Processed: Bug#1068457 marked as pending in azure-uamqp-python

2024-04-17 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 pending
Bug #1068457 [src:azure-uamqp-python] azure-uamqp-python: CVE-2024-29195
Added tag(s) pending.

-- 
1068457: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068457
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1068457: marked as pending in azure-uamqp-python

2024-04-17 Thread Thomas Goirand
Control: tag -1 pending

Hello,

Bug #1068457 in azure-uamqp-python reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/python-team/packages/azure-uamqp-python/-/commit/f4f79087f50551619f9659594ecf7f08f6acb952


* CVE-2024-29195: An attacker can cause an integer wraparound or under-
allocation or heap buffer overflow due to vulnerabilities in parameter
checking mechanism, by exploiting the buffer length parameter in Azure C
SDK, which may lead to remote code execution. Applied upstream patch:
CVE-2024-29195_Add-malloc-size-checks.patch (Closes: #1068457).


(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1068457