Your message dated Sun, 24 Jan 2010 15:44:54 +0000
with message-id <[email protected]>
and subject line Bug#560912: fixed in python2.5 2.5.4-3.1
has caused the Debian Bug report #560912,
regarding CVE-2009-3560 and CVE-2009-3720 denial-of-services
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
560912: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560912
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
package: python2.5
severity: serious
tags: security

Hi,

The following CVE (Common Vulnerabilities & Exposures) ids were
published for expat.  I have determined that this package embeds a
vulnerable copy of xmlparse.c and xmltok_impl.c.  However, since this is
a mass bug filing (due to so many packages embedding expat), I have
not had time to determine whether the vulnerable code is actually
present in any of the binary packages derived from this source package.
Please determine whether this is the case. If the binary packages are
not affected, please feel free to close the bug with a message
containing the details of what you did to check.

CVE-2009-3560[0]:
| The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1,
| as used in the XML-Twig module for Perl, allows context-dependent
| attackers to cause a denial of service (application crash) via an XML
| document with malformed UTF-8 sequences that trigger a buffer
| over-read, related to the doProlog function in lib/xmlparse.c, a
| different vulnerability than CVE-2009-2625 and CVE-2009-3720.

CVE-2009-3720[1]:
| The updatePosition function in lib/xmltok_impl.c in libexpat in Expat
| 2.0.1, as used in Python, PyXML, w3c-libwww, and other software,
| allows context-dependent attackers to cause a denial of service
| (application crash) via an XML document with crafted UTF-8 sequences
| that trigger a buffer over-read, a different vulnerability than
| CVE-2009-2625.

These issues also affect old versions of expat, so this package in etch
and lenny is very likely affected.  This is a low-severity security
issue, so DSAs will not be issued to correct these problems.  However,
you can optionally submit a proposed-update to the release team for
inclusion in the next stable point releases.  If you plan to do this, 
please open new bugs and include the security tag so we are aware that
you are working on that.

For further information see [0],[1],[2],[3].  In particular, [2] and [3]
are links to the patches for CVE-2009-3560 and CVE-2009-3720
respectively. Note that the ideal solution would be to make use of the
system expat so only one package will need to be updated for future
security issues. Preferably in your update to unstable, alter your
package to make use of the system expat.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3560
    http://security-tracker.debian.org/tracker/CVE-2009-3560
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3720
    http://security-tracker.debian.org/tracker/CVE-2009-3720
[2]
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.165
[3]
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&r2=1.15&view=patch



--- End Message ---
--- Begin Message ---
Source: python2.5
Source-Version: 2.5.4-3.1

We believe that the bug you reported is fixed in the latest version of
python2.5, which is due to be installed in the Debian FTP archive:

idle-python2.5_2.5.4-3.1_all.deb
  to main/p/python2.5/idle-python2.5_2.5.4-3.1_all.deb
python2.5-dbg_2.5.4-3.1_i386.deb
  to main/p/python2.5/python2.5-dbg_2.5.4-3.1_i386.deb
python2.5-dev_2.5.4-3.1_i386.deb
  to main/p/python2.5/python2.5-dev_2.5.4-3.1_i386.deb
python2.5-examples_2.5.4-3.1_all.deb
  to main/p/python2.5/python2.5-examples_2.5.4-3.1_all.deb
python2.5-minimal_2.5.4-3.1_i386.deb
  to main/p/python2.5/python2.5-minimal_2.5.4-3.1_i386.deb
python2.5_2.5.4-3.1.diff.gz
  to main/p/python2.5/python2.5_2.5.4-3.1.diff.gz
python2.5_2.5.4-3.1.dsc
  to main/p/python2.5/python2.5_2.5.4-3.1.dsc
python2.5_2.5.4-3.1_i386.deb
  to main/p/python2.5/python2.5_2.5.4-3.1_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Giuseppe Iuculano <[email protected]> (supplier of updated python2.5 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sun, 24 Jan 2010 12:48:21 +0100
Source: python2.5
Binary: python2.5 python2.5-minimal python2.5-examples python2.5-dev 
idle-python2.5 python2.5-dbg
Architecture: source all i386
Version: 2.5.4-3.1
Distribution: unstable
Urgency: high
Maintainer: Matthias Klose <[email protected]>
Changed-By: Giuseppe Iuculano <[email protected]>
Description: 
 idle-python2.5 - An IDE for Python (v2.5) using Tkinter
 python2.5  - An interactive high-level object-oriented language (version 2.5)
 python2.5-dbg - Debug Build of the Python Interpreter (version 2.5)
 python2.5-dev - Header files and a static library for Python (v2.5)
 python2.5-examples - Examples for the Python language (v2.5)
 python2.5-minimal - A minimal subset of the Python language (version 2.5)
Closes: 560912
Changes: 
 python2.5 (2.5.4-3.1) unstable; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * Fix two denial-of-service vulnerabilities: CVE-2009-3560 and CVE-2009-3720.
     (Closes: #560912)
Checksums-Sha1: 
 8e1c0a4808ec8a7d8aab751ac7309d19c0c0fad5 1846 python2.5_2.5.4-3.1.dsc
 f956b5afca5d3209cecf7af7aa6c87ac9b6335a1 212721 python2.5_2.5.4-3.1.diff.gz
 67b57d15b1facba6d38a33adf5bceacb0bacb1e1 650886 
python2.5-examples_2.5.4-3.1_all.deb
 f3470bcbf09e484698dca5a09fbec84866b8e1bc 67988 idle-python2.5_2.5.4-3.1_all.deb
 b54d0daee1706cc5e111ebfbcbda5d73b864f0c3 2916454 python2.5_2.5.4-3.1_i386.deb
 7bb434bf6e3ad17fea9eafea032828e5082c1b88 1199946 
python2.5-minimal_2.5.4-3.1_i386.deb
 dee6bc0cc9990a3f9cd989cd5abd9b7ed0174f53 1883920 
python2.5-dev_2.5.4-3.1_i386.deb
 6b55954955aff1584980b82f17be0241eaad7706 7334344 
python2.5-dbg_2.5.4-3.1_i386.deb
Checksums-Sha256: 
 4d30dc758cb59ba0b6e16d1cdf0e00695a15bf3dc0e28825742f0d1a2bbc2053 1846 
python2.5_2.5.4-3.1.dsc
 1ccce42d58818492f79067daabb2dca7a8e12d52016b1fd0bd642d7487e160c2 212721 
python2.5_2.5.4-3.1.diff.gz
 5fe3dd0611e20cab860576171b6814444efbea79dd0b6d17302a192f5e0a77ca 650886 
python2.5-examples_2.5.4-3.1_all.deb
 c9149cb22b22a42d8f54e0b2b5773df8f9b69fa8507476eb929363ece3c603fb 67988 
idle-python2.5_2.5.4-3.1_all.deb
 1e714176684c0ecf737d682735a1d8a4a3894c1a8c352e0b97117c3f883773e5 2916454 
python2.5_2.5.4-3.1_i386.deb
 f699c241db41904179bad7462e1de9042719852edc16d87bd9aab0918667a587 1199946 
python2.5-minimal_2.5.4-3.1_i386.deb
 7e0a29a033f1e175b38376d24cfd7271f3272d2451740a645bd800c4383f8588 1883920 
python2.5-dev_2.5.4-3.1_i386.deb
 7889bd0cf611a47ac1f0c50ee58536974219b37c01017305c2b9a941b35b7788 7334344 
python2.5-dbg_2.5.4-3.1_i386.deb
Files: 
 f15b697b9f7a003580b1c3d697345ac0 1846 python optional python2.5_2.5.4-3.1.dsc
 3b9ef5d1dbb4e68e5c899b71b92819be 212721 python optional 
python2.5_2.5.4-3.1.diff.gz
 ec8467b92e09ea8b646853e980bdb7a5 650886 python optional 
python2.5-examples_2.5.4-3.1_all.deb
 dd6b31a88cc1de3db8b412b6bcd3f945 67988 python optional 
idle-python2.5_2.5.4-3.1_all.deb
 ce61850420edf36568fafdc55b09af4c 2916454 python optional 
python2.5_2.5.4-3.1_i386.deb
 1972cd12839f7a8aa9b66f3b64e706b3 1199946 python optional 
python2.5-minimal_2.5.4-3.1_i386.deb
 18f5dd1fd60c08acdc9f54b7e2b957ed 1883920 python optional 
python2.5-dev_2.5.4-3.1_i386.deb
 715a04d25f92f4858c041c6a502bfb60 7334344 python extra 
python2.5-dbg_2.5.4-3.1_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAktcXMAACgkQNxpp46476aoTXwCfdvcrgoQfxsyj5QlkBe4xzEqs
GecAnAi4b9HpK43sBbImlReF4fORqaFx
=lLL7
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to