Your message dated Sun, 1 Dec 2019 17:57:43 +0100
with message-id <20191201165739.ga13...@debian.org>
and subject line Re: Bug#943468: php-fpm: CVE-2019-11043: Vulnerability in 
PHP-FPM Could Lead to Remote Code Execution on nginx
has caused the Debian Bug report #943468,
regarding php7.3: CVE-2019-11043
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
943468: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=943468
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: php7.3
Version: 7.3.10-1
Severity: grave
Tags: security upstream
Justification: user security hole
Control: fixed -1 7.3.11-1~deb10u1

Hi,

The following vulnerability was published for php7.3, but this is mant
basically just as tracking item for stable -> testing updates as
DSA-4553-1 with 7.3.11-1~deb10u1 fixing this issue in stable to have
it at some point in testing. That said php7.3 is anyway specially
handled.

CVE-2019-11043[0]:
| In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below
| 7.3.11 in certain configurations of FPM setup it is possible to cause
| FPM module to write past allocated buffers into the space reserved for
| FCGI protocol data, thus opening the possibility of remote code
| execution.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-11043
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11043

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Version: 7.3.12-1

On Sun, Dec 01, 2019 at 12:06:40PM +0100, Ivo De Decker wrote:
> Please fix this by uploading a new version to unstable.

This happened now. Thanks!

The upload didn't close this bug. Doing so now.

Ivo

--- End Message ---

Reply via email to