Your message dated Mon, 30 Sep 2019 21:32:09 +0000
with message-id <[email protected]>
and subject line Bug#931246: fixed in flightcrew 0.7.2+dfsg-13+deb10u1
has caused the Debian Bug report #931246,
regarding flightcrew: CVE-2019-13032
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
931246: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931246
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: flightcrew
Version: 0.7.2+dfsg-13
Severity: important
Tags: security upstream
Forwarded: https://github.com/Sigil-Ebook/flightcrew/issues/53
Control: found -1 0.7.2+dfsg-9

Hi,

The following vulnerability was published for flightcrew.

CVE-2019-13032[0]:
| An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL
| pointer dereference occurs in GetRelativePathToNcx() or
| GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to
| xc::XMLUri::isValidURI(). This affects third-party software (not
| Sigil) that uses FlightCrew as a library.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-13032
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13032
[1] https://github.com/Sigil-Ebook/flightcrew/issues/53

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: flightcrew
Source-Version: 0.7.2+dfsg-13+deb10u1

We believe that the bug you reported is fixed in the latest version of
flightcrew, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Francois Mazen <[email protected]> (supplier of updated flightcrew package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 08 Sep 2019 21:55:23 +0200
Source: flightcrew
Architecture: source
Version: 0.7.2+dfsg-13+deb10u1
Distribution: buster
Urgency: high
Maintainer: Mattia Rizzolo <[email protected]>
Changed-By: Francois Mazen <[email protected]>
Closes: 931246
Changes:
 flightcrew (0.7.2+dfsg-13+deb10u1) buster; urgency=high
 .
   * Fix CVE-2019-13241 for Buster.
   * Fix CVE-2019-13032 for Buster.  Closes: #931246
Checksums-Sha1:
 ff9d952c7411f13e7b7ec7892dafd8c9376f8c2a 2294 
flightcrew_0.7.2+dfsg-13+deb10u1.dsc
 417a119a8b4291d3f1edeeb7618b2baf3f17d490 13920 
flightcrew_0.7.2+dfsg-13+deb10u1.debian.tar.xz
 510a78f0d897d1c8e0c96a551516783cf6a589b9 10784 
flightcrew_0.7.2+dfsg-13+deb10u1_amd64.buildinfo
Checksums-Sha256:
 571edd0452f569fbc26766748c5e6ccf6817bbf598ad8aec61268979e6e0673f 2294 
flightcrew_0.7.2+dfsg-13+deb10u1.dsc
 e918547bfe337b043238bcb2546523cfff1a104d40d2f50682272e253a9ade8b 13920 
flightcrew_0.7.2+dfsg-13+deb10u1.debian.tar.xz
 cafc00e1a72ef216ee158cc8fbedbb15eed3c33f27514b1601a97259d4e215b0 10784 
flightcrew_0.7.2+dfsg-13+deb10u1_amd64.buildinfo
Files:
 01b5ee8079d8c95a98da721d1cff6c6d 2294 text optional 
flightcrew_0.7.2+dfsg-13+deb10u1.dsc
 6fe413a2f11784178767aee0e335b7bd 13920 text optional 
flightcrew_0.7.2+dfsg-13+deb10u1.debian.tar.xz
 82730061bbae17e56182189a77ebed3a 10784 text optional 
flightcrew_0.7.2+dfsg-13+deb10u1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEi3hoeGwz5cZMTQpICBa54Yx2K60FAl2HnWkACgkQCBa54Yx2
K60NpRAAnYIJ63wD8gyQDsCdwCwX4R6t75QBhOqPAPJHdSFBDvPbrUDUSSg3DrhM
PqMZUp/XufKvcBRPpoxuMpNd6wPB5TkstbA0zcLmhJBw0QPasXwLeqSoIrULJdwS
nKCuIQ9JyPsbuALXB6vtg1IataCEMxExHoSuJXd2QclUacxJkxXBWXfG7wr1CI97
mLPc1pWAPjryKtKze8na4BuUmNUxQu0iFT3Kfh9v3Qdid2s1S+aLBoL6StLjn1Be
2J3CcObkQLRp/OuzsYlY/gs/gTvwZOPESW1hXS5eDqPmUtL+AjTsJFgWYKJyhTgu
1wod/TJbBKd5o3AODdyvMiL0DcoQqUUVHVcYtjqRhhtaFgOmJ72dKyFYreVvzUHi
oBu+kYzg3kUtySiejFOPEd6HZyfqxfEYRmWyBrY58nVI9cPM/8fwwkg5lKvNvdHX
7qnGMyx3T5GT1lf1rtBwdj8QcvIEmW0QuB3/NlpYRcyCvOQJ7CS7ND98skegbzQ1
uzLM8YIZktJOod4hqoYWzpc+6LFtnTD+myLLS4xiPeCS+q9JzC8jdt6RpyLrvY8F
uOQQ9Dmbrh7c7lVhGTYiFcG+rQ/c1fSnLifRb7+5dpMz3w8qqS5v6SIcSNTFmm77
59H13lJbX84hoSytJ8u1kzCcMMtbTEmVkUkayDcDdQW0y+gzEw0=
=gh2w
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to