Your message dated Wed, 01 Jul 2015 18:33:57 +0000
with message-id <[email protected]>
and subject line Bug#784785: fixed in djvulibre 3.5.27.1-2
has caused the Debian Bug report #784785,
regarding libdjvulibre21: follows include chunk "-"
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
784785: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=784785
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: libdjvulibre21
Version: 3.5.27.1-1
Usertags: afl

DjVuLibre seems to follow include chunks pointing to the component file named "-", trying to read stuff from stdin:

$ djvudump incl-stdin.djvu
 FORM:DJVU [13]
   INCL [1]          Indirection chunk --> {-}

$ ddjvu incl-stdin.djvu
[blocks waiting for input]

$ ddjvu < incl-stdin.djvu
Segmentation fault


This bug was found using American fuzzy lop:
http://lcamtuf.coredump.cx/afl/

-- System Information:
Debian Release: stretch/sid
 APT prefers unstable
 APT policy: (990, 'unstable'), (500, 'experimental')
Architecture: i386 (x86_64)
Foreign Architectures: amd64

Kernel: Linux 3.2.0-4-amd64 (SMP w/2 CPU cores)
Locale: LANG=C, LC_CTYPE=pl_PL.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)

Versions of packages libdjvulibre21 depends on:
ii  libc6              2.19-18
ii  libdjvulibre-text  3.5.27.1-1
ii  libgcc1            1:5.1.1-4
ii  libjpeg62-turbo    1:1.3.1-12
ii  libstdc++6         5.1.1-4

--
Jakub Wilk

--- End Message ---
--- Begin Message ---
Source: djvulibre
Source-Version: 3.5.27.1-2

We believe that the bug you reported is fixed in the latest version of
djvulibre, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Barak A. Pearlmutter <[email protected]> (supplier of updated djvulibre package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Tue, 30 Jun 2015 09:18:13 +0300
Source: djvulibre
Binary: libdjvulibre-dev libdjvulibre21 libdjvulibre-text djvulibre-dbg 
djvulibre-desktop djview djview3 djvuserve djvulibre-bin
Architecture: source amd64 all
Version: 3.5.27.1-2
Distribution: unstable
Urgency: medium
Maintainer: Barak A. Pearlmutter <[email protected]>
Changed-By: Barak A. Pearlmutter <[email protected]>
Description:
 djview     - Transition package, djview3 to djview4
 djview3    - Transition package, djview3 to djview4
 djvulibre-bin - Utilities for the DjVu image format
 djvulibre-dbg - Debug symbols for the DjVu image format
 djvulibre-desktop - Desktop support for the DjVu image format
 djvuserve  - CGI program for unbundling DjVu files on the fly
 libdjvulibre-dev - Development files for the DjVu image format
 libdjvulibre-text - Linguistic support files for libdjvulibre
 libdjvulibre21 - Runtime support for the DjVu image format
Closes: 784785 784919 790371
Changes:
 djvulibre (3.5.27.1-2) unstable; urgency=medium
 .
   * merge upstream fix for string issue (closes: #784785)
   * merge upstream signed/unsigned fix (closes: #784919)
   * use gzip -n option for reproducible build (closes: #790371)
Checksums-Sha1:
 bfbb36532730d72d9cc3015751aa5b321728178d 2455 djvulibre_3.5.27.1-2.dsc
 fc2f176fcd31daddc37c8b5867ec2e32c80be73b 17096 
djvulibre_3.5.27.1-2.debian.tar.xz
 6b7094f9f3f1898f13710bc637a3342e7347e2b0 2398736 
libdjvulibre-dev_3.5.27.1-2_amd64.deb
 a04e1ccc599998b9247b70bd5bb6e93c2cf79851 594182 
libdjvulibre21_3.5.27.1-2_amd64.deb
 28f44c9f17b397172d7d1d83beec3352769af909 60220 
libdjvulibre-text_3.5.27.1-2_all.deb
 b6fa2fb5ced766fc0fbe1dd057e13d412190456a 4341980 
djvulibre-dbg_3.5.27.1-2_amd64.deb
 b1345b4c2d2606de8c3c080d74aa82893b331442 101298 
djvulibre-desktop_3.5.27.1-2_all.deb
 6fc1adbb995e3d3c6c236665f99589c84893ef36 16324 djview_3.5.27.1-2_amd64.deb
 59f89f24d906eff51da1de914870bd4028ab6d1b 16318 djview3_3.5.27.1-2_amd64.deb
 3ea492c6085c34c39b989b7dc5eead3bd3148786 33478 djvuserve_3.5.27.1-2_amd64.deb
 50c699e6a9ce4f7c5f0ccfd30e10dfa3e4c0b686 288688 
djvulibre-bin_3.5.27.1-2_amd64.deb
Checksums-Sha256:
 9bc70169cdcbf71ce40d5c301f21b295e4472612b796171ba7bd62cf1ef9c910 2455 
djvulibre_3.5.27.1-2.dsc
 68fa5f5fc6713833953d205c420b68ab4a54be48a29fa7568d78c9f64d59e94a 17096 
djvulibre_3.5.27.1-2.debian.tar.xz
 ee5373f270f74d95b5f905ea29ad748d3932818fd5e2f04e5b9803594bc85930 2398736 
libdjvulibre-dev_3.5.27.1-2_amd64.deb
 6813fd8b50c5cd4ab49dc7878ca17f68e61f44b4ab9122f47f6bb9070306f7a2 594182 
libdjvulibre21_3.5.27.1-2_amd64.deb
 95974d7556ca59676c32f856684afcc91cd5cfb6384bfba8eb8121cd286172ef 60220 
libdjvulibre-text_3.5.27.1-2_all.deb
 a2f90561a6de6ad28af8e01e66b2e21e3d8e2132542580f07b68272979b2352b 4341980 
djvulibre-dbg_3.5.27.1-2_amd64.deb
 56126155f4ec6ed976ea09b841142b4f748a27f5aeba3ca6f29a432390f0e563 101298 
djvulibre-desktop_3.5.27.1-2_all.deb
 3facd662a592ae7390c3495da57bc4875540a454f32357d6b23bbff2b64ee790 16324 
djview_3.5.27.1-2_amd64.deb
 311d9e108634e716ac75cca47e5dd005c767858011582d04ddf013fd7f4cb468 16318 
djview3_3.5.27.1-2_amd64.deb
 4d317326aa1d0566995106763a5086defa9dfd912e48e2b925c029c5da6fb993 33478 
djvuserve_3.5.27.1-2_amd64.deb
 8430591296c1f6578efdc4726ffea523ae33982c4978bafd6dbf87df10f6810a 288688 
djvulibre-bin_3.5.27.1-2_amd64.deb
Files:
 48bdb1fdf51ecc22c93357d37f08e771 2455 libs optional djvulibre_3.5.27.1-2.dsc
 1cf3a380969c896b5426cabff309a670 17096 libs optional 
djvulibre_3.5.27.1-2.debian.tar.xz
 e1f9e339f5927e2238623de1f586357a 2398736 libdevel optional 
libdjvulibre-dev_3.5.27.1-2_amd64.deb
 aada8c21054b2454e3521f799028a9e1 594182 libs optional 
libdjvulibre21_3.5.27.1-2_amd64.deb
 a967a8ba4056efb7bc690ccb4233d4b9 60220 libs optional 
libdjvulibre-text_3.5.27.1-2_all.deb
 6c0bb368b62bfa0a87ef6527196c285e 4341980 debug extra 
djvulibre-dbg_3.5.27.1-2_amd64.deb
 779e474ae9c986bcd6a911e60ded9888 101298 libs optional 
djvulibre-desktop_3.5.27.1-2_all.deb
 1fb085af9601d25b354ce2277bdc14af 16324 graphics optional 
djview_3.5.27.1-2_amd64.deb
 9c4c8b767042e2a0c0082a89199c6a2f 16318 graphics optional 
djview3_3.5.27.1-2_amd64.deb
 5e4703d504165631f703def47fa9631f 33478 web optional 
djvuserve_3.5.27.1-2_amd64.deb
 6b1956ad40bf0503814ffd7c55c55d7b 288688 graphics optional 
djvulibre-bin_3.5.27.1-2_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJVkjVWAAoJEBJbV0deGQ0Yv8AP/RUbGF/yGYGNIp5ZEDtPyhxu
/iGUzHI74FOtJHmwgR/U2MOlxKbjt1jSlGxc3oB/F6PB7pfYUtEnLhX2A4uPE7Y0
fu2Vt1TyfB0IJe8uk2jjm9901ADNMaCmJ/HzKxXVAdPRUO1bVbTRkr4883oKT3zV
AFIB3lTpRmfhFTm3uRNrIshunYlSmyl5JmwQGO9hwQAo9t1DVF3/PHavKndNkw+g
QqtrCRt6E1CLaSsThcjJVNj3N6154aGjhRRKeiiXzMF3KlYzKsAybr5ybwoqOHSf
9CnQCJOVzq2vPwsBLTzrWIrv+WAM1i5E6/5dQkInzvsAMbboHQRnWegCgNMC3fF1
fedFayCbTSftZvlMlbewEBRCQzjhD7wUqb7+XvArvZ3I6Z2l/1eappNa2Rdxq+pd
cMz7Bv1KXKbjgC2bGzTrWho9UZWSiLfMcj/aBrbiqNsR0Fu9A6szx1riZBipiJ9S
Z8KO39YSaiiyQfTlrOQe+WmNfu3dMIsSIOIjWeqamu/oYdRevTCTXKFCwIe3zgR7
fRS/JIVolS68JsgBG/h5+Lwzdg+IUTLHeDG4EFDaXdPWoY9k16jjpOMKGwRvLiMC
QJxP48/9KbWiPT4zEin9kQBenU+M0vuUr0IQb6161p9CANhdmpSCFxAHSP3tt5CF
edesscbxxCXzZqo/boHa
=shdh
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to