Your message dated Fri, 05 Feb 2016 12:20:58 +0000
with message-id <e1arfni-0004vb...@franck.debian.org>
and subject line Bug#813187: fixed in eglibc 2.11.3-4+deb6u9
has caused the Debian Bug report #813187,
regarding glibc: CVE-2014-9761: Unbounded stack allocation in nan* functions
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
813187: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=813187
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: glibc
Version: 2.19-18
Severity: normal
Tags: security upstream
Forwarded: https://sourceware.org/bugzilla/show_bug.cgi?id=16962
Hi,
the following vulnerability was published for glibc, reporting it as
well to the BTS to have a BTS <-> security-tracker cross reference.
CVE-2014-9761[0]:
nan function unbounded stack allocation
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2014-9761
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1300310
[2] https://sourceware.org/bugzilla/show_bug.cgi?id=16962
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: eglibc
Source-Version: 2.11.3-4+deb6u9
We believe that the bug you reported is fixed in the latest version of
eglibc, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 813...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Santiago Ruano Rincón <santiag...@riseup.net> (supplier of updated eglibc
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 04 Feb 2016 20:54:36 +0100
Source: eglibc
Binary: libc-bin libc-dev-bin glibc-doc eglibc-source locales locales-all nscd
libc6 libc6-dev libc6-dbg libc6-prof libc6-pic libc6-udeb libc6.1 libc6.1-dev
libc6.1-dbg libc6.1-prof libc6.1-pic libc6.1-udeb libc0.3 libc0.3-dev
libc0.3-dbg libc0.3-prof libc0.3-pic libc0.3-udeb libc0.1 libc0.1-dev
libc0.1-dbg libc0.1-prof libc0.1-pic libc0.1-udeb libc6-i386 libc6-dev-i386
libc6-sparc64 libc6-dev-sparc64 libc6-s390x libc6-dev-s390x libc6-amd64
libc6-dev-amd64 libc6-powerpc libc6-dev-powerpc libc6-ppc64 libc6-dev-ppc64
libc6-mipsn32 libc6-dev-mipsn32 libc6-mips64 libc6-dev-mips64 libc0.1-i386
libc0.1-dev-i386 libc6-sparcv9b libc6-i686 libc6-xen libc0.1-i686 libc0.3-i686
libc0.3-xen libc6.1-alphaev67 libnss-dns-udeb libnss-files-udeb
Architecture: source all amd64
Version: 2.11.3-4+deb6u9
Distribution: squeeze-lts
Urgency: medium
Maintainer: GNU Libc Maintainers <debian-glibc@lists.debian.org>
Changed-By: Santiago Ruano Rincón <santiag...@riseup.net>
Description:
eglibc-source - Embedded GNU C Library: sources
glibc-doc - Embedded GNU C Library: Documentation
libc-bin - Embedded GNU C Library: Binaries
libc-dev-bin - Embedded GNU C Library: Development binaries
libc0.1 - Embedded GNU C Library: Shared libraries
libc0.1-dbg - Embedded GNU C Library: detached debugging symbols
libc0.1-dev - Embedded GNU C Library: Development Libraries and Header Files
libc0.1-dev-i386 - Embedded GNU C Library: 32bit development libraries for
AMD64
libc0.1-i386 - Embedded GNU C Library: 32bit shared libraries for AMD64
libc0.1-i686 - Embedded GNU C Library: Shared libraries [i686 optimized]
libc0.1-pic - Embedded GNU C Library: PIC archive library
libc0.1-prof - Embedded GNU C Library: Profiling Libraries
libc0.1-udeb - Embedded GNU C Library: Shared libraries - udeb (udeb)
libc0.3 - Embedded GNU C Library: Shared libraries
libc0.3-dbg - Embedded GNU C Library: detached debugging symbols
libc0.3-dev - Embedded GNU C Library: Development Libraries and Header Files
libc0.3-i686 - Embedded GNU C Library: Shared libraries [i686 optimized]
libc0.3-pic - Embedded GNU C Library: PIC archive library
libc0.3-prof - Embedded GNU C Library: Profiling Libraries
libc0.3-udeb - Embedded GNU C Library: Shared libraries - udeb (udeb)
libc0.3-xen - Embedded GNU C Library: Shared libraries [Xen version]
libc6 - Embedded GNU C Library: Shared libraries
libc6-amd64 - Embedded GNU C Library: 64bit Shared libraries for AMD64
libc6-dbg - Embedded GNU C Library: detached debugging symbols
libc6-dev - Embedded GNU C Library: Development Libraries and Header Files
libc6-dev-amd64 - Embedded GNU C Library: 64bit Development Libraries for AMD64
libc6-dev-i386 - Embedded GNU C Library: 32-bit development libraries for AMD64
libc6-dev-mips64 - Embedded GNU C Library: 64bit Development Libraries for
MIPS64
libc6-dev-mipsn32 - Embedded GNU C Library: n32 Development Libraries for
MIPS64
libc6-dev-powerpc - Embedded GNU C Library: 32bit powerpc development
libraries for p
libc6-dev-ppc64 - Embedded GNU C Library: 64bit Development Libraries for
PowerPC64
libc6-dev-s390x - Embedded GNU C Library: 64bit Development Libraries for IBM
zSeri
libc6-dev-sparc64 - Embedded GNU C Library: 64bit Development Libraries for
UltraSPAR
libc6-i386 - Embedded GNU C Library: 32-bit shared libraries for AMD64
libc6-i686 - Embedded GNU C Library: Shared libraries [i686 optimized]
libc6-mips64 - Embedded GNU C Library: 64bit Shared libraries for MIPS64
libc6-mipsn32 - Embedded GNU C Library: n32 Shared libraries for MIPS64
libc6-pic - Embedded GNU C Library: PIC archive library
libc6-powerpc - Embedded GNU C Library: 32bit powerpc shared libraries for
ppc64
libc6-ppc64 - Embedded GNU C Library: 64bit Shared libraries for PowerPC64
libc6-prof - Embedded GNU C Library: Profiling Libraries
libc6-s390x - Embedded GNU C Library: 64bit Shared libraries for IBM zSeries
libc6-sparc64 - Embedded GNU C Library: 64bit Shared libraries for UltraSPARC
libc6-sparcv9b - Embedded GNU C Library: Shared libraries [v9b optimized]
libc6-udeb - Embedded GNU C Library: Shared libraries - udeb (udeb)
libc6-xen - Embedded GNU C Library: Shared libraries [Xen version]
libc6.1 - Embedded GNU C Library: Shared libraries
libc6.1-alphaev67 - Embedded GNU C Library: Shared libraries (EV67 optimized)
libc6.1-dbg - Embedded GNU C Library: detached debugging symbols
libc6.1-dev - Embedded GNU C Library: Development Libraries and Header Files
libc6.1-pic - Embedded GNU C Library: PIC archive library
libc6.1-prof - Embedded GNU C Library: Profiling Libraries
libc6.1-udeb - Embedded GNU C Library: Shared libraries - udeb (udeb)
libnss-dns-udeb - Embedded GNU C Library: NSS helper for DNS - udeb (udeb)
libnss-files-udeb - Embedded GNU C Library: NSS helper for files - udeb (udeb)
locales - Embedded GNU C Library: National Language (locale) data [support]
locales-all - Embedded GNU C Library: Precompiled locale data
nscd - Embedded GNU C Library: Name Service Cache Daemon
Closes: 812441 812445 812455 813187
Changes:
eglibc (2.11.3-4+deb6u9) squeeze-lts; urgency=medium
.
* Non-maintainer upload by the Squeeze LTS Team.
* Fix CVE-2014-9761: Unbounded stack allocation in nan* functions.
Closes: #813187.
* Fix CVE-2015-8776: Segmentation fault caused by passing out-of-range data
to strftime(). Closes: #812445.
* Fix CVE-2015-8778: Integer overflow in hcreate and hcreate_r.
Closes: #812441.
* Fix CVE-2015-8779: Multiple unbounded stack allocations in catopen().
Closes: #812455.
Checksums-Sha1:
d285a4ba6656a9215323d0a3b29364a5079331d2 3250 eglibc_2.11.3-4+deb6u9.dsc
c6e3d5d1a67869e72e943c3f1a62c6cda05e08e2 990384 eglibc_2.11.3-4+deb6u9.diff.gz
bddc5a15d157130398f22a783ef05d0e922155a9 1854040
glibc-doc_2.11.3-4+deb6u9_all.deb
0e2f1de9f48d5e8d5e83c128ebe00a96aeac7aa2 11227394
eglibc-source_2.11.3-4+deb6u9_all.deb
8ce4e5d85fe4f0f01d89b42c0fdc0c8f195d2c63 4760432
locales_2.11.3-4+deb6u9_all.deb
f724ce90524e9c4f215b95f598978a4cb0052ebc 4306982
libc6_2.11.3-4+deb6u9_amd64.deb
aeff9f282a19286a436540f589206706e2d67b46 2617498
libc6-dev_2.11.3-4+deb6u9_amd64.deb
bfab507e9852cf43d0d657a5c26f71272290dbd8 2059568
libc6-prof_2.11.3-4+deb6u9_amd64.deb
ac75d66f7be3ab85af41522779144d6a755be63c 1574938
libc6-pic_2.11.3-4+deb6u9_amd64.deb
f3157da6152cfbd6b2ad000ac70d6ed2b7d29170 756370
libc-bin_2.11.3-4+deb6u9_amd64.deb
2c1aa47f91cf179cad9d29eb43eb90d0cb108a95 211242
libc-dev-bin_2.11.3-4+deb6u9_amd64.deb
a98dd2ddcd9349c9d39186fbfab154b5a0212bf7 3603888
locales-all_2.11.3-4+deb6u9_amd64.deb
47204594544cd52f09ba79e7f6fdccba21a3a897 3841374
libc6-i386_2.11.3-4+deb6u9_amd64.deb
402bbfdc5fa0b487f0806038b0c87e61b59ce2f4 1556430
libc6-dev-i386_2.11.3-4+deb6u9_amd64.deb
d3632518540989a16828be0cc026f521ba45ad9e 201130 nscd_2.11.3-4+deb6u9_amd64.deb
10a2679e709efdc14e6b19970bbf7aac84ffbef5 10585246
libc6-dbg_2.11.3-4+deb6u9_amd64.deb
42ceb550ab69c496e012ecb0954706894a5a1e4a 1172628
libc6-udeb_2.11.3-4+deb6u9_amd64.udeb
b2b10c8f1996b6a60be02b143f76c6c42f817e44 11108
libnss-dns-udeb_2.11.3-4+deb6u9_amd64.udeb
a401243af0d410ead7c6d11de174c7f5f89fb28c 20142
libnss-files-udeb_2.11.3-4+deb6u9_amd64.udeb
Checksums-Sha256:
ef8f8103b778881d68744b53a79e2185e7d78248e59fea8e8179b85e923e006f 3250
eglibc_2.11.3-4+deb6u9.dsc
dc6c661e3406390b25cd7ae0d16b2b7b979a9cf6f874b1f710aa17e77a430e82 990384
eglibc_2.11.3-4+deb6u9.diff.gz
6aa2b554cdfd61cc18e8d1cb5579d2d4abcd4990a3198ae5af7456abcae9b049 1854040
glibc-doc_2.11.3-4+deb6u9_all.deb
fe3c812bdaaf33d60a0378e10bbe358aff3d14435e65f361b5bc59a8df7c1e4d 11227394
eglibc-source_2.11.3-4+deb6u9_all.deb
330c9b18df2f3f77a3b604ce68e76bbcaabf288565632e5334418415170cadb8 4760432
locales_2.11.3-4+deb6u9_all.deb
bc8a03cdacd587c77142fbbaf1f31e283dde995256fdfe73e6d1a0dd2ec161c9 4306982
libc6_2.11.3-4+deb6u9_amd64.deb
aee39e3a8e0ecb4023b0369f8cc3940e3814955be16bfb26af969c8d38d70dc1 2617498
libc6-dev_2.11.3-4+deb6u9_amd64.deb
d4620d33e1bdae5dd447d26e8c4a4f095d3bd7192a7bffc2f77b82e9357d6091 2059568
libc6-prof_2.11.3-4+deb6u9_amd64.deb
155ff7eccf46262c7850ec9128a49b49e18de2743fcc37681b6fe99fbb7f03c4 1574938
libc6-pic_2.11.3-4+deb6u9_amd64.deb
27d840767004f1d6b99fb6141b786cc625f2448ea6dc3ea3ba4246f3476f4bee 756370
libc-bin_2.11.3-4+deb6u9_amd64.deb
df0cd96ad5c85b41f1ce6016831e0673d7487e963b0db8a9f9e66d19a68001a8 211242
libc-dev-bin_2.11.3-4+deb6u9_amd64.deb
2dcf5f02d0f2ac807b6fa8dbfc3940b075f868413402fdb96765e15b1f64854a 3603888
locales-all_2.11.3-4+deb6u9_amd64.deb
ce6e6ea558e39dbba7361740a255ce3f267821679d04e0561fc9dd79d52bfd39 3841374
libc6-i386_2.11.3-4+deb6u9_amd64.deb
42ebda60737b28fc468129033ccbf24321610bdabffa7fe4492bc3902e0bd194 1556430
libc6-dev-i386_2.11.3-4+deb6u9_amd64.deb
f2da6a0a8ef3d758cecf4efb73eb3ff6db41172ba4c0493a94ceba1122c4bac1 201130
nscd_2.11.3-4+deb6u9_amd64.deb
2e8d10250605952b77ba95f8704fc4f2efe13870d4318aedb981d6240470013c 10585246
libc6-dbg_2.11.3-4+deb6u9_amd64.deb
f8ca756e8af00a2557ded9885b45716390444e572f8b876b8d14256e97dfc82a 1172628
libc6-udeb_2.11.3-4+deb6u9_amd64.udeb
ceff527a12b8d0a614c10fc806439380d6c4aa28d637644a32787fdda7c1e9f7 11108
libnss-dns-udeb_2.11.3-4+deb6u9_amd64.udeb
ffe11f1adf95eafb3e09858525aeb728f62efb352f8edb3afe8279aa8cbf3438 20142
libnss-files-udeb_2.11.3-4+deb6u9_amd64.udeb
Files:
aa1c9f9f62a8cc7e7291686c7e7bb04f 3250 libs required eglibc_2.11.3-4+deb6u9.dsc
74e798764a617a610c6c9cba9894e1d8 990384 libs required
eglibc_2.11.3-4+deb6u9.diff.gz
34619f5be90b1c0b32019d15f8a9d0b7 1854040 doc optional
glibc-doc_2.11.3-4+deb6u9_all.deb
24021664a2f2cd30df28cd9fb3f755c3 11227394 devel optional
eglibc-source_2.11.3-4+deb6u9_all.deb
7dde06777c7fcb3c5bbee9e250623eb3 4760432 localization standard
locales_2.11.3-4+deb6u9_all.deb
e4195fc5ce566d32e883cd9f0584a23a 4306982 libs required
libc6_2.11.3-4+deb6u9_amd64.deb
b1e2e889b57b79d86d7b7d82af741ec0 2617498 libdevel optional
libc6-dev_2.11.3-4+deb6u9_amd64.deb
b03c6c648fc2268435b82917b5bddb05 2059568 libdevel extra
libc6-prof_2.11.3-4+deb6u9_amd64.deb
ad8b26bd99aa09eaa2b79abc91b74c4a 1574938 libdevel optional
libc6-pic_2.11.3-4+deb6u9_amd64.deb
7df25d65ee57ce1d4f123f88746c95d3 756370 libs required
libc-bin_2.11.3-4+deb6u9_amd64.deb
24d063a21ff0a3e71b0e35bc3ef0fcba 211242 libdevel optional
libc-dev-bin_2.11.3-4+deb6u9_amd64.deb
9cc041aa64b4023e293f59ba45dda337 3603888 localization extra
locales-all_2.11.3-4+deb6u9_amd64.deb
23860c3d0565dd369f080895249fcee0 3841374 libs optional
libc6-i386_2.11.3-4+deb6u9_amd64.deb
fa37b70e86eacd2486cead37d5e08a4f 1556430 libdevel optional
libc6-dev-i386_2.11.3-4+deb6u9_amd64.deb
49c7cc517104acb2fd1c4de2bf015558 201130 admin optional
nscd_2.11.3-4+deb6u9_amd64.deb
190e2a23584d79c93dae5017487b2f84 10585246 debug extra
libc6-dbg_2.11.3-4+deb6u9_amd64.deb
a86f42229a1ac3ea7cabee88eae8bcd1 1172628 debian-installer extra
libc6-udeb_2.11.3-4+deb6u9_amd64.udeb
a71cc1f8fdfc21370327ae4ecebb4433 11108 debian-installer extra
libnss-dns-udeb_2.11.3-4+deb6u9_amd64.udeb
1a6890e68feb92099a7e5847c101e82c 20142 debian-installer extra
libnss-files-udeb_2.11.3-4+deb6u9_amd64.udeb
Package-Type: udeb
-----BEGIN PGP SIGNATURE-----
iQIcBAEBCgAGBQJWtIYiAAoJEN5v/bjI1ki9EGUP/iFIZkQUf0eWof4J9uog+s1f
7V1aMi4thzg7BXzUGu/16Q3RACbwLJzEYu8Cqk4YiAoLbvd4vQKa6DhCk3RnZWdE
uHnH2oCIqZ1+etPiQ0oqOvnPSkOpevaSnNmyIj8Fhr0FWSCwUuH2XNK8i3Q10p5N
NPBPrQ4jf3WmpocTkCVTf8MlxcBQUyRs5KiTDTdkX2AV9mAPCVMUbDp0Ss0yXvNe
tQau+iYDvljzOJKb2CSI0+TMWCPJvLwWFGeXyIRhRQcQoWWGvxCrCIVpT3DPJBZG
McXPB7dt8YcrihAIUf9a4PgiIeQRq31A0rhH5bT5VOKIx0z4r9TMQyWv4EsJZAQs
SSPkBeiMz4TTd5lcRck+l9zI0pj1qseE/B6cf9a056nOFp7GOn2pcbBcoFm9BxXP
u8IFNaC8Cq2ReYPC/FJGYiXbcrDg6dLSvfefhgPkV0OXNz8nxiyLAkuB+UmQbuYX
VzC/mWI13RKI1PvPSmmqLMrLWaC2Ua5KaN+DgXSC0iyjcj/Xx1US8xmWnSlGYzQW
eIDi/bkS/BXCeWKhKOr8cw6hH2OUI6ngO+YIsCOsDM6L35Ej9Q+uINNDstQH+LGt
qlaPIxitJxASSXZVlPBbSU+4Kit9qJ6HbG5IZ/8T2OW7/7JqOSS1O/d7SZLEztOe
EbYJ35RQ9H08V/m06EzN
=Cu/n
-----END PGP SIGNATURE-----
--- End Message ---