Your message dated Fri, 29 Nov 2019 03:06:05 +0000
with message-id <[email protected]>
and subject line Bug#944605: fixed in python-psutil 5.6.7-1
has caused the Debian Bug report #944605,
regarding python-psutil: CVE-2019-18874
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
944605: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=944605
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: python-psutil
Version: 5.5.1-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/giampaolo/psutil/pull/1616
Hi,
The following vulnerability was published for python-psutil.
CVE-2019-18874[0]:
| psutil (aka python-psutil) through 5.6.5 can have a double free. This
| occurs because of refcount mishandling within a while or for loop that
| converts system data into a Python object.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2019-18874
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18874
[1] https://github.com/giampaolo/psutil/pull/1616
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: python-psutil
Source-Version: 5.6.7-1
We believe that the bug you reported is fixed in the latest version of
python-psutil, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Sandro Tosi <[email protected]> (supplier of updated python-psutil package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Thu, 28 Nov 2019 21:43:56 -0500
Source: python-psutil
Architecture: source
Version: 5.6.7-1
Distribution: unstable
Urgency: medium
Maintainer: Sandro Tosi <[email protected]>
Changed-By: Sandro Tosi <[email protected]>
Closes: 944605
Changes:
python-psutil (5.6.7-1) unstable; urgency=medium
.
[ Ondřej Nový ]
* Use debhelper-compat instead of debian/compat.
* Bump Standards-Version to 4.4.1.
.
[ Sandro Tosi ]
* New upstream release, fix CVE-2019-18874; Closes: #944605
* debian/patches/0001-dont-depend-on-install-when-running-tests.patch
- refresh patch to new upstream code
Checksums-Sha1:
1aca93dbdbe537a2689208556635b31948d0176d 2461 python-psutil_5.6.7-1.dsc
6b1b0877b866a6ae86bc9a4d25fff747d2ad646b 312072 python-psutil_5.6.7.orig.tar.xz
836ab5f23c363ff893e7269731e0bc23b7ac2961 6236
python-psutil_5.6.7-1.debian.tar.xz
cc2fe2fcac5b8464f9f2bd0563ff2fbed1be9ee7 9173
python-psutil_5.6.7-1_source.buildinfo
Checksums-Sha256:
ee2bafcb5c1815fe02d0b58cac5926bce2b9374f563aad960bf69054442e1392 2461
python-psutil_5.6.7-1.dsc
9dc8822b4129c087d2a7c4baf331c28aa40c1645d3cdf75ed2328783a600d704 312072
python-psutil_5.6.7.orig.tar.xz
7a7eb82ea0fe6e959412d42ee1c2b458c6d6d273aa23dfa41c94b6151a3c659a 6236
python-psutil_5.6.7-1.debian.tar.xz
c8717880fa879716e99ddee317f8aabd54499f453f8253cd2eec053273e8ccc5 9173
python-psutil_5.6.7-1_source.buildinfo
Files:
eec192b082ad4b16b9b1857ab0a29ce7 2461 python optional python-psutil_5.6.7-1.dsc
f37459c0156160806c6a2f7527538d8c 312072 python optional
python-psutil_5.6.7.orig.tar.xz
80a06d3b95d9f9003bf66d009e5ac436 6236 python optional
python-psutil_5.6.7-1.debian.tar.xz
a444aaa90ba5aabb16223b2ebac4811b 9173 python optional
python-psutil_5.6.7-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEufrTGSrz5KUwnZ05h588mTgBqU8FAl3ghnUACgkQh588mTgB
qU9Y3A/9Fk6dn/3WoH6h45XHd6axDtLg0Z9X7QFgUMTlVP7YBmrfdDGrEERA2A+d
yaF8lp3NLZfPqArrWAkWDku1aXDAxJRNG//LU4lsR27C/N5yPkZgPLQ+dKxE1Sfw
IFlMofbsQxPsenZ11BS6uQzEz2yFFIFMnTZniCyo3U1LOtEyvtfSvMFtWD6675py
FJs6LRDDYuF9flyQTe78KdHhjLpA8zLLJeR4P79bR2JoZn8Hga8lig4TYnRgnbP1
hE6pYirfhJCHgFamzagHXD1/S2brAoeTlTRLSTe58FDJ388/K7ayrp/nmThXOAOa
CupIGdSLukiHYAdrujS+qoKKi61wRm5JWahfDxsZGKTCsAtYzfg8CmgquOKTzTIB
LxnfImM1IkVw+ZV0/OAok317oUca0QAR+QKhW2aMyIHa7332h+/6/UhurLBFfivf
T68TSQueyoivp3gpi1FoL66b1/wz7yFl4MakPSy+3cmFZqjTR13djbhMYAfP+8DV
FHHNNkCZr5J+xxoRshbVl899kPth6hgZ8q9q6HTUILEhuedywAMCfHwtmpYsOMwi
GK/2S/6JQ2ZoIn1uuhbS4RFnDFwTCJU5FGDuBaSwxQxRNvFYmMIdoNSciHOX2p3z
PvQooIgpOOWoK0rXYGuQTK7p5inectZM25nbdbTXRjvm8NVvyg0=
=KQx1
-----END PGP SIGNATURE-----
--- End Message ---