[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#812445: marked as done (glibc: CVE-2015-8776: Segmentation fault caused by passing out-of-range data to strftime())



Your message dated Fri, 05 Feb 2016 12:20:58 +0000
with message-id <E1aRfNi-0004VP-Id@franck.debian.org>
and subject line Bug#812445: fixed in eglibc 2.11.3-4+deb6u9
has caused the Debian Bug report #812445,
regarding glibc: CVE-2015-8776: Segmentation fault caused by passing out-of-range data to strftime()
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
812445: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=812445
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Source: glibc
Version: 2.19-18
Severity: important
Tags: security upstream
Forwarded: https://sourceware.org/bugzilla/show_bug.cgi?id=18985

Hi,

the following vulnerability was published for glibc.

CVE-2015-8776[0]:
Passing out of range data to strftime() causes a segfault

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2015-8776
[1] https://sourceware.org/bugzilla/show_bug.cgi?id=18985

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: eglibc
Source-Version: 2.11.3-4+deb6u9

We believe that the bug you reported is fixed in the latest version of
eglibc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 812445@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Santiago Ruano Rincón <santiagorr@riseup.net> (supplier of updated eglibc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 04 Feb 2016 20:54:36 +0100
Source: eglibc
Binary: libc-bin libc-dev-bin glibc-doc eglibc-source locales locales-all nscd libc6 libc6-dev libc6-dbg libc6-prof libc6-pic libc6-udeb libc6.1 libc6.1-dev libc6.1-dbg libc6.1-prof libc6.1-pic libc6.1-udeb libc0.3 libc0.3-dev libc0.3-dbg libc0.3-prof libc0.3-pic libc0.3-udeb libc0.1 libc0.1-dev libc0.1-dbg libc0.1-prof libc0.1-pic libc0.1-udeb libc6-i386 libc6-dev-i386 libc6-sparc64 libc6-dev-sparc64 libc6-s390x libc6-dev-s390x libc6-amd64 libc6-dev-amd64 libc6-powerpc libc6-dev-powerpc libc6-ppc64 libc6-dev-ppc64 libc6-mipsn32 libc6-dev-mipsn32 libc6-mips64 libc6-dev-mips64 libc0.1-i386 libc0.1-dev-i386 libc6-sparcv9b libc6-i686 libc6-xen libc0.1-i686 libc0.3-i686 libc0.3-xen libc6.1-alphaev67 libnss-dns-udeb libnss-files-udeb
Architecture: source all amd64
Version: 2.11.3-4+deb6u9
Distribution: squeeze-lts
Urgency: medium
Maintainer: GNU Libc Maintainers <debian-glibc@lists.debian.org>
Changed-By: Santiago Ruano Rincón <santiagorr@riseup.net>
Description: 
 eglibc-source - Embedded GNU C Library: sources
 glibc-doc  - Embedded GNU C Library: Documentation
 libc-bin   - Embedded GNU C Library: Binaries
 libc-dev-bin - Embedded GNU C Library: Development binaries
 libc0.1    - Embedded GNU C Library: Shared libraries
 libc0.1-dbg - Embedded GNU C Library: detached debugging symbols
 libc0.1-dev - Embedded GNU C Library: Development Libraries and Header Files
 libc0.1-dev-i386 - Embedded GNU C Library: 32bit development libraries for AMD64
 libc0.1-i386 - Embedded GNU C Library: 32bit shared libraries for AMD64
 libc0.1-i686 - Embedded GNU C Library: Shared libraries [i686 optimized]
 libc0.1-pic - Embedded GNU C Library: PIC archive library
 libc0.1-prof - Embedded GNU C Library: Profiling Libraries
 libc0.1-udeb - Embedded GNU C Library: Shared libraries - udeb (udeb)
 libc0.3    - Embedded GNU C Library: Shared libraries
 libc0.3-dbg - Embedded GNU C Library: detached debugging symbols
 libc0.3-dev - Embedded GNU C Library: Development Libraries and Header Files
 libc0.3-i686 - Embedded GNU C Library: Shared libraries [i686 optimized]
 libc0.3-pic - Embedded GNU C Library: PIC archive library
 libc0.3-prof - Embedded GNU C Library: Profiling Libraries
 libc0.3-udeb - Embedded GNU C Library: Shared libraries - udeb (udeb)
 libc0.3-xen - Embedded GNU C Library: Shared libraries [Xen version]
 libc6      - Embedded GNU C Library: Shared libraries
 libc6-amd64 - Embedded GNU C Library: 64bit Shared libraries for AMD64
 libc6-dbg  - Embedded GNU C Library: detached debugging symbols
 libc6-dev  - Embedded GNU C Library: Development Libraries and Header Files
 libc6-dev-amd64 - Embedded GNU C Library: 64bit Development Libraries for AMD64
 libc6-dev-i386 - Embedded GNU C Library: 32-bit development libraries for AMD64
 libc6-dev-mips64 - Embedded GNU C Library: 64bit Development Libraries for MIPS64
 libc6-dev-mipsn32 - Embedded GNU C Library: n32 Development Libraries for MIPS64
 libc6-dev-powerpc - Embedded GNU C Library: 32bit powerpc development libraries for p
 libc6-dev-ppc64 - Embedded GNU C Library: 64bit Development Libraries for PowerPC64
 libc6-dev-s390x - Embedded GNU C Library: 64bit Development Libraries for IBM zSeri
 libc6-dev-sparc64 - Embedded GNU C Library: 64bit Development Libraries for UltraSPAR
 libc6-i386 - Embedded GNU C Library: 32-bit shared libraries for AMD64
 libc6-i686 - Embedded GNU C Library: Shared libraries [i686 optimized]
 libc6-mips64 - Embedded GNU C Library: 64bit Shared libraries for MIPS64
 libc6-mipsn32 - Embedded GNU C Library: n32 Shared libraries for MIPS64
 libc6-pic  - Embedded GNU C Library: PIC archive library
 libc6-powerpc - Embedded GNU C Library: 32bit powerpc shared libraries for ppc64
 libc6-ppc64 - Embedded GNU C Library: 64bit Shared libraries for PowerPC64
 libc6-prof - Embedded GNU C Library: Profiling Libraries
 libc6-s390x - Embedded GNU C Library: 64bit Shared libraries for IBM zSeries
 libc6-sparc64 - Embedded GNU C Library: 64bit Shared libraries for UltraSPARC
 libc6-sparcv9b - Embedded GNU C Library: Shared libraries [v9b optimized]
 libc6-udeb - Embedded GNU C Library: Shared libraries - udeb (udeb)
 libc6-xen  - Embedded GNU C Library: Shared libraries [Xen version]
 libc6.1    - Embedded GNU C Library: Shared libraries
 libc6.1-alphaev67 - Embedded GNU C Library: Shared libraries (EV67 optimized)
 libc6.1-dbg - Embedded GNU C Library: detached debugging symbols
 libc6.1-dev - Embedded GNU C Library: Development Libraries and Header Files
 libc6.1-pic - Embedded GNU C Library: PIC archive library
 libc6.1-prof - Embedded GNU C Library: Profiling Libraries
 libc6.1-udeb - Embedded GNU C Library: Shared libraries - udeb (udeb)
 libnss-dns-udeb - Embedded GNU C Library: NSS helper for DNS - udeb (udeb)
 libnss-files-udeb - Embedded GNU C Library: NSS helper for files - udeb (udeb)
 locales    - Embedded GNU C Library: National Language (locale) data [support]
 locales-all - Embedded GNU C Library: Precompiled locale data
 nscd       - Embedded GNU C Library: Name Service Cache Daemon
Closes: 812441 812445 812455 813187
Changes: 
 eglibc (2.11.3-4+deb6u9) squeeze-lts; urgency=medium
 .
   * Non-maintainer upload by the Squeeze LTS Team.
   * Fix CVE-2014-9761: Unbounded stack allocation in nan* functions.
     Closes: #813187.
   * Fix CVE-2015-8776: Segmentation fault caused by passing out-of-range data
     to strftime(). Closes: #812445.
   * Fix CVE-2015-8778: Integer overflow in hcreate and hcreate_r.
     Closes: #812441.
   * Fix CVE-2015-8779: Multiple unbounded stack allocations in catopen().
     Closes: #812455.
Checksums-Sha1: 
 d285a4ba6656a9215323d0a3b29364a5079331d2 3250 eglibc_2.11.3-4+deb6u9.dsc
 c6e3d5d1a67869e72e943c3f1a62c6cda05e08e2 990384 eglibc_2.11.3-4+deb6u9.diff.gz
 bddc5a15d157130398f22a783ef05d0e922155a9 1854040 glibc-doc_2.11.3-4+deb6u9_all.deb
 0e2f1de9f48d5e8d5e83c128ebe00a96aeac7aa2 11227394 eglibc-source_2.11.3-4+deb6u9_all.deb
 8ce4e5d85fe4f0f01d89b42c0fdc0c8f195d2c63 4760432 locales_2.11.3-4+deb6u9_all.deb
 f724ce90524e9c4f215b95f598978a4cb0052ebc 4306982 libc6_2.11.3-4+deb6u9_amd64.deb
 aeff9f282a19286a436540f589206706e2d67b46 2617498 libc6-dev_2.11.3-4+deb6u9_amd64.deb
 bfab507e9852cf43d0d657a5c26f71272290dbd8 2059568 libc6-prof_2.11.3-4+deb6u9_amd64.deb
 ac75d66f7be3ab85af41522779144d6a755be63c 1574938 libc6-pic_2.11.3-4+deb6u9_amd64.deb
 f3157da6152cfbd6b2ad000ac70d6ed2b7d29170 756370 libc-bin_2.11.3-4+deb6u9_amd64.deb
 2c1aa47f91cf179cad9d29eb43eb90d0cb108a95 211242 libc-dev-bin_2.11.3-4+deb6u9_amd64.deb
 a98dd2ddcd9349c9d39186fbfab154b5a0212bf7 3603888 locales-all_2.11.3-4+deb6u9_amd64.deb
 47204594544cd52f09ba79e7f6fdccba21a3a897 3841374 libc6-i386_2.11.3-4+deb6u9_amd64.deb
 402bbfdc5fa0b487f0806038b0c87e61b59ce2f4 1556430 libc6-dev-i386_2.11.3-4+deb6u9_amd64.deb
 d3632518540989a16828be0cc026f521ba45ad9e 201130 nscd_2.11.3-4+deb6u9_amd64.deb
 10a2679e709efdc14e6b19970bbf7aac84ffbef5 10585246 libc6-dbg_2.11.3-4+deb6u9_amd64.deb
 42ceb550ab69c496e012ecb0954706894a5a1e4a 1172628 libc6-udeb_2.11.3-4+deb6u9_amd64.udeb
 b2b10c8f1996b6a60be02b143f76c6c42f817e44 11108 libnss-dns-udeb_2.11.3-4+deb6u9_amd64.udeb
 a401243af0d410ead7c6d11de174c7f5f89fb28c 20142 libnss-files-udeb_2.11.3-4+deb6u9_amd64.udeb
Checksums-Sha256: 
 ef8f8103b778881d68744b53a79e2185e7d78248e59fea8e8179b85e923e006f 3250 eglibc_2.11.3-4+deb6u9.dsc
 dc6c661e3406390b25cd7ae0d16b2b7b979a9cf6f874b1f710aa17e77a430e82 990384 eglibc_2.11.3-4+deb6u9.diff.gz
 6aa2b554cdfd61cc18e8d1cb5579d2d4abcd4990a3198ae5af7456abcae9b049 1854040 glibc-doc_2.11.3-4+deb6u9_all.deb
 fe3c812bdaaf33d60a0378e10bbe358aff3d14435e65f361b5bc59a8df7c1e4d 11227394 eglibc-source_2.11.3-4+deb6u9_all.deb
 330c9b18df2f3f77a3b604ce68e76bbcaabf288565632e5334418415170cadb8 4760432 locales_2.11.3-4+deb6u9_all.deb
 bc8a03cdacd587c77142fbbaf1f31e283dde995256fdfe73e6d1a0dd2ec161c9 4306982 libc6_2.11.3-4+deb6u9_amd64.deb
 aee39e3a8e0ecb4023b0369f8cc3940e3814955be16bfb26af969c8d38d70dc1 2617498 libc6-dev_2.11.3-4+deb6u9_amd64.deb
 d4620d33e1bdae5dd447d26e8c4a4f095d3bd7192a7bffc2f77b82e9357d6091 2059568 libc6-prof_2.11.3-4+deb6u9_amd64.deb
 155ff7eccf46262c7850ec9128a49b49e18de2743fcc37681b6fe99fbb7f03c4 1574938 libc6-pic_2.11.3-4+deb6u9_amd64.deb
 27d840767004f1d6b99fb6141b786cc625f2448ea6dc3ea3ba4246f3476f4bee 756370 libc-bin_2.11.3-4+deb6u9_amd64.deb
 df0cd96ad5c85b41f1ce6016831e0673d7487e963b0db8a9f9e66d19a68001a8 211242 libc-dev-bin_2.11.3-4+deb6u9_amd64.deb
 2dcf5f02d0f2ac807b6fa8dbfc3940b075f868413402fdb96765e15b1f64854a 3603888 locales-all_2.11.3-4+deb6u9_amd64.deb
 ce6e6ea558e39dbba7361740a255ce3f267821679d04e0561fc9dd79d52bfd39 3841374 libc6-i386_2.11.3-4+deb6u9_amd64.deb
 42ebda60737b28fc468129033ccbf24321610bdabffa7fe4492bc3902e0bd194 1556430 libc6-dev-i386_2.11.3-4+deb6u9_amd64.deb
 f2da6a0a8ef3d758cecf4efb73eb3ff6db41172ba4c0493a94ceba1122c4bac1 201130 nscd_2.11.3-4+deb6u9_amd64.deb
 2e8d10250605952b77ba95f8704fc4f2efe13870d4318aedb981d6240470013c 10585246 libc6-dbg_2.11.3-4+deb6u9_amd64.deb
 f8ca756e8af00a2557ded9885b45716390444e572f8b876b8d14256e97dfc82a 1172628 libc6-udeb_2.11.3-4+deb6u9_amd64.udeb
 ceff527a12b8d0a614c10fc806439380d6c4aa28d637644a32787fdda7c1e9f7 11108 libnss-dns-udeb_2.11.3-4+deb6u9_amd64.udeb
 ffe11f1adf95eafb3e09858525aeb728f62efb352f8edb3afe8279aa8cbf3438 20142 libnss-files-udeb_2.11.3-4+deb6u9_amd64.udeb
Files: 
 aa1c9f9f62a8cc7e7291686c7e7bb04f 3250 libs required eglibc_2.11.3-4+deb6u9.dsc
 74e798764a617a610c6c9cba9894e1d8 990384 libs required eglibc_2.11.3-4+deb6u9.diff.gz
 34619f5be90b1c0b32019d15f8a9d0b7 1854040 doc optional glibc-doc_2.11.3-4+deb6u9_all.deb
 24021664a2f2cd30df28cd9fb3f755c3 11227394 devel optional eglibc-source_2.11.3-4+deb6u9_all.deb
 7dde06777c7fcb3c5bbee9e250623eb3 4760432 localization standard locales_2.11.3-4+deb6u9_all.deb
 e4195fc5ce566d32e883cd9f0584a23a 4306982 libs required libc6_2.11.3-4+deb6u9_amd64.deb
 b1e2e889b57b79d86d7b7d82af741ec0 2617498 libdevel optional libc6-dev_2.11.3-4+deb6u9_amd64.deb
 b03c6c648fc2268435b82917b5bddb05 2059568 libdevel extra libc6-prof_2.11.3-4+deb6u9_amd64.deb
 ad8b26bd99aa09eaa2b79abc91b74c4a 1574938 libdevel optional libc6-pic_2.11.3-4+deb6u9_amd64.deb
 7df25d65ee57ce1d4f123f88746c95d3 756370 libs required libc-bin_2.11.3-4+deb6u9_amd64.deb
 24d063a21ff0a3e71b0e35bc3ef0fcba 211242 libdevel optional libc-dev-bin_2.11.3-4+deb6u9_amd64.deb
 9cc041aa64b4023e293f59ba45dda337 3603888 localization extra locales-all_2.11.3-4+deb6u9_amd64.deb
 23860c3d0565dd369f080895249fcee0 3841374 libs optional libc6-i386_2.11.3-4+deb6u9_amd64.deb
 fa37b70e86eacd2486cead37d5e08a4f 1556430 libdevel optional libc6-dev-i386_2.11.3-4+deb6u9_amd64.deb
 49c7cc517104acb2fd1c4de2bf015558 201130 admin optional nscd_2.11.3-4+deb6u9_amd64.deb
 190e2a23584d79c93dae5017487b2f84 10585246 debug extra libc6-dbg_2.11.3-4+deb6u9_amd64.deb
 a86f42229a1ac3ea7cabee88eae8bcd1 1172628 debian-installer extra libc6-udeb_2.11.3-4+deb6u9_amd64.udeb
 a71cc1f8fdfc21370327ae4ecebb4433 11108 debian-installer extra libnss-dns-udeb_2.11.3-4+deb6u9_amd64.udeb
 1a6890e68feb92099a7e5847c101e82c 20142 debian-installer extra libnss-files-udeb_2.11.3-4+deb6u9_amd64.udeb
Package-Type: udeb

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJWtIYiAAoJEN5v/bjI1ki9EGUP/iFIZkQUf0eWof4J9uog+s1f
7V1aMi4thzg7BXzUGu/16Q3RACbwLJzEYu8Cqk4YiAoLbvd4vQKa6DhCk3RnZWdE
uHnH2oCIqZ1+etPiQ0oqOvnPSkOpevaSnNmyIj8Fhr0FWSCwUuH2XNK8i3Q10p5N
NPBPrQ4jf3WmpocTkCVTf8MlxcBQUyRs5KiTDTdkX2AV9mAPCVMUbDp0Ss0yXvNe
tQau+iYDvljzOJKb2CSI0+TMWCPJvLwWFGeXyIRhRQcQoWWGvxCrCIVpT3DPJBZG
McXPB7dt8YcrihAIUf9a4PgiIeQRq31A0rhH5bT5VOKIx0z4r9TMQyWv4EsJZAQs
SSPkBeiMz4TTd5lcRck+l9zI0pj1qseE/B6cf9a056nOFp7GOn2pcbBcoFm9BxXP
u8IFNaC8Cq2ReYPC/FJGYiXbcrDg6dLSvfefhgPkV0OXNz8nxiyLAkuB+UmQbuYX
VzC/mWI13RKI1PvPSmmqLMrLWaC2Ua5KaN+DgXSC0iyjcj/Xx1US8xmWnSlGYzQW
eIDi/bkS/BXCeWKhKOr8cw6hH2OUI6ngO+YIsCOsDM6L35Ej9Q+uINNDstQH+LGt
qlaPIxitJxASSXZVlPBbSU+4Kit9qJ6HbG5IZ/8T2OW7/7JqOSS1O/d7SZLEztOe
EbYJ35RQ9H08V/m06EzN
=Cu/n
-----END PGP SIGNATURE-----

--- End Message ---

Reply to: