Your message dated Tue, 22 Oct 2019 20:46:22 +0000
with message-id <e1in12s-0005ck...@fasolo.debian.org>
and subject line Bug#942830: fixed in file 1:5.37-6
has caused the Debian Bug report #942830,
regarding CVE-2019-18218
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
942830: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=942830
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: file
Severity: grave
Tags: security
This was assigned CVE-2019-18218:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16780
https://github.com/file/file/commit/46a8443f76cec4b41ec736eca396984c74664f84
Cheers,
Moritz
--- End Message ---
--- Begin Message ---
Source: file
Source-Version: 1:5.37-6
We believe that the bug you reported is fixed in the latest version of
file, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 942...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Christoph Biedl <debian.a...@manchmal.in-ulm.de> (supplier of updated file
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 22 Oct 2019 21:05:34 +0200
Source: file
Architecture: source
Version: 1:5.37-6
Distribution: unstable
Urgency: high
Maintainer: Christoph Biedl <debian.a...@manchmal.in-ulm.de>
Changed-By: Christoph Biedl <debian.a...@manchmal.in-ulm.de>
Closes: 942830
Changes:
file (1:5.37-6) unstable; urgency=high
.
* Cherry-pick commit to restrict the number of CDF_VECTOR elements.
Closes: #942830 [CVE-2019-18218]
Checksums-Sha1:
ac532cb4a7c944f94701636e629ef98213aa9c4a 2214 file_5.37-6.dsc
e9e8884d51a44a701e02ed5a0bfa4ae1cd0d8540 37648 file_5.37-6.debian.tar.xz
fd02051ff6deb6d557a928308868df2e07ce1806 6529 file_5.37-6_powerpc.buildinfo
Checksums-Sha256:
9e549c158d657c6345f5a33d4c151a7c4a383953c2ea9c74171e10b942dddd69 2214
file_5.37-6.dsc
a20a1af3ece8b33c6da832d1dd04e3ff8b79a7d4833311b335b3f2c6fa09bd5a 37648
file_5.37-6.debian.tar.xz
43ce7f96437838c4bbc134cce60b3a32e3f35d028662d17e7c5017e1088749c2 6529
file_5.37-6_powerpc.buildinfo
Files:
912c1f4d91a09b56b5a6297782345a7a 2214 utils standard file_5.37-6.dsc
8ee2441a44994fe0bc64e43811f9f10b 37648 utils standard file_5.37-6.debian.tar.xz
307c25838043960cab5750269ac19b7d 6529 utils standard
file_5.37-6_powerpc.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEWXMI+726A12MfJXdxCxY61kUkv0FAl2vYcwACgkQxCxY61kU
kv3ddQ//Tc43TJTV/MMXM4MMhLmKBRHv7roD8HTuyP4OQW0sa8qP9bzjs6Xmtixr
cASK+kwTeewrvygxliFHo/cK30sLl2aTnj8fUQzcF+IWXlqo2JKxKaopyF1ko/YQ
iGlri7DekxDU4Pt3anLCtRqjCmDPIBIV+XssS2Zhffyc/3h3SvKzrNj2XJnQtFg9
Qo9FW+IkCtONX+Dh60byR/N0l3g2Q0zKwxc5eCLOgkrw0NDRwE50m9KvSJVTs/hE
5KLYpBXG/PQJQhPuQj1iHAseBmfz8MY5zAx33ZKUxiNEZta2z/JpFizNvvxwt2ke
Cd3dvgYIrozjziMPIthFOhy9D885RvGpKXmoz9m98xSOYFJlbXl3SGmU8PQh/ABh
Q6h0KC8JcOabFIy8pXQVismTiz+AHivdrO6RGMFhgeMy39YmlrszRosxB25Qc0Bl
STkIuP67VxgPxa7cFb9Wipeb+xg0NOovjP40cOXyCAhPJ8shC0tzrWaXFwtpR0hN
zh6OrxxgDm0kgDOvXXrCCdv72jTwQgMLMK5wOdiWkDHAx2o/bn63Nk360BE4U+rE
8Wwx/iS94CRScRbMQoxF92XA70Nwp9sVgm/ItCVD6REkRiAUhg+9zANED6tM9/EI
o1ossTMnEaZzP6rYF3TVGru8ykbNOE7x3USomhnTDI3SNBl61zM=
=5R/y
-----END PGP SIGNATURE-----
--- End Message ---