Your message dated Sun, 16 Apr 2017 10:04:07 +0000
with message-id <e1czh2n-00091x...@fasolo.debian.org>
and subject line Bug#860314: fixed in icu 57.1-6
has caused the Debian Bug report #860314,
regarding icu: CVE-2017-7867 CVE-2017-7868: Heap-buffer-overflow in
utf8TextAccess
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
860314: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860314
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: icu
Version: 52.1-8
Severity: grave
Tags: patch security upstream
Justification: user security hole
Forwarded: https://ssl.icu-project.org/trac/ticket/12888
*** /tmp/icu.reportbug
Package: icu
X-Debbugs-CC: t...@security.debian.org
secure-testing-t...@lists.alioth.debian.org
Severity: grave
Tags: security
Hi,
the following vulnerability was published for icu.
CVE-2017-7867[0]:
| International Components for Unicode (ICU) for C/C++ before 2017-02-13
| has an out-of-bounds write caused by a heap-based buffer overflow
| related to the utf8TextAccess function in common/utext.cpp and the
| utext_setNativeIndex* function.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2017-7867
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7867
[1] https://ssl.icu-project.org/trac/ticket/12888 (closed unfortunately)
[2] https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=213
[3] https://ssl.icu-project.org/trac/changeset/39671
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: icu
Source-Version: 57.1-6
We believe that the bug you reported is fixed in the latest version of
icu, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 860...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <g...@debian.org> (supplier of updated icu package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Sun, 16 Apr 2017 08:50:52 +0000
Source: icu
Binary: libicu57 libicu57-dbg libicu-dev icu-devtools icu-devtools-dbg icu-doc
Architecture: source amd64 all
Version: 57.1-6
Distribution: unstable
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <g...@debian.org>
Changed-By: Laszlo Boszormenyi (GCS) <g...@debian.org>
Description:
icu-devtools - Development utilities for International Components for Unicode
icu-devtools-dbg - Development utilities for International Components for
Unicode (d
icu-doc - API documentation for ICU classes and functions
libicu-dev - Development files for International Components for Unicode
libicu57 - International Components for Unicode
libicu57-dbg - International Components for Unicode (debug symbols)
Closes: 860314
Changes:
icu (57.1-6) unstable; urgency=high
.
* Backport upstream security fix for CVE-2017-7867 and CVE-2017-7868,
heap-buffer-overflow in utf8TextAccess (closes: #860314).
Checksums-Sha1:
08e69c2fbd860d8fb6887775b50f0142f205d82f 2105 icu_57.1-6.dsc
4fef403bae2b650734a986432a6306b6ab0db84d 32768 icu_57.1-6.debian.tar.xz
5a30b59856c96b4c0c4fad3cfd422b041411ffa4 642958
icu-devtools-dbg_57.1-6_amd64.deb
cce08540d1e80737addbeae6861cab7b6505dcdf 177570 icu-devtools_57.1-6_amd64.deb
a285e65cb4332d87893afbc65922dc80b33a45b6 2396862 icu-doc_57.1-6_all.deb
8bd6f06ceecd1c68d5dad8b3b88e2d875a4832a8 7583 icu_57.1-6_amd64.buildinfo
04701fb58b11fa7116a290de8287fa17a86442a9 16481438 libicu-dev_57.1-6_amd64.deb
90ee12b652bbcb12cc5d63a0f433aff77cd3c57f 7368098 libicu57-dbg_57.1-6_amd64.deb
cae0a3bdb91b12cb7673a4c84da1978055233bcd 7701442 libicu57_57.1-6_amd64.deb
Checksums-Sha256:
6d3979c7e13e23d4de31e0ff3b83c34e4824e4982cfed9887b21ab6b6c272e6b 2105
icu_57.1-6.dsc
9c1239e6c395aa44880617a8f67f1f9936a9536ad0c85b8c0ceedf4c0bf40819 32768
icu_57.1-6.debian.tar.xz
3d78289a964e9139a1d1754e2e6074236e9c776a32cb5471dd0e7cc4735c97f5 642958
icu-devtools-dbg_57.1-6_amd64.deb
839f2ac21cbb7f6db4047ee8734249be1d74af6de16f5af10abcb06d546889a4 177570
icu-devtools_57.1-6_amd64.deb
2dc20c33b56080c5872c7c6a68e2f468e2e9efe82975a1320d624ee6081368a1 2396862
icu-doc_57.1-6_all.deb
5bc7a1a2e2b14ddb9331f775fe622e89a91ad56e2dd3efe06dd9ed796b194ba8 7583
icu_57.1-6_amd64.buildinfo
19c854784e9bddece8f184c1d94925e2e6d577b0e2e58f0b649e17d5b10dbd13 16481438
libicu-dev_57.1-6_amd64.deb
edb8480e5bbe5a6d0a5cbeb7cf0b12eaeabeb7f170085f5c7e1a16e85accdca5 7368098
libicu57-dbg_57.1-6_amd64.deb
6d44f35bfc8b9a4c9040a420b72fa41fdb533490025c301d67c59ae8ff6d23f1 7701442
libicu57_57.1-6_amd64.deb
Files:
e0b55515aa0a6b7c40d5d24f7e7dd3f9 2105 libs optional icu_57.1-6.dsc
9ec396ee896de8d57ae92722403e3610 32768 libs optional icu_57.1-6.debian.tar.xz
7d65c05a03f0d596b6d2b60c88ea769d 642958 debug extra
icu-devtools-dbg_57.1-6_amd64.deb
d28cec4ce656674580cdfba77002cf1d 177570 libdevel optional
icu-devtools_57.1-6_amd64.deb
f58ce0d9229e7b27dbc7a4d1a0c7fe6f 2396862 doc optional icu-doc_57.1-6_all.deb
f60f491a8ea1299dad758bda071558a0 7583 libs optional icu_57.1-6_amd64.buildinfo
8de9d0cffc8ee9e26d528a6972aa6bc4 16481438 libdevel optional
libicu-dev_57.1-6_amd64.deb
226ac83c6d60e664f4ae5a0df2e4bf79 7368098 debug extra
libicu57-dbg_57.1-6_amd64.deb
5dcf0e06d17a7da272497b202c956131 7701442 libs optional
libicu57_57.1-6_amd64.deb
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAljzO7gACgkQ3OMQ54ZM
yL+tMBAAms673oeipmAnZsV4BHhErMnvlhwQx6M5VsYfrI3GZ+wDTztlPjtqJUby
kXuPdM8Xm64V0uZcWZwVXraeP0GtlKm/aF/S2TMSJBsKO0Hp32hKY3dlet2iv9DG
ac04bLQcmpI5p3w3cDq7g9Hm8DRhm8iiyAlxt7lZik1OF0qHR8lkMND4MBtUwaoC
tk7sA6cFqfaIyXF4viGOFarLEB7+q1HcSnSw0Avp5RXMf8wPBUkyp1S+7Gx0aU38
MZklE5iQfR2SxVCduzXVrrknId2NdpulU4YffdNlmJ1+gnMawQJ73hNsbs8WVDKR
Gn8iH4ksZahHIGMzfOM/8dozW3dzQJHmiDPQRDiA1KW5QqpOySWzT62gnmcqx1Sy
dWnexOCbaNSVs6FCNkgZXGMqjLd1FLMxVKENwnmCOwXmf3Xyi3YpAEhiAmNMkZ5K
43/wq1gqVsVqfoyZ9DucpFPgPc4RHah8MqPt+cbhQxocpsSfmclrNu+6h1AYEEM5
pxNBc4RtCDo344xhRGa8lA0QwsAKJDLmiMRo2IsSITeEnvnqnyf3FDmEMId7gRhq
XBCgm59d0JPeDsBN1rvupkfPvFTGPBeyCOWgkAksbycA8jp8qHBEmhPi06cs4Agz
95f8A8PCIH6h+7cnX7tW6qoXeBKAJp7y6pqJCjjgpEdSIXaCQTU=
=X4+p
-----END PGP SIGNATURE-----
--- End Message ---