Bug#1034177: bzip2: CVE-2023-29415 CVE-2023-29416 CVE-2023-29418 CVE-2023-29419 CVE-2023-29420 CVE-2023-29421

2023-04-10 Thread Salvatore Bonaccorso
Hi Santiago, On Mon, Apr 10, 2023 at 08:51:06PM +0200, Santiago Ruano Rincón wrote: > Control: reassign -1 bzip3 > Control: retitle -1 bipz3 CVE-2023-29415 CVE-2023-29416 > CVE-2023-29418 CVE-2023-29419 CVE-2023-29420 CVE-2023-29421 > > Dear Moritz and Sec Team, > > Please, correct me if I am

Bug#1034177: bzip2: CVE-2023-29415 CVE-2023-29416 CVE-2023-29418 CVE-2023-29419 CVE-2023-29420 CVE-2023-29421

2023-04-10 Thread Santiago Ruano Rincón
Control: reassign -1 bzip3 Control: retitle -1 bipz3 CVE-2023-29415 CVE-2023-29416 CVE-2023-29418 CVE-2023-29419 CVE-2023-29420 CVE-2023-29421 Dear Moritz and Sec Team, Please, correct me if I am wrong, but it seems a bzip3 bug, instead of a bzip2's. El 10/04/23 a las 19:33, Moritz Mühlenhoff

Bug#1034177: bzip2: CVE-2023-29415 CVE-2023-29416 CVE-2023-29418 CVE-2023-29419 CVE-2023-29420 CVE-2023-29421

2023-04-10 Thread Salvatore Bonaccorso
Hi Moritz, On Mon, Apr 10, 2023 at 07:33:38PM +0200, Moritz Mühlenhoff wrote: > Source: bzip2 > X-Debbugs-CC: t...@security.debian.org > Severity: grave > Tags: security > > Hi, > > The following vulnerabilities were published for bzip2. I think this all should be against src:bzip3 instead?

Bug#1034177: bzip2: CVE-2023-29415 CVE-2023-29416 CVE-2023-29418 CVE-2023-29419 CVE-2023-29420 CVE-2023-29421

2023-04-10 Thread Moritz Mühlenhoff
Source: bzip2 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for bzip2. CVE-2023-29415[0]: | An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial | of service (process hang) can occur with a crafted archive