Your message dated Fri, 30 Mar 2018 19:49:17 +0000
with message-id <[email protected]>
and subject line Bug#887129: fixed in miniupnpd 1.8.20140523-4.1+deb9u1
has caused the Debian Bug report #887129,
regarding miniupnpd: CVE-2017-1000494
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
887129: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=887129
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: miniupnpd
Version: 1.8.20140523-4
Severity: important
Tags: security upstream
Forwarded: https://github.com/miniupnp/miniupnp/issues/268
Hi,
the following vulnerability was published for miniupnpd.
CVE-2017-1000494[0]:
| Uninitialized stack variable vulnerability in NameValueParserEndElt
| (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause
| Denial of Service (Segmentation fault and Memory Corruption) or
| possibly have unspecified other impact
To demonstrate the issue one can compile miniupnpd, removing
hardening and addint noopt at teast and triggering the segfault by the
reproducers provided in the upstream issue.
Adapting the upstream commits [2], [3] to the older version seem to
adress the issue, please double check again.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2017-1000494
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000494
[1] https://github.com/miniupnp/miniupnp/issues/268
[2]
https://github.com/miniupnp/miniupnp/commit/7aeb624b44f86d335841242ff427433190e7168a
[3]
https://github.com/miniupnp/miniupnp/commit/a0573e251817ec090a8c9f9f41b56d720c835a6c
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: miniupnpd
Source-Version: 1.8.20140523-4.1+deb9u1
We believe that the bug you reported is fixed in the latest version of
miniupnpd, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated miniupnpd package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Wed, 07 Feb 2018 12:18:50 +0100
Source: miniupnpd
Binary: miniupnpd
Architecture: source amd64
Version: 1.8.20140523-4.1+deb9u1
Distribution: stretch
Urgency: medium
Maintainer: Thomas Goirand <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Description:
miniupnpd - UPnP and NAT-PMP daemon for gateway routers
Closes: 887129
Changes:
miniupnpd (1.8.20140523-4.1+deb9u1) stretch; urgency=medium
.
* Apply patch from upstream for CVE-2017-1000494 (Closes: #887129).
Checksums-Sha1:
ec5c353a732cc20aceb5e40fc043786fff291549 1973
miniupnpd_1.8.20140523-4.1+deb9u1.dsc
358b43f24952eb96801f6d7610c83f4adc270c79 18568
miniupnpd_1.8.20140523-4.1+deb9u1.debian.tar.xz
8a578348b186dff81e05b22ffb2f0430732e5545 6135
miniupnpd_1.8.20140523-4.1+deb9u1_amd64.buildinfo
05793effd67e8fe78b521d1e50704069bbc926c2 87014
miniupnpd_1.8.20140523-4.1+deb9u1_amd64.deb
Checksums-Sha256:
f47fb766e4560decb6dc74b2b62f93138fa96088574c1587d352d093af66358c 1973
miniupnpd_1.8.20140523-4.1+deb9u1.dsc
937bc48a02ff85699c08560512724ed0e53baba7bae985f8718adfe7355d58dc 18568
miniupnpd_1.8.20140523-4.1+deb9u1.debian.tar.xz
223e1d41ceccac67576829e568213780c9a757bd7bba632a494a35eacaa6e56d 6135
miniupnpd_1.8.20140523-4.1+deb9u1_amd64.buildinfo
28d5cd8b9235a38e1374081c15f9d9ad02f6cf6f83bbe13976541dca8c03c370 87014
miniupnpd_1.8.20140523-4.1+deb9u1_amd64.deb
Files:
221be2a1c8987fa6eea3c809ef87684b 1973 net optional
miniupnpd_1.8.20140523-4.1+deb9u1.dsc
ef0dd74e24ffe40dc9ddcd52a2a806d3 18568 net optional
miniupnpd_1.8.20140523-4.1+deb9u1.debian.tar.xz
358d548e2d60cfac24be60c589733648 6135 net optional
miniupnpd_1.8.20140523-4.1+deb9u1_amd64.buildinfo
c208f5c80e4ea17859c25d8aacc63154 87014 net optional
miniupnpd_1.8.20140523-4.1+deb9u1_amd64.deb
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEtKCq/KhshgVdBnYUq1PlA1hod6YFAlp64P0ACgkQq1PlA1ho
d6aomw/9FWm4+sbAFO3hSI9nilP+yXJAkb4pnBbj319gcG7DOWc5J/TP0Fjv0c7m
PNdSacaCqk0MktHguQ2zJ6NdNbsemgBujLfNBA0GwacErKM2sMEVAiTWJHmTCkVQ
5icKSLhvgfetQ4SG3wUN0mapXX+5jG5lbxBH6EeOrFBO4R0FBo7p8LSeQKqlgXD0
hGyuYQ5jh9bHEWyD6gq1QTSr1nYbZxAfEG2KDCDQUc8r5/ZIKkF9Z6/8kwiMPb9k
6YX0ZcBCauXcdkCI/Jg8utQxOejfZZ/YmUUEUown3KOkNc21YZk74Kfgv2rIANMB
4Z5P7la5Sw8v3KDMndgB/GQkwidHSJ5mFM/ZvqSkLcOWXRK7biRf1NU7XRYCbgfG
slP7ZZqJoHZMJx/rHSkWv7NW8tT3EP22NWEG0iRrLr4aEUtH0yivdP67oATreScO
SSDTKC4MiAna2pjFMKU0lMWwFbimIcoUhU1Xs+s+KxQoFJVbLgANbjfh5mLf4Y/u
gA8OLZdk58RhOy9KPWv6PxsFo7A6WXIWe3uSNc9qQcGPjK+k7WxrLkSg5lMM0Myw
LDbmX+E1Jvir19dtAn1FybX0RYjB/bXS9iTKRdGHhXFSsjc3T+uKoA9+EtKokOjY
9/FOy/wrNhG6Sm3JjtpUJ3e7NdsOdR5+kFaaQ6ci42LBDYBnYJM=
=tGBf
-----END PGP SIGNATURE-----
--- End Message ---