Your message dated Tue, 3 Sep 2013 21:53:49 +0200
with message-id <20130903195349.GA12746@eldamar.local>
and subject line Re: Bug#719462: libmodplug: CVE-2013-4233 CVE-2013-4234
has caused the Debian Bug report #719462,
regarding libmodplug: CVE-2013-4233 CVE-2013-4234
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
719462: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=719462
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: libmodplug
Severity: grave
Tags: security
Justification: user security hole

Hi,
please see 
http://blog.scrt.ch/2013/07/24/vlc-abc-parsing-seems-to-be-a-ctf-challenge/

For the CVE assignments:
http://seclists.org/oss-sec/2013/q3/343

Cheers,
        Moritz

--- End Message ---
--- Begin Message ---
Source: libmodplug
Source-Version: 1:0.8.8.4-4

Closes contained a typo referring to another bugreport:

On Tue, 2013-09-03 at 03:18 +0000, Zed Pobre wrote:
>  libmodplug (1:0.8.8.4-4) unstable; urgency=high
>  .
>      * Merge all changes from latest upstream Git repository (0.8.8.4 with
>        additional patches), including the following security changes:
>        * CVE-2013-4233: fix integer overflow in load_abc.cpp
>        * CVE-2013-4234: fix heap overflows in abc_MIDI_drum and 
> abc_MIDI_gchord
>        * Closes: #719642

--- End Message ---

Reply via email to