Your message dated Wed, 26 Oct 2005 21:32:05 -0700 with message-id <[EMAIL PROTECTED]> and subject line Bug#335497: fixed in bmv 1.2-18 has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what I am talking about this indicates a serious mail system misconfiguration somewhere. Please contact me immediately.) Debian bug tracking system administrator (administrator, Debian Bugs database) -------------------------------------- Received: (at submit) by bugs.debian.org; 24 Oct 2005 09:51:31 +0000 >From [EMAIL PROTECTED] Mon Oct 24 02:51:31 2005 Return-path: <[EMAIL PROTECTED]> Received: from inutil.org (vserver151.vserver151.serverflex.de) [193.22.164.111] by spohr.debian.org with esmtp (Exim 3.36 1 (Debian)) id 1ETyzL-000802-00; Mon, 24 Oct 2005 02:51:31 -0700 Received: from wlan-client-041.informatik.uni-bremen.de ([134.102.116.42] helo=localhost.localdomain) by vserver151.vserver151.serverflex.de with esmtpsa (TLS-1.0:RSA_AES_256_CBC_SHA:32) (Exim 4.50) id 1ETyzJ-0001cY-NV for [EMAIL PROTECTED]; Mon, 24 Oct 2005 11:51:29 +0200 Received: from jmm by localhost.localdomain with local (Exim 4.54) id 1ETz00-00022h-W2; Mon, 24 Oct 2005 11:52:13 +0200 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit From: Moritz Muehlenhoff <[EMAIL PROTECTED]> To: Debian Bug Tracking System <[EMAIL PROTECTED]> Subject: CVE-2005-3278: Local root exploit in Postscript handling X-Mailer: reportbug 3.17 Date: Mon, 24 Oct 2005 11:52:12 +0200 X-Debbugs-Cc: Debian Security Team <[EMAIL PROTECTED]> Message-Id: <[EMAIL PROTECTED]> X-SA-Exim-Connect-IP: 134.102.116.42 X-SA-Exim-Mail-From: [EMAIL PROTECTED] X-SA-Exim-Scanned: No (on vserver151.vserver151.serverflex.de); SAEximRunCond expanded to false Delivered-To: [EMAIL PROTECTED] X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 (1.212-2003-09-23-exp) on spohr.debian.org X-Spam-Level: X-Spam-Status: No, hits=-11.0 required=4.0 tests=BAYES_00,HAS_PACKAGE, X_DEBBUGS_CC autolearn=ham version=2.60-bugs.debian.org_2005_01_02 Package: bmv Version: 1.2-17 Severity: grave Tags: security Justification: user security hole An integer overflow in bmv can lead to a local privilege escalation. Please see http://felinemenace.org/advisories/bmv_advisory.txt for details. This has been assigned CVE-2005-3278, please mention so in the changelog. The advisory mentions another vulnerability, which doesn't affect the binary package, this has been assigned CVE-2005-3279. Cheers, Moritz -- System Information: Debian Release: testing/unstable APT prefers unstable APT policy: (500, 'unstable') Architecture: i386 (i686) Shell: /bin/sh linked to /bin/bash Kernel: Linux 2.6.14-rc1 Locale: LANG=C, [EMAIL PROTECTED] (charmap=ISO-8859-15) Versions of packages bmv depends on: ii gs-gpl [gs] 8.15-4 The GPL Ghostscript PostScript int ii libc6 2.3.5-7 GNU C Library: Shared libraries an ii libsvga1 1:1.4.3-22 console SVGA display libraries bmv recommends no packages. -- no debconf information --------------------------------------- Received: (at 335497-close) by bugs.debian.org; 27 Oct 2005 04:38:14 +0000 >From [EMAIL PROTECTED] Wed Oct 26 21:38:14 2005 Return-path: <[EMAIL PROTECTED]> Received: from katie by spohr.debian.org with local (Exim 3.36 1 (Debian)) id 1EUzQr-0003Th-00; Wed, 26 Oct 2005 21:32:05 -0700 From: Guillem Jover <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] X-Katie: $Revision: 1.56 $ Subject: Bug#335497: fixed in bmv 1.2-18 Message-Id: <[EMAIL PROTECTED]> Sender: Archive Administrator <[EMAIL PROTECTED]> Date: Wed, 26 Oct 2005 21:32:05 -0700 Delivered-To: [EMAIL PROTECTED] X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 (1.212-2003-09-23-exp) on spohr.debian.org X-Spam-Level: X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER autolearn=no version=2.60-bugs.debian.org_2005_01_02 Source: bmv Source-Version: 1.2-18 We believe that the bug you reported is fixed in the latest version of bmv, which is due to be installed in the Debian FTP archive: bmv_1.2-18.diff.gz to pool/main/b/bmv/bmv_1.2-18.diff.gz bmv_1.2-18.dsc to pool/main/b/bmv/bmv_1.2-18.dsc bmv_1.2-18_i386.deb to pool/main/b/bmv/bmv_1.2-18_i386.deb A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [EMAIL PROTECTED], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Guillem Jover <[EMAIL PROTECTED]> (supplier of updated bmv package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [EMAIL PROTECTED]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Thu, 27 Oct 2005 07:12:47 +0300 Source: bmv Binary: bmv Architecture: source i386 Version: 1.2-18 Distribution: unstable Urgency: high Maintainer: Guillem Jover <[EMAIL PROTECTED]> Changed-By: Guillem Jover <[EMAIL PROTECTED]> Description: bmv - PostScript viewer for SVGAlib Closes: 260537 335326 335497 Changes: bmv (1.2-18) unstable; urgency=high . * Update watch file to version 3. * Now using Standards-Version 3.6.2 (no changes needed). * Lower case manpage header title. * Disallow heap corruption when giving the proper argument to "%%Pages:" on a PostScript file [CVE-2005-3278]. (Closes: #335497) * Update FSF's address. * Fix the license statement in debian/copyright to refer to the GPL instead of the LGPL. * Fix typo in manpage. (Closes: #335326) Thanks A Costa <[EMAIL PROTECTED]>. * Add detail to the -v option description in the manpage. (Closes: #260537) Thanks A Costa <[EMAIL PROTECTED]>. Files: fde9ef089721017a70fe139c7a158b05 557 text optional bmv_1.2-18.dsc 590ef95d4724fba0f29efd7158f2ff9d 13222 text optional bmv_1.2-18.diff.gz 0a33c0bbfc24ec083f6e681d9c0d708c 23628 text optional bmv_1.2-18_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (GNU/Linux) iD8DBQFDYFQvuW9ciZ2SjJsRAgdIAJ0dmpGqhff4xHpCODkIu/NxA38o8ACcDpQw ZFOKH6VhbO9SQx+Jo4BnYs0= =U1oB -----END PGP SIGNATURE----- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]