Your message dated Sun, 13 Dec 2009 18:16:48 +0000
with message-id <e1njszw-0000ky...@ries.debian.org>
and subject line Bug#560945: fixed in vxl 1.13.0-2
has caused the Debian Bug report #560945,
regarding CVE-2009-3560 and CVE-2009-3720 denial-of-services
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
560945: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560945
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
package: vxl
severity: serious
tags: security

Hi,

The following CVE (Common Vulnerabilities & Exposures) ids were
published for expat.  I have determined that this package embeds a
vulnerable copy of xmlparse.c and xmltok_impl.c.  However, since this is
a mass bug filing (due to so many packages embedding expat), I have
not had time to determine whether the vulnerable code is actually
present in any of the binary packages derived from this source package.
Please determine whether this is the case. If the binary packages are
not affected, please feel free to close the bug with a message
containing the details of what you did to check.

CVE-2009-3560[0]:
| The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1,
| as used in the XML-Twig module for Perl, allows context-dependent
| attackers to cause a denial of service (application crash) via an XML
| document with malformed UTF-8 sequences that trigger a buffer
| over-read, related to the doProlog function in lib/xmlparse.c, a
| different vulnerability than CVE-2009-2625 and CVE-2009-3720.

CVE-2009-3720[1]:
| The updatePosition function in lib/xmltok_impl.c in libexpat in Expat
| 2.0.1, as used in Python, PyXML, w3c-libwww, and other software,
| allows context-dependent attackers to cause a denial of service
| (application crash) via an XML document with crafted UTF-8 sequences
| that trigger a buffer over-read, a different vulnerability than
| CVE-2009-2625.

These issues also affect old versions of expat, so this package in etch
and lenny is very likely affected.  This is a low-severity security
issue, so DSAs will not be issued to correct these problems.  However,
you can optionally submit a proposed-update to the release team for
inclusion in the next stable point releases.  If you plan to do this, 
please open new bugs and include the security tag so we are aware that
you are working on that.

For further information see [0],[1],[2],[3].  In particular, [2] and [3]
are links to the patches for CVE-2009-3560 and CVE-2009-3720
respectively. Note that the ideal solution would be to make use of the
system expat so only one package will need to be updated for future
security issues. Preferably in your update to unstable, alter your
package to make use of the system expat.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3560
    http://security-tracker.debian.org/tracker/CVE-2009-3560
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3720
    http://security-tracker.debian.org/tracker/CVE-2009-3720
[2]
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.165
[3]
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&r2=1.15&view=patch



--- End Message ---
--- Begin Message ---
Source: vxl
Source-Version: 1.13.0-2

We believe that the bug you reported is fixed in the latest version of
vxl, which is due to be installed in the Debian FTP archive:

libvxl1-dev_1.13.0-2_amd64.deb
  to main/v/vxl/libvxl1-dev_1.13.0-2_amd64.deb
libvxl1.13_1.13.0-2_amd64.deb
  to main/v/vxl/libvxl1.13_1.13.0-2_amd64.deb
vxl_1.13.0-2.diff.gz
  to main/v/vxl/vxl_1.13.0-2.diff.gz
vxl_1.13.0-2.dsc
  to main/v/vxl/vxl_1.13.0-2.dsc



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 560...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Mathieu Malaterre <mathieu.malate...@gmail.com> (supplier of updated vxl 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sun, 13 Dec 2009 11:49:36 +0100
Source: vxl
Binary: libvxl1.13 libvxl1-dev
Architecture: source amd64
Version: 1.13.0-2
Distribution: unstable
Urgency: low
Maintainer: Debian Med Packaging Team 
<debian-med-packag...@lists.alioth.debian.org>
Changed-By: Mathieu Malaterre <mathieu.malate...@gmail.com>
Description: 
 libvxl1-dev - C++ Libraries for Computer Vision Research
 libvxl1.13 - C++ Libraries for Computer Vision Research
Closes: 560945
Changes: 
 vxl (1.13.0-2) unstable; urgency=low
 .
   * Use system expat (Closes: #560945)
Checksums-Sha1: 
 2983733be808a6482b7e0511c1caa5cb9d6965e6 1361 vxl_1.13.0-2.dsc
 e211ac84e101a66f57945e10a1a172f996df2a8e 6637 vxl_1.13.0-2.diff.gz
 48c7e7ba5a07d37082ef20d2c2a5e03bb8da8476 1822402 libvxl1.13_1.13.0-2_amd64.deb
 33bdcaf4698419c81269d58cd03b9e749997cc16 407582 libvxl1-dev_1.13.0-2_amd64.deb
Checksums-Sha256: 
 2238b65d39202f93a02ae424fa1ad66a81b0898be288ab4c7c4bb23c14d09ae2 1361 
vxl_1.13.0-2.dsc
 3635abd958cf6a87a68b1948b11da56517a76aebea5228f6e257fecce65de95e 6637 
vxl_1.13.0-2.diff.gz
 73c07f6355bb5ed2f425ff975537f3e81de820df897f07d96c06cf6b7b1a51fa 1822402 
libvxl1.13_1.13.0-2_amd64.deb
 f2cd303623ac803e6d828a01fb4f49bdf0051508330238d17f804e325fddc248 407582 
libvxl1-dev_1.13.0-2_amd64.deb
Files: 
 2b06009b6d04470a485e895ff6c7825c 1361 science optional vxl_1.13.0-2.dsc
 07fba075bf5c4e5c1f587d9a4e65b220 6637 science optional vxl_1.13.0-2.diff.gz
 3cc2f26555224a46d6031af6f9e574bb 1822402 libs optional 
libvxl1.13_1.13.0-2_amd64.deb
 2fb8ee6dc9f1bbe489339e10f6331f1d 407582 libdevel optional 
libvxl1-dev_1.13.0-2_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkslKmMACgkQEpFKvQ6iPytiwwCdECP1OoY0Anan64tkxSIvj6Sz
DDoAn1+uC+f1g5VdtUzy/3kIA9fQhQI9
=M6b4
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to