Your message dated Thu, 28 Dec 2023 21:20:46 +0000
with message-id <[email protected]>
and subject line Bug#947431: fixed in xerces-c 3.2.4+debian-1.1
has caused the Debian Bug report #947431,
regarding xerces-c: CVE-2018-1311: use-after-free vulnerability processing 
external DTD
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
947431: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=947431
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: xerces-c
Version: 3.2.2+debian-1
Severity: important
Tags: security upstream
Forwarded: https://issues.apache.org/jira/browse/XERCESC-2188
Control: found -1 3.1.4+debian-2+deb9u1
Control: found -1 3.1.4+debian-1

Hi,

The following vulnerability was published for xerces-c. There is no
upstream fix and only suggested mitigations, at time of writing the
bugreport.

CVE-2018-1311[0]:
| The Apache Xerces-C 3.0.0 to 3.2.2 XML parser contains a use-after-
| free error triggered during the scanning of external DTDs. This flaw
| has not been addressed in the maintained version of the library and
| has no current mitigation other than to disable DTD processing. This
| can be accomplished via the DOM using a standard parser feature, or
| via SAX using the XERCES_DISABLE_DTD environment variable.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-1311
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1311
[1] https://issues.apache.org/jira/browse/XERCESC-2188
[2] https://xerces.apache.org/xerces-c/secadv/CVE-2018-1311.txt
[3] https://marc.info/?l=xerces-c-users&m=157653840106914&w=2

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: xerces-c
Source-Version: 3.2.4+debian-1.1
Done: Guilhem Moulin <[email protected]>

We believe that the bug you reported is fixed in the latest version of
xerces-c, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Guilhem Moulin <[email protected]> (supplier of updated xerces-c package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 28 Dec 2023 21:17:42 +0100
Source: xerces-c
Architecture: source
Version: 3.2.4+debian-1.1
Distribution: unstable
Urgency: medium
Maintainer: William Blough <[email protected]>
Changed-By: Guilhem Moulin <[email protected]>
Closes: 947431
Changes:
 xerces-c (3.2.4+debian-1.1) unstable; urgency=medium
 .
   * Non-maintainer upload.
   * Backport upstream patches from 3.2.5:
     + Fix NetAccessorTest to exit with non-zero status in case of error.
     + Fix CVE-2018-1311: Use-after-free on external DTD scan.  This replaces
       RedHat's mitigation patch (which had a memory leak).
       Closes: #947431
Checksums-Sha1:
 2849a1185c65a8c07674ef9ef5eb0225bf800fa9 2342 xerces-c_3.2.4+debian-1.1.dsc
 c11c98b791b7edeb75a439c0bb5465adcb51b079 26336 
xerces-c_3.2.4+debian-1.1.debian.tar.xz
 a482889e6904055db109c520b55abb5d7ba2af06 11061 
xerces-c_3.2.4+debian-1.1_amd64.buildinfo
Checksums-Sha256:
 fd7af2d4652fe210ec114b1d6a41afb8ff656672ca4034ec52479879f68883f4 2342 
xerces-c_3.2.4+debian-1.1.dsc
 8629bb6b7eb9122d63b757e7d14e67861665533c6d33823fb318468cfe427a65 26336 
xerces-c_3.2.4+debian-1.1.debian.tar.xz
 adb9a5deb2e314b22ff3c589493be193bde38d3a184798b44c02f7ad6c233f83 11061 
xerces-c_3.2.4+debian-1.1_amd64.buildinfo
Files:
 436d000c5a8e2f416a8639b32c9e33d3 2342 libs optional 
xerces-c_3.2.4+debian-1.1.dsc
 e07a0f5a2bccc9872bb0e2e9c041c8c7 26336 libs optional 
xerces-c_3.2.4+debian-1.1.debian.tar.xz
 4116ac21ebe5e6325802400226d2a0b8 11061 libs optional 
xerces-c_3.2.4+debian-1.1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmWN2poACgkQ05pJnDwh
pVKbvxAArJVdOl69KC8UUVNxFk3Bhj35eNJW6CjrxX6JI2TG/8LmrHyqSkUeuK/w
KNtfN7lDxgxnPyehpCAyk7jE+4PxmJgFqfaN3tOCiPoIFYE3mgfouJqvyCkEvnzF
OOXrlVWFzpMn0Qb+m/Cc87bdChZh81vf2YGHIknMk9iwDeVY2JHPVhTRWDP9ZOg5
Bcfv92PSOm9XDNVwIx89/yIqWRuVcLqjpXDFJvjxp/O5LsBf3Dwzxjsl7STQfFwv
ubs8Gzh8O0aUl+kmF3X+swAhXK9GngQQXU6/xogdi9SZHpZ0nTmVitmNQYDg2Y8z
0eoCR7hjSJ6H1/0GAD0TW4gICQLcIzx2P4/YMCnQmHoe/AZ59sDrlMHU7mCOvDEy
z4jWu6zKTGzYiCy7ylmQDkDXnDwOpFKYijXyaueejskhQfnqqKMmPbbtaFWJOFsj
iowX9SIV3dex36v9pHtAwdAHGp7HqoAZ0Nqg4Wm3xGp/ARQRn7wus9smLTnhnCHc
/X73HYGDXRznKX1lTRTHB8PC7CLMmAFIirrQFFr6WZRg4FT9dlmjviUT+h3P2z3S
QhczgOgrUSV3ILp3Dw6isx1UUXzexSBcup3qt8PCXPBeFuEbtGIewbJNK0gxgScF
yfNgKXCX5c4q/QsCeNVn2FG2kSzSUVX+HMByii3aL9I49DeATdE=
=BSAM
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to