Your message dated Wed, 30 Mar 2022 21:22:31 +0200
with message-id <[email protected]>
and subject line Re: Bug#991370: libmatio: CVE-2020-36428
has caused the Debian Bug report #991370,
regarding libmatio: CVE-2020-36428
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
991370: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=991370
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libmatio
Version: 1.5.19-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for libmatio.
CVE-2020-36428[0]:
| matio (aka MAT File I/O Library) 1.5.18 through 1.5.21 has a heap-
| based buffer overflow in ReadInt32DataDouble (called from
| ReadInt32Data and Mat_VarRead4).
Not fixed yet (at time of writing) upstream I think.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2020-36428
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36428
[1] https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=21421
[2]
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/matio/OSV-2020-799.yaml
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: libmatio
Source-Version: 1.5.22-1
Hi Sébastien,
Thanks a lot for the quick followups!
On Wed, Mar 30, 2022 at 09:14:06PM +0200, Sébastien Villemot wrote:
> Le mercredi 30 mars 2022 à 21:08 +0200, Sébastien Villemot a écrit :
> > > The OSV-2020-799.yaml cannot be taken into account because it was
> > > marked as such as consequence of
> > > https://github.com/google/oss-fuzz-vulns/issues/12 as far i can see.
> > > Actually it looks that tbeu considers it invalid issue? If this turned
> > > not to be true, what is the fix?
> >
> > If upstream is wrong, then I have no idea what would be the fix.
>
> I forgot to mention that tbeu is the upstream maintainer.
Yes and this is part of why I'm confused about the status, because it
was the upstream maintainer claiming the issue is invalid. But let's
follow that then.
Regards,
Salvatore
--- End Message ---
--
debian-science-maintainers mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-science-maintainers