Your message dated Wed, 26 Oct 2005 21:32:05 -0700
with message-id <[EMAIL PROTECTED]>
and subject line Bug#335497: fixed in bmv 1.2-18
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 24 Oct 2005 09:51:31 +0000
>From [EMAIL PROTECTED] Mon Oct 24 02:51:31 2005
Return-path: <[EMAIL PROTECTED]>
Received: from inutil.org (vserver151.vserver151.serverflex.de) 
[193.22.164.111] 
        by spohr.debian.org with esmtp (Exim 3.36 1 (Debian))
        id 1ETyzL-000802-00; Mon, 24 Oct 2005 02:51:31 -0700
Received: from wlan-client-041.informatik.uni-bremen.de ([134.102.116.42] 
helo=localhost.localdomain)
        by vserver151.vserver151.serverflex.de with esmtpsa 
(TLS-1.0:RSA_AES_256_CBC_SHA:32)
        (Exim 4.50)
        id 1ETyzJ-0001cY-NV
        for [EMAIL PROTECTED]; Mon, 24 Oct 2005 11:51:29 +0200
Received: from jmm by localhost.localdomain with local (Exim 4.54)
        id 1ETz00-00022h-W2; Mon, 24 Oct 2005 11:52:13 +0200
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Moritz Muehlenhoff <[EMAIL PROTECTED]>
To: Debian Bug Tracking System <[EMAIL PROTECTED]>
Subject: CVE-2005-3278: Local root exploit in Postscript handling
X-Mailer: reportbug 3.17
Date: Mon, 24 Oct 2005 11:52:12 +0200
X-Debbugs-Cc: Debian Security Team <[EMAIL PROTECTED]>
Message-Id: <[EMAIL PROTECTED]>
X-SA-Exim-Connect-IP: 134.102.116.42
X-SA-Exim-Mail-From: [EMAIL PROTECTED]
X-SA-Exim-Scanned: No (on vserver151.vserver151.serverflex.de); SAEximRunCond 
expanded to false
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
        (1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Level: 
X-Spam-Status: No, hits=-11.0 required=4.0 tests=BAYES_00,HAS_PACKAGE,
        X_DEBBUGS_CC autolearn=ham version=2.60-bugs.debian.org_2005_01_02

Package: bmv
Version: 1.2-17
Severity: grave
Tags: security
Justification: user security hole

An integer overflow in bmv can lead to a local privilege escalation.
Please see http://felinemenace.org/advisories/bmv_advisory.txt for
details. This has been assigned CVE-2005-3278, please mention so
in the changelog.

The advisory mentions another vulnerability, which doesn't affect
the binary package, this has been assigned CVE-2005-3279.

Cheers,
        Moritz

-- System Information:
Debian Release: testing/unstable
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.14-rc1
Locale: LANG=C, [EMAIL PROTECTED] (charmap=ISO-8859-15)

Versions of packages bmv depends on:
ii  gs-gpl [gs]                   8.15-4     The GPL Ghostscript PostScript int
ii  libc6                         2.3.5-7    GNU C Library: Shared libraries an
ii  libsvga1                      1:1.4.3-22 console SVGA display libraries

bmv recommends no packages.

-- no debconf information

---------------------------------------
Received: (at 335497-close) by bugs.debian.org; 27 Oct 2005 04:38:14 +0000
>From [EMAIL PROTECTED] Wed Oct 26 21:38:14 2005
Return-path: <[EMAIL PROTECTED]>
Received: from katie by spohr.debian.org with local (Exim 3.36 1 (Debian))
        id 1EUzQr-0003Th-00; Wed, 26 Oct 2005 21:32:05 -0700
From: Guillem Jover <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
X-Katie: $Revision: 1.56 $
Subject: Bug#335497: fixed in bmv 1.2-18
Message-Id: <[EMAIL PROTECTED]>
Sender: Archive Administrator <[EMAIL PROTECTED]>
Date: Wed, 26 Oct 2005 21:32:05 -0700
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
        (1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Level: 
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER 
        autolearn=no version=2.60-bugs.debian.org_2005_01_02

Source: bmv
Source-Version: 1.2-18

We believe that the bug you reported is fixed in the latest version of
bmv, which is due to be installed in the Debian FTP archive:

bmv_1.2-18.diff.gz
  to pool/main/b/bmv/bmv_1.2-18.diff.gz
bmv_1.2-18.dsc
  to pool/main/b/bmv/bmv_1.2-18.dsc
bmv_1.2-18_i386.deb
  to pool/main/b/bmv/bmv_1.2-18_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Guillem Jover <[EMAIL PROTECTED]> (supplier of updated bmv package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Thu, 27 Oct 2005 07:12:47 +0300
Source: bmv
Binary: bmv
Architecture: source i386
Version: 1.2-18
Distribution: unstable
Urgency: high
Maintainer: Guillem Jover <[EMAIL PROTECTED]>
Changed-By: Guillem Jover <[EMAIL PROTECTED]>
Description: 
 bmv        - PostScript viewer for SVGAlib
Closes: 260537 335326 335497
Changes: 
 bmv (1.2-18) unstable; urgency=high
 .
   * Update watch file to version 3.
   * Now using Standards-Version 3.6.2 (no changes needed).
   * Lower case manpage header title.
   * Disallow heap corruption when giving the proper argument to "%%Pages:"
     on a PostScript file [CVE-2005-3278]. (Closes: #335497)
   * Update FSF's address.
   * Fix the license statement in debian/copyright to refer to the GPL
     instead of the LGPL.
   * Fix typo in manpage. (Closes: #335326)
     Thanks A Costa <[EMAIL PROTECTED]>.
   * Add detail to the -v option description in the manpage. (Closes: #260537)
     Thanks A Costa <[EMAIL PROTECTED]>.
Files: 
 fde9ef089721017a70fe139c7a158b05 557 text optional bmv_1.2-18.dsc
 590ef95d4724fba0f29efd7158f2ff9d 13222 text optional bmv_1.2-18.diff.gz
 0a33c0bbfc24ec083f6e681d9c0d708c 23628 text optional bmv_1.2-18_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFDYFQvuW9ciZ2SjJsRAgdIAJ0dmpGqhff4xHpCODkIu/NxA38o8ACcDpQw
ZFOKH6VhbO9SQx+Jo4BnYs0=
=U1oB
-----END PGP SIGNATURE-----


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to