Your message dated Sun, 28 Aug 2022 12:02:08 +0000
with message-id <e1osgzq-00fvst...@fasolo.debian.org>
and subject line Bug#1014534: fixed in dlt-daemon 2.18.6-1+deb11u1
has caused the Debian Bug report #1014534,
regarding dlt-daemon: CVE-2022-31291
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
1014534: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1014534
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: dlt-daemon
X-Debbugs-CC: t...@security.debian.org
Severity: grave
Tags: security

Hi,

The following vulnerability was published for dlt-daemon.

CVE-2022-31291[0]:
| An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows
| attackers to cause a double free via crafted TCP packets.

https://github.com/COVESA/dlt-daemon/pull/376
https://github.com/COVESA/dlt-daemon/commit/6a3bd901d825c7206797e36ea98e10a218f5aad2

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2022-31291
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31291

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: dlt-daemon
Source-Version: 2.18.6-1+deb11u1
Done: Adrian Bunk <b...@debian.org>

We believe that the bug you reported is fixed in the latest version of
dlt-daemon, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1014...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Adrian Bunk <b...@debian.org> (supplier of updated dlt-daemon package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 27 Aug 2022 14:59:10 +0300
Source: dlt-daemon
Architecture: source
Version: 2.18.6-1+deb11u1
Distribution: bullseye
Urgency: medium
Maintainer: Aigars Mahinovs <aigar...@debian.org>
Changed-By: Adrian Bunk <b...@debian.org>
Closes: 1014534
Changes:
 dlt-daemon (2.18.6-1+deb11u1) bullseye; urgency=medium
 .
   * Non-maintainer upload.
   * CVE-2022-31291: Double free in dlt_config_file_set_section().
     (Closes: #1014534)
Checksums-Sha1:
 b3ea4309bef002c6a7ea1b80684b4a41cc6455c0 2162 dlt-daemon_2.18.6-1+deb11u1.dsc
 76233de26953fee82d9a7610c83e2849dcfa3630 5904 
dlt-daemon_2.18.6-1+deb11u1.debian.tar.xz
Checksums-Sha256:
 2cd09945c993dce2f451fd69f513b5460ffdf2ad22c226f4a0aa2bc465155f73 2162 
dlt-daemon_2.18.6-1+deb11u1.dsc
 4bb222459db24f873ea87a3f341ee0f5bfb3749565271a99c65aa44ee9c07a1b 5904 
dlt-daemon_2.18.6-1+deb11u1.debian.tar.xz
Files:
 cd552c0bc6a3546277a8cec4553918ed 2162 libs optional 
dlt-daemon_2.18.6-1+deb11u1.dsc
 1c55a903531c59a7ec6440691edea63f 5904 libs optional 
dlt-daemon_2.18.6-1+deb11u1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmMKChkACgkQiNJCh6LY
mLFDKw/+L5qfw6wvAGXIOb9KMFUINhRlUZEL54+skr3WHNxiNxRM2lG6dnfdcrCx
nxFncdKD5gO+SnYzrbEPwkvYuQp+r3PSo3SO3wKpYSnbnMLPJLxaS5+lNu2zua0+
CspgNGWTl9opogOZCxxYnmL4b2PZncLEz6eRUolxa/Tcu0OpH3pU05OCVsOBQmgh
Liotc2J4LbuWePaUsITO+27aU2Y8rlPSmaeET7cxPQzBtGPUNlAtPYyOQ+O/S+MX
Wf5MsaP+jsVCMEzt9KmAuyZ/LNsy7YenxWcLjB4RQpxa4J8/NIkTKbq5W06+I4s+
R5cUQt9OJSB0GaW9fdSLxVrkXpJDzU/BzQWPjMwG64WeTW3u7hCoLSE1hc6LdXRJ
xh3+Da7yDWhLAWdvJEH7Y92WrpdQjRJATdgSE8SBPlOovu4uQzfR8etNeYkRwt6o
gjr7FiU8jyrgj6GEB9zQ32/OgRuox0u4pUCfgJ6FYYpGYFvPX5We0mYb6TC27IzM
BNbHekGie4O00xUI1yrntqf3M418aJoGYEcoCyROyyR5PnP/XcR0Yg8vZ7CqX6mq
L0lrmnPUWxCMpdOFB6b9SIYHyke012LKTXwUsxWkBFxwh8PXdJkedVmW8kKtRK6C
RjK2n05hvSaGGbZt4AebLAxGgnlnopiVt3rzhHQRVPYAS085obY=
=1eqg
-----END PGP SIGNATURE-----

Attachment: pgpWkyJmMR9uG.pgp
Description: PGP signature


--- End Message ---

Reply via email to