Your message dated Thu, 13 Oct 2022 23:32:15 +0200
with message-id <Y0iD3/[email protected]>
and subject line Re: Accepted cimg 3.1.6+dfsg-1 (source) into unstable
has caused the Debian Bug report #1018941,
regarding cimg: CVE-2022-1325 - memory exhaustion from a malicious pandore or
bmp file
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1018941: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1018941
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: cimg
Version: 3.0.2+dfsg-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team
<[email protected]>
Hi,
The following vulnerability was published for cimg.
CVE-2022-1325[0]:
| A flaw was found in Clmg, where with the help of a maliciously crafted
| pandore or bmp file with modified dx and dy header field values it is
| possible to trick the application into allocating huge buffer sizes
| like 64 Gigabyte upon reading the file from disk or from a virtual
| buffer.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2022-1325
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1325
Please adjust the affected versions in the BTS as needed.
-- System Information:
Debian Release: bookworm/sid
APT prefers unstable
APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)
Kernel: Linux 5.18.0-4-amd64 (SMP w/6 CPU threads; PREEMPT)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8),
LANGUAGE=en_GB:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
--- End Message ---
--- Begin Message ---
Source: cimg
Source-Version: 3.1.6+dfsg-1
On Thu, Oct 13, 2022 at 08:51:59PM +0000, Debian FTP Masters wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA256
>
> Format: 1.8
> Date: Thu, 13 Oct 2022 21:43:59 +0200
> Source: cimg
> Architecture: source
> Version: 3.1.6+dfsg-1
> Distribution: unstable
> Urgency: medium
> Maintainer: Debian Science Maintainers
> <[email protected]>
> Changed-By: Andreas Tille <[email protected]>
> Closes: 1020028
> Changes:
> cimg (3.1.6+dfsg-1) unstable; urgency=medium
> .
> * New upstream version
> * Standards-Version: 4.6.1 (routine-update)
> * Set upstream metadata fields: Repository-Browse.
> * Try hard to follow new package and file layout of libimath-dev
> Closes: #1020028
Seems to fix CVE-2022-1325.
Regards,
Salvatore
--- End Message ---
--
debian-science-maintainers mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-science-maintainers