Your message dated Sat, 30 May 2020 19:17:08 +0000
with message-id <[email protected]>
and subject line Bug#960199: fixed in libexif 0.6.21-5.1+deb10u2
has caused the Debian Bug report #960199,
regarding libexif: CVE-2020-12767
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
960199: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=960199
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libexif
Version: 0.6.21-6
Severity: important
Tags: security upstream
Forwarded: https://github.com/libexif/libexif/issues/31
Control: found -1 0.6.21-5.1+deb10u1
Control: found -1 0.6.21-2+deb9u1
Control: found -1 0.6.21-2
Hi,
The following vulnerability was published for libexif.
CVE-2020-12767[0]:
| exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-
| by-zero error.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2020-12767
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12767
[1] https://github.com/libexif/libexif/issues/31
[2]
https://github.com/libexif/libexif/commit/e22f73064f804c94e90b642cd0db4697c827da72
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: libexif
Source-Version: 0.6.21-5.1+deb10u2
Done: Mike Gabriel <[email protected]>
We believe that the bug you reported is fixed in the latest version of
libexif, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Mike Gabriel <[email protected]> (supplier of updated libexif package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Thu, 21 May 2020 11:26:42 +0200
Source: libexif
Architecture: source
Version: 0.6.21-5.1+deb10u2
Distribution: buster
Urgency: medium
Maintainer: Debian PhotoTools Maintainers
<[email protected]>
Changed-By: Mike Gabriel <[email protected]>
Closes: 960199
Changes:
libexif (0.6.21-5.1+deb10u2) buster; urgency=medium
.
[ Mike Gabriel ]
* Sponsored upload.
* debian/patches: Trivial rebase of various patches.
.
[ Hugh McMaster ]
* Team upload.
* Add upstream patches to fix two security issues:
- cve-2020-12767.patch: Prevent some possible division-by-zero errors
in exif_entry_get_value() (CVE-2020-12767) (Closes: #960199).
- cve-2020-0093.patch: Prevent read buffer overflow (CVE-2020-0093).
Checksums-Sha1:
849fbb11d9d0d2c1a211dfc72dee386db59aa667 2178 libexif_0.6.21-5.1+deb10u2.dsc
ff1bf3c05ac6ff85f9a90973b698426cfdba5a76 14576
libexif_0.6.21-5.1+deb10u2.debian.tar.xz
a004fcf9a45387ff0c1e6b1d1ad5ac0e3824c583 8019
libexif_0.6.21-5.1+deb10u2_source.buildinfo
Checksums-Sha256:
c99723cab60f58e661186298d792b1acd840c926dbd36d5dc1f12ed1345962b0 2178
libexif_0.6.21-5.1+deb10u2.dsc
e917f7c169ea9c416be7a113895b79c6623c0cdfaa2880a53bb5f0f9f9798f02 14576
libexif_0.6.21-5.1+deb10u2.debian.tar.xz
6d438fdda7aa82d2531203f671a36d829e3759471d042aede18cbcb761c6d422 8019
libexif_0.6.21-5.1+deb10u2_source.buildinfo
Files:
25be56a747499322bdea766ae731aeab 2178 libs optional
libexif_0.6.21-5.1+deb10u2.dsc
e6dde630add0f5406006f1ed6b94d3b1 14576 libs optional
libexif_0.6.21-5.1+deb10u2.debian.tar.xz
97f3d4905134d47e18217fb1a623b3b6 8019 libs optional
libexif_0.6.21-5.1+deb10u2_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJJBAEBCAAzFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAl7GSecVHHN1bndlYXZl
ckBkZWJpYW4ub3JnAAoJEJr0azAldxsxqPsP/3Bbp3mH6R1kwP5bmlGe/Q3NQ8JJ
17TNArPEDjj45M8g3IJ4HE+5Hv11D54uMBZ2ws5p+OlsSk4FWoJGzbnkt6737TNq
v1Z063HL/grXQ3fpuBSsoDH6n9HXm2T5/3cvz//iXYGAtI/jc+1By3trC+zWPr0Y
SjZzBRKxr6YWKaJJyLXFpU3O1iGnIW/9AgvZJTZma3FPcd/41vBz88waTwRRbiK2
GCjs6StRhe2JFY6XfKcxJZqAI30dB+aeOBV5NoWdMR8o5NxHHt031OF1ykZUdRSJ
DLtOBRh37XF5HBH8gWNsr0r56Z1k6HhDzdXF4CLhA6YFFBjw2gvNWHCQ3UToHFCR
dBFlj6hmWSR90dP0/dYYdr+Z6zEp9qNcMixgzkr+tKQuvRVdZvJrtb1geK49iNtv
3NjxEFG0EXzOt5xES54t7JUQkdj5UfQWtCAhJaHeKrRs5SPE4jb/KquA2XMc/H2v
JHKCyZ8lFLJLz9NR0pyTWv7einjHHww05WEZ19CbRjVAmwRwg4TaJj8g5wEhQHEs
RXWvuelx06itUADSLaZRcsxfTwbUJwTD6LFQOKGrtBy7NylbpcDhz33NoEiM1WA5
O0RPeH34d1p9nnXy7Bh/JIgVIZvhYdOGI6osVK3gTZfA1vFg9IlrzW7yn6uH5ae5
6Hzrzu1kB37JDvTB
=KZww
-----END PGP SIGNATURE-----
--- End Message ---
--
Pkg-phototools-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-phototools-devel