[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#796105: marked as done (CVE-2015-1781)



Your message dated Sun, 13 Sep 2015 17:19:48 +0000
with message-id <E1ZbAwO-0002Z1-V0@franck.debian.org>
and subject line Bug#796105: fixed in glibc 2.19-20
has caused the Debian Bug report #796105,
regarding CVE-2015-1781
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
796105: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=796105
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Source: glibc
Severity: important
Tags: security

Hi,
please see https://sourceware.org/bugzilla/show_bug.cgi?id=18287

Fix:
https://sourceware.org/git/?p=glibc.git;a=commit;h=2959eda9272a03386

Cheers,
        Moritz

--- End Message ---
--- Begin Message ---
Source: glibc
Source-Version: 2.19-20

We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 796105@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aurelien Jarno <aurel32@debian.org> (supplier of updated glibc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sun, 13 Sep 2015 18:39:36 +0200
Source: glibc
Binary: libc-bin libc-dev-bin glibc-doc glibc-source locales locales-all nscd multiarch-support libc6 libc6-dev libc6-dbg libc6-pic libc6-udeb libc6.1 libc6.1-dev libc6.1-dbg libc6.1-pic libc6.1-udeb libc0.3 libc0.3-dev libc0.3-dbg libc0.3-pic libc0.3-udeb libc0.1 libc0.1-dev libc0.1-dbg libc0.1-pic libc0.1-udeb libc6-i386 libc6-dev-i386 libc6-sparc libc6-dev-sparc libc6-sparc64 libc6-dev-sparc64 libc6-s390 libc6-dev-s390 libc6-amd64 libc6-dev-amd64 libc6-powerpc libc6-dev-powerpc libc6-ppc64 libc6-dev-ppc64 libc6-mips32 libc6-dev-mips32 libc6-mipsn32 libc6-dev-mipsn32 libc6-mips64 libc6-dev-mips64 libc0.1-i386 libc0.1-dev-i386 libc6-x32 libc6-dev-x32 libc6-i686 libc6-xen libc0.1-i686 libc0.3-i686 libc0.3-xen libc6.1-alphaev67 libc6-loongson2f libnss-dns-udeb libnss-files-udeb
Architecture: source all amd64
Version: 2.19-20
Distribution: unstable
Urgency: medium
Maintainer: Aurelien Jarno <aurel32@debian.org>
Changed-By: Aurelien Jarno <aurel32@debian.org>
Description:
 glibc-doc  - GNU C Library: Documentation
 glibc-source - GNU C Library: sources
 libc-bin   - GNU C Library: Binaries
 libc-dev-bin - GNU C Library: Development binaries
 libc0.1    - GNU C Library: Shared libraries
 libc0.1-dbg - GNU C Library: detached debugging symbols
 libc0.1-dev - GNU C Library: Development Libraries and Header Files
 libc0.1-dev-i386 - GNU C Library: 32bit development libraries for AMD64
 libc0.1-i386 - GNU C Library: 32bit shared libraries for AMD64
 libc0.1-i686 - GNU C Library: Shared libraries [i686 optimized]
 libc0.1-pic - GNU C Library: PIC archive library
 libc0.1-udeb - GNU C Library: Shared libraries - udeb (udeb)
 libc0.3    - GNU C Library: Shared libraries
 libc0.3-dbg - GNU C Library: detached debugging symbols
 libc0.3-dev - GNU C Library: Development Libraries and Header Files
 libc0.3-i686 - GNU C Library: Shared libraries [i686 optimized]
 libc0.3-pic - GNU C Library: PIC archive library
 libc0.3-udeb - GNU C Library: Shared libraries - udeb (udeb)
 libc0.3-xen - GNU C Library: Shared libraries [Xen version]
 libc6      - GNU C Library: Shared libraries
 libc6-amd64 - GNU C Library: 64bit Shared libraries for AMD64
 libc6-dbg  - GNU C Library: detached debugging symbols
 libc6-dev  - GNU C Library: Development Libraries and Header Files
 libc6-dev-amd64 - GNU C Library: 64bit Development Libraries for AMD64
 libc6-dev-i386 - GNU C Library: 32-bit development libraries for AMD64
 libc6-dev-mips32 - GNU C Library: o32 Development Libraries for MIPS
 libc6-dev-mips64 - GNU C Library: 64bit Development Libraries for MIPS64
 libc6-dev-mipsn32 - GNU C Library: n32 Development Libraries for MIPS64
 libc6-dev-powerpc - GNU C Library: 32bit powerpc development libraries for ppc64
 libc6-dev-ppc64 - GNU C Library: 64bit Development Libraries for PowerPC64
 libc6-dev-s390 - GNU C Library: 32bit Development Libraries for IBM zSeries
 libc6-dev-sparc - GNU C Library: 32bit Development Libraries for SPARC
 libc6-dev-sparc64 - GNU C Library: 64bit Development Libraries for UltraSPARC
 libc6-dev-x32 - GNU C Library: X32 ABI Development Libraries for AMD64
 libc6-i386 - GNU C Library: 32-bit shared libraries for AMD64
 libc6-i686 - GNU C Library: Shared libraries [i686 optimized]
 libc6-loongson2f - GNU C Library: Shared libraries (Loongson 2F optimized)
 libc6-mips32 - GNU C Library: o32 Shared libraries for MIPS
 libc6-mips64 - GNU C Library: 64bit Shared libraries for MIPS64
 libc6-mipsn32 - GNU C Library: n32 Shared libraries for MIPS64
 libc6-pic  - GNU C Library: PIC archive library
 libc6-powerpc - GNU C Library: 32bit powerpc shared libraries for ppc64
 libc6-ppc64 - GNU C Library: 64bit Shared libraries for PowerPC64
 libc6-s390 - GNU C Library: 32bit Shared libraries for IBM zSeries
 libc6-sparc - GNU C Library: 32bit Shared libraries for SPARC
 libc6-sparc64 - GNU C Library: 64bit Shared libraries for UltraSPARC
 libc6-udeb - GNU C Library: Shared libraries - udeb (udeb)
 libc6-x32  - GNU C Library: X32 ABI Shared libraries for AMD64
 libc6-xen  - GNU C Library: Shared libraries [Xen version]
 libc6.1    - GNU C Library: Shared libraries
 libc6.1-alphaev67 - GNU C Library: Shared libraries (EV67 optimized)
 libc6.1-dbg - GNU C Library: detached debugging symbols
 libc6.1-dev - GNU C Library: Development Libraries and Header Files
 libc6.1-pic - GNU C Library: PIC archive library
 libc6.1-udeb - GNU C Library: Shared libraries - udeb (udeb)
 libnss-dns-udeb - GNU C Library: NSS helper for DNS - udeb (udeb)
 libnss-files-udeb - GNU C Library: NSS helper for files - udeb (udeb)
 locales    - GNU C Library: National Language (locale) data [support]
 locales-all - GNU C Library: Precompiled locale data
 multiarch-support - Transitional package to ensure multiarch compatibility
 nscd       - GNU C Library: Name Service Cache Daemon
Closes: 759197 785664 788999 793543 794222 796105 796899 798515
Changes:
 glibc (2.19-20) unstable; urgency=medium
 .
   [ Samuel Thibault ]
   * patches/hurd-i386/tg-mmap32th_bit.diff: New patch to fix libpciaccess
     mapping of BARs above 2GiB. Closes: #793543.
   * rules.d/build.mk: Also install crt0.o in stage1, if any.
   * sysdeps/hurd-i386.mk: Fix stage1 about xen packages for hurd-i386 too.
   * patches/hurd-i386/tg-sysheaders.diff: New patch to fix stage1 finding hurd
     headers.
   * patches/hurd-i386/cvs-libpthread_clean2.diff: New patch to drop spurious
     code getting in the way for stage1.
   * patches/hurd-i386/cvs-libpthread_build.diff: New patch to fix build of
     generic libpthread code.
   * patches/hurd-i386/libpthread_build.diff: Fix header inclusion to get
     pthread headers from libpthread/ instead of system.
   * sysdeps/hurd.mk: Create symlinks to kernel and hurd headers required for
     build, so that we can pass --with-headers to configure to make the build
     really self-hosted.
   * patches/hurd-i386/local-clock_gettime_MONOTONIC.diff: Update patch to not
     advertise _POSIX_CLOCK_SELECTION for vlc
   * patches/hurd-i386/{local,cvs}-bootstrap.diff: New patch to fix crt*.o build
     in stage1.
   * rules, rules.d/build.mk: Set MIG to gnu-type alias of mig, to fix
     cross-build.
   * control, control.d/main: Bump mig dependency to get the gnu-type alias in
     non-cross case too.
 .
   [ Aurelien Jarno ]
   * Update from upstream stable branch:
     - Fix pthread_mutex_trylock with lock elision.  Closes: #759197,
       #788999.
     - Fix gprof entry point on ppc64el.  Closes: #794222.
     - Fix a buffer overflow in getanswer_r (CVE-2015-1781).  Closes: #796105.
     - Fix getaddrinfo sometimes returning uninitialized data with nscd.
       Closes: #798515.
   * sysdeps.mk/mips*.mk: force the ISA until it gets propagated to all GCC
     versions.
   * Update hppa patches.  Closes: #785664:
     - Replace patches/hppa/local-fpu.diff by upstream patch cvs-fpu-r2.diff.
     - Add patches/hppa/cvs-fpu2.diff from upstream.
     - Add patches/hppa/local-fptr-table-size.diff from Carlos O'Donnell.
     - Add patches/hppa/local-setcontext.diff.
     - Add patches/hppa/cvs-start.diff from upstream.
   * patches/any/cvs-pie-lt_executable.diff: new patch from upstream to fix
     explicit loader invocation with PIE binaries.  Closes: #796899.
Checksums-Sha1:
 2ee6868c14db5a0a6412f44c06319b0425521652 8222 glibc_2.19-20.dsc
 d968c04b1110b1dce99508048d92cd204491afac 1038748 glibc_2.19-20.debian.tar.xz
 8ad1e850112bfa3e397b1caf35e1aace77880557 2266790 glibc-doc_2.19-20_all.deb
 85d054841ef23623f52481dd00304283161adfad 13960810 glibc-source_2.19-20_all.deb
 1bbbda5228781e936579f1d13f851a3c19fa346d 3940066 locales_2.19-20_all.deb
Checksums-Sha256:
 4edcf510ba7b11aebd44cb39226747510c0ceaec9d4b062ce436c8c96715a7bd 8222 glibc_2.19-20.dsc
 e5c27244ecc8f088925a9d1616ad4bb4a5d4fc70c8cbe9e317dc7136eb213f84 1038748 glibc_2.19-20.debian.tar.xz
 ba250aa9c25813a94b856bb37db91b1a4cf1cf68ee707dc20cc20b6436dfa7de 2266790 glibc-doc_2.19-20_all.deb
 0f34c015e348e2cfb6e745acf377964a5b3dbc71877029c64ff7fc4b70488c1c 13960810 glibc-source_2.19-20_all.deb
 7708da48f1494e487e20f428cd42b24e0d6237235751deccfa2a03b0ae1d4a73 3940066 locales_2.19-20_all.deb
Files:
 27db97bff19706ea2227fa1d98f48bd3 8222 libs required glibc_2.19-20.dsc
 985147451775b38eef77ed7d4eebc9c7 1038748 libs required glibc_2.19-20.debian.tar.xz
 a9094f887d98b4dd3a8a8bc1247f6d36 2266790 doc optional glibc-doc_2.19-20_all.deb
 3568fe39aedf06ec58630159e7fb6b5a 13960810 devel optional glibc-source_2.19-20_all.deb
 217bb24d52031967c5eaee4ddd403171 3940066 localization standard locales_2.19-20_all.deb
Package-Type: udeb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJV9av/AAoJELqceAYd3Yyb3AgP/3rf7q3IBUvNa/tLGrTDgtxO
EcIGASNB4ZhyspHXHxTL1q59rExcXoNVk6oAkjXUBN6jmWbNlGUougs0ylbBOsdK
y+RYKa7VGWofd9kJedOrRSaI1WO99sQYkRTvx4loN6TS8/nMGgPgstXpJ3xxz24y
ikLFTK1Tq8x0J+QSfTp8DUKqIW2ZNibTQD93eVQkgSRlI42USwiK1Q+jRhcubwj3
c0mxRX4N1YMwB7liHTxX5aKmHjtYD87TJP9uTLT6vVhNzSpQI3iM7z517DnWZ1+Y
xFXLyUklWk2246c0xX4eejc6cLwJEjzZUQ1IFDBykSnI44lVj6PGBAAVmppgu3Xl
+6hrjMnipEnIBVYotoN4xTcdmAturZR5+oHK2hqpjYnwQ/lujdCPdrNw+ddFtG1S
3ntGGnmQJhS92UyTQZcVPnJ6mqCUtkodNA8wfnR7MYGbr5HPzsKlOCQH8jW55Dpq
gDpzfksi1JtDHCmFvaiuFBx78uuiMEou8dDtmKFV1HKofA2TMCD8eUvNQn5siFVE
4yrKfs3A6u9RwopBLqafKQ8Lq8GlSMpb8GQKjRYVAOtGNBHpxniSctzHpCUt7446
T2koauU13Eyky2UB6mAnHaXdnK+ONQZTWXJDmLoSkQzqBhjX55DBr97THYxnCNJ/
oEACvRPvX5lnxF4wVtDA
=NwK6
-----END PGP SIGNATURE-----

--- End Message ---

Reply to: