Your message dated Thu, 01 Oct 2015 09:35:38 +0000
with message-id <e1zhah4-0004sd...@franck.debian.org>
and subject line Bug#779047: fixed in fuseiso 20070708-3.2
has caused the Debian Bug report #779047,
regarding Two security issues
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
779047: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=779047
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: fuseiso
Severity: grave
Tags: security
Hi,
two vulnerabilities have been found in fuseiso:
https://bugzilla.redhat.com/show_bug.cgi?id=863102
https://bugzilla.redhat.com/show_bug.cgi?id=863091
CVE IDs have been requested, but are not yet assigned:
http://www.openwall.com/lists/oss-security/2015/02/06/7
Cheers,
Moritz
--- End Message ---
--- Begin Message ---
Source: fuseiso
Source-Version: 20070708-3.2
We believe that the bug you reported is fixed in the latest version of
fuseiso, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 779...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Mike Gabriel <sunwea...@debian.org> (supplier of updated fuseiso package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Thu, 01 Oct 2015 11:27:12 +0200
Source: fuseiso
Binary: fuseiso
Architecture: source amd64
Version: 20070708-3.2
Distribution: unstable
Urgency: medium
Maintainer: David Paleino <da...@debian.org>
Changed-By: Mike Gabriel <sunwea...@debian.org>
Description:
fuseiso - FUSE module to mount ISO filesystem images
Closes: 779047
Changes:
fuseiso (20070708-3.2) unstable; urgency=medium
.
* Non-maintainer upload.
* debian/patches (Closes: #779047):
+ Add 02-prevent-buffer-overflow.patch. Prevent stack-based buffer overflow
when concatenating strings to an absolute path name. Prevention is done
by checking that the result will stay under the maximum path length as
given
by the platforms PATH_MAX constant.
+ Add 03-prevent-integer-overflow.patch. Prevent integer overflow in ZISO
code. Bail out if a ZF block size > 2^17 is to be read.
Checksums-Sha1:
448b27af7fbf0e84c93e64ccd54f6cee6f03954e 1906 fuseiso_20070708-3.2.dsc
51551f323c579637dbc7c5cb01bb20b5e794fd0f 5028
fuseiso_20070708-3.2.debian.tar.xz
1a8569f90fe272c7cd8400fc9239b1848a63a289 19708 fuseiso_20070708-3.2_amd64.deb
Checksums-Sha256:
6a42820b4bee09cc0b08272973c88e9d0490e42b75124d18da6a7081db5c9be6 1906
fuseiso_20070708-3.2.dsc
8f26cf5994d59a9c388b758c6793551fb6008165c8169971c1ff6a60c7b93e96 5028
fuseiso_20070708-3.2.debian.tar.xz
b74d0ea66e925b46b12e4ff28a1e4ad37d724d9c5703c880f267944d2042dad3 19708
fuseiso_20070708-3.2_amd64.deb
Files:
52c0fc47310847dd6c03c4ed33606956 1906 admin optional fuseiso_20070708-3.2.dsc
4d4837edbd0e177a55d4a1df6fe8c91c 5028 admin optional
fuseiso_20070708-3.2.debian.tar.xz
10c91fdfba96cada86247a53a080695a 19708 admin optional
fuseiso_20070708-3.2_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCAAGBQJWDPyXAAoJEJr0azAldxsxKM4P/A5GJ/jNjNp6R3zXXWin/zWQ
yN+YEaTpM/oniliTDvkk0zZTjkYQUitkXYprFMb94SYK+IoxJUhuT8uIy9vQJ8hH
nrP0Wp4e3oeCLJYZCUOU+gea9AH9P7N6qG6Py9LRHokYmQXmkEkD1wyKDGBOpmnl
eA12Y/4OhDa1sWjNwylOZysOzJhJaNWYWVl2eXR1lTUPLzMyZICT7FzDyaNLwegY
U1FHETMM4GnhpUJaRg1YylwCxGcu3KNLWkX2lRSg73vyvoapbb1SvILOfiGW5bwp
lgh3hcusXO5y4QAo9GAic3m4MgqvH8J1aLQxX4kc93KMYVJ7ojkNQIqmAQtx0Y99
Tc1roDAtg9Kde6KjLjqWP+Eh/In44xS64NmNcC44X/AoRdXlzvWrjgCmMwZ9PbVI
DNShgbQXDAF7bK7T0yWsyufRxyF3PCGrL8kiboy/SnmMFdL9RfrlR80vX4hcmnBP
uqPJ3eKEKHzlRPUty3Uc+DdbWUaqK5xMY6bC2EgsNR7JpnEm+wTlei0gErxYLrAO
HkVlcI4Y6YU1qulp5SIag9wMI28YI/jC5Wqy6SSlBBMdPdcav/qi3Ma1RHYDyB6e
HdHI1VLo3RnrCmTO8DHHPSDtN7J/b2XM1MzSGwoWdX+EFABcM9LOa2dvV6M75EeO
sHCoQvnjPPavQiD44MZp
=Dm/w
-----END PGP SIGNATURE-----
--- End Message ---