Your message dated Mon, 31 Aug 2026 17:32:05 +0000
with message-id <[email protected]>
and subject line Bug#1144490: fixed in xapian-core 1.4.29-3+deb13u1
has caused the Debian Bug report #1144490,
regarding libxapian30: CVE-2026-77643: previously missed corner case of 
CVE-2018-0499
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1144490: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144490
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: libxapian30
Version: 1.4.31-2
Fixed: 1.4.32-1
Severity: serious
Tags: security
Justification: potential security vulnerability
X-Debbugs-Cc: Debian Security Team <[email protected]>

This was reported to upstream's public development list:

https://lists.xapian.org/pipermail/xapian-devel/2026-August/003429.html

The bug is missing HTML escaping, potentially allowing an attacker to inject
unescaped data into generated HTML search results.  It's effectively a
corner case missed when we fixed CVE-2018-0499.

It affects upstream releases 1.4.x for x <= 31 and 2.0.0.
Upstream releases 1.4.32 and 2.0.1 include a fix, and I've already
uploaded 1.4.32 to unstable and 2.0.1 to experimental.

There are patches here:

https://trac.xapian.org/wiki/SecurityFixes/2018-07-02#a2026-08-13update
The actually fix is just this (the patches also add test coverage):


     if (hi_start.empty() && hi_end.empty() && text.size() <= length) {        
-        // Too easy!
-        return text;
+        // The text is already short enough so we just need to perform
+        // escaping.
+        string output;
+        append_escaping_xml(text.data(), text.data() + text.size(), output);
+        return output;
     }

The 4 variables in the condition are all parameters from the
MSet::snippet() API call.  In order to be exploited, hi_start and hi_end
need to be passed as empty strings (they have default values which
aren't empty).  I'd expect most usage in a web context would want to
highlight matching terms in the snippet and so it's probably uncommon to
pass empty string here - I looked for an example of such usage with
codesearch.d.n but didn't find anything.

However empty highlighting strings are a legitimate way to call this
method, and I may have missed an instance, or such use may be present in
code that hasn't been packaged for Debian.  Therefore I think we should
apply this patch to stable.

I've already contacted the security team and they said we should handle
this via a stable update.

Cheers,
    Olly

--- End Message ---
--- Begin Message ---
Source: xapian-core
Source-Version: 1.4.29-3+deb13u1
Done: Olly Betts <[email protected]>

We believe that the bug you reported is fixed in the latest version of
xapian-core, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Olly Betts <[email protected]> (supplier of updated xapian-core package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 16 Aug 2026 09:59:21 +1200
Source: xapian-core
Architecture: source
Version: 1.4.29-3+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Olly Betts <[email protected]>
Changed-By: Olly Betts <[email protected]>
Closes: 1144490
Changes:
 xapian-core (1.4.29-3+deb13u1) trixie; urgency=medium
 .
   * Cherry-pick fix for missed corner case of CVE-2018-0499.  New patch:
     cve-2018-0499-mset-snippet-escaping-no-highlighting-1.4.x.patch
     (Closes: #1144490)
Checksums-Sha1:
 d55887c43f638a3695acae2d1b03fd3f3584ee4a 2170 xapian-core_1.4.29-3+deb13u1.dsc
 3d4f92359d5aa31eb75b2512c5f4fd728a46bb34 21188 
xapian-core_1.4.29-3+deb13u1.debian.tar.xz
 5d5a2afab491ec63837fcf825bd55f8970ca3754 8185 
xapian-core_1.4.29-3+deb13u1_amd64.buildinfo
Checksums-Sha256:
 a8ce3f460f0174c243afaadbed7a8fde835ff1bf96813a9685ebe12d3350eaa0 2170 
xapian-core_1.4.29-3+deb13u1.dsc
 de94df438d212e40bb96ecac3032a9c8ef2fcf173fd0d9ad5a69b83c84143ee2 21188 
xapian-core_1.4.29-3+deb13u1.debian.tar.xz
 cc44cd021096c213571f083794498d7729521a0ec970ab56f76bce29a152f1bc 8185 
xapian-core_1.4.29-3+deb13u1_amd64.buildinfo
Files:
 c3d5088c80cce7f38247d9ed095dd337 2170 libs optional 
xapian-core_1.4.29-3+deb13u1.dsc
 952d2b30f69f0d3f6b45d68cec0270c0 21188 libs optional 
xapian-core_1.4.29-3+deb13u1.debian.tar.xz
 2b30373171908b423079cc95a0e6ed41 8185 libs optional 
xapian-core_1.4.29-3+deb13u1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEECOJAD/f+j+3jrLUoGBR7BzutKwcFAmqA5TUACgkQGBR7Bzut
KwcHgg/8CcA0xg/UrNdziNdqHM8V1DwOHoQIP63vXLIp93DyZcW+/Q6ZPuxFInhI
GhK3Dknlg2skjm83Nh2VDJbDb6Jb4Ufyh31KavS3umMV8ap9bsQuyi8YrLGk7QoB
9SpPYhGaKE4G+I6z9FWx2TkjVbQc1UkBhWO7//tvNdLuTuoBMwuChXXAEqsF8Tqg
d/9umaPvhPNEwc1H1GGBhlquQrl/7736vHWMRA4OjfwfDTEbc/AuugwkCK/jV+4k
m8K/6i1wu2at9s9Q4J4GnhMJIxW0VD8RZn+0Dtha572CC/fBWcBwhCK818AybrPL
aISf6PUgGpTUTLPbNV2CYT7pYpyCOlpYdmeuyzK37YPjNtAzTJg7NndjH5HyqNXX
nCp/f2A7ZYCLHLrbMgI1mHLapKyNXmPKJArP3a6pIHumhpKs3CWr5FMK5EpkObg+
YlUM8QNnzhPQTQ1jxTHi9QXxnhNr48d5eVgqNHfMhNc6EpS/EL2DHg0JDH6VC3KP
Hzvrmgi5HIzltY1XGMLW3faiXjHnh192MLC+ssT6+OO1yBCuFNsN2A43fd7CszIl
EH7n0nRwv6dVkolyPc0ppHihLrCkx1bXdk61t3+2/Pqm/q8QImdlaGTUwyAZt1KQ
pHMTMbcWy4kr38+/1tIIF65BFH2ph5dh+fyNsWswrHRtgi0on10=
=183y
-----END PGP SIGNATURE-----

Attachment: pgpEHNFNpyJJL.pgp
Description: PGP signature


--- End Message ---

Reply via email to