Your message dated Tue, 02 Aug 2022 20:16:13 +0000
with message-id <[email protected]>
and subject line Bug#769938: fixed in procmail 3.22-26+deb10u1
has caused the Debian Bug report #769938,
regarding procmail: NULL pointer dereference
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
769938: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769938
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: procmail
Version: 3.22-22
Usertags: afl

If there's no \n at all in the mail, or if the "From " line contains null byte, procmail dereferences NULL pointer:

$ printf 'From ' | procmail -d jwilk
Segmentation fault


This bug was brought to you by American fuzzy lop:
http://lcamtuf.coredump.cx/afl/

-- System Information:
Debian Release: jessie/sid
 APT prefers unstable
 APT policy: (990, 'unstable'), (500, 'experimental')
Architecture: i386 (x86_64)
Foreign Architectures: amd64

Kernel: Linux 3.2.0-4-amd64 (SMP w/2 CPU cores)
Locale: LANG=C, LC_CTYPE=pl_PL.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages procmail depends on:
ii  libc6  2.19-13

Versions of packages procmail recommends:
ii  esmtp-run [mail-transport-agent]  1.2-12
ii  fetchmail                         6.3.26-1+b1

--
Jakub Wilk

--- End Message ---
--- Begin Message ---
Source: procmail
Source-Version: 3.22-26+deb10u1
Done: Santiago Vila <[email protected]>

We believe that the bug you reported is fixed in the latest version of
procmail, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Santiago Vila <[email protected]> (supplier of updated procmail package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sun, 31 Jul 2022 20:10:00 +0200
Source: procmail
Architecture: source
Version: 3.22-26+deb10u1
Distribution: buster
Urgency: medium
Maintainer: Santiago Vila <[email protected]>
Changed-By: Santiago Vila <[email protected]>
Closes: 769938
Changes:
 procmail (3.22-26+deb10u1) buster; urgency=medium
 .
   * Fix NULL pointer dereference. Closes: #769938.
     Reported by Jakub Wilk using American Fuzzy Lop.
     Patch from Stephen R. van den Berg.
Checksums-Sha1:
 26b2335c4ff2c4e6478d7984d627493807d20309 1352 procmail_3.22-26+deb10u1.dsc
 8eab2489620bfea156375c4a3eed07117e47fc15 20264 
procmail_3.22-26+deb10u1.debian.tar.xz
 2ea78a30441abdd4ae478079e11cbe61f0b16f2e 3827 
procmail_3.22-26+deb10u1_source.buildinfo
Checksums-Sha256:
 58f0539d391d7b280190e0f4131b61fdcfe6c9597e55391c60c1e85b6a34b394 1352 
procmail_3.22-26+deb10u1.dsc
 79cc2a0e11d1e90116b87f1cc073d3836eaa2fce4e7b293715ca00753b00c147 20264 
procmail_3.22-26+deb10u1.debian.tar.xz
 78f144116655af58217faada89c39b9358ee3dcf0dd39d4fba9a2653f567533c 3827 
procmail_3.22-26+deb10u1_source.buildinfo
Files:
 2f369f8116963e28946ce5e5baa7b1af 1352 mail standard 
procmail_3.22-26+deb10u1.dsc
 9f746f00b1b079a483e49d4a6ee26f86 20264 mail standard 
procmail_3.22-26+deb10u1.debian.tar.xz
 a5b5a4f603eafecfd25b72c2d291c4ff 3827 mail standard 
procmail_3.22-26+deb10u1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEE1Uw7+v+wQt44LaXXQc5/C58bizIFAmLmxw8ACgkQQc5/C58b
izKBZAf/Qgmn45iA6LKWm/o422J636lukMJy44Phd7q9HyrhsPDKJm2N78ETZ5UO
spM4SRw/nNaj+PkBm7ijgND0T/UBXC/qCmuKapNGGZQXknxJoxsf2BKHtc3gbgK0
xHpNkHYKhb8a4z78jrDik0byXUuETf60jDvHbilSk+/UhCw/ikU3nRAS70Mf6O2C
/VIsvX1tI8qQIQD2kL28PVrFtCEb47Xn7dyiNX2Pl9dVGZU74cSoKRS36DVG37IL
TaUcsUZadbWggZzQUVr/j0lSx9gtvaoNGUr9f2MoQYFlY1Gaw07EJIPZTo8BpKQY
bipCPmdFEEjrCMSz+CFUXmrbt+GHJQ==
=/CIt
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to