yDfuskR2Uzg3++kquLL7vlDuBwa6rvfJk2bfAknqoTFqW2
hnBIDRqghPdNDr392eEHYvjbLtmOUeA+qPpTevDcLIMmBHCbY6azoqgpbKXoMS70
xHqU7pevpPhgHneUOX5DgmZgBiZM2EdKYyejUjup2uAGlCpgxHcNksOVwwNm9wIY
dzbkSGtTJDVTDIAtbW4pMH1N1uzmL9OzLeIqpyjjrkAvPm6gQR6ZOpUw/pWUdb+s
gn1WEFtIWlxPN/xketI0s9C4/RintnVRr8f0+0KEaefHXVA3wag=
=nkAh
-----END PGP SIGNATURE-----

Attachment: pgpH0A0VCMlYN.pgp
Description: PGP signature


--- End Message ---

Reply via email to