Your message dated Thu, 16 Feb 2012 12:22:12 +0100
with message-id <4f3ce6e4.6040...@phys.ethz.ch>
and subject line CVE-2007-6731, CVE-2007-6732: Multiple buffer overflows
has caused the Debian Bug report #546730,
regarding CVE-2007-6731, CVE-2007-6732: Multiple buffer overflows
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
546730: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=546730
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: xmp
Version: 2.0.4d-11
Severity: serious
Tags: security
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for xmp.
CVE-2007-6731[0]:
| Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers
| to execute arbitrary code via an OXM file with a negative value, which
| bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in
| misc/oxm.c, leading to a buffer overflow.
This is already fixed in debian unstable.
Please coordinate with the security team (t...@security.debian.org) to
prepare packages for the stable and oldstable releases.
If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6731
http://security-tracker.debian.net/tracker/CVE-2007-6731
Cheers,
Giuseppe.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAkqvdDoACgkQNxpp46476aot0gCeKr7w18XoPG1yyirwc2sfsnNC
88kAn3fVbLhhpWt8EgFAI/dvxWdrllp0
=WBlF
-----END PGP SIGNATURE-----
--- End Message ---
--- Begin Message ---
this is not relevant anymore.
gurkan
--- End Message ---