Your message dated Sun, 13 Aug 2023 12:57:57 +0000 with message-id <8958838.mb39LrW5L8@portable-bastien> and subject line Already fixed: has caused the Debian Bug report #1041111, regarding sox: CVE-2023-34318 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact owner@bugs.debian.org immediately.) -- 1041111: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1041111 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
--- Begin Message ---
- To: submit@bugs.debian.org
- Subject: sox: CVE-2023-34318
- From: Moritz Mühlenhoff <jmm@inutil.org>
- Date: Fri, 14 Jul 2023 23:43:32 +0200
- Message-id: <ZLHBhDQZu6kg1rXw@pisco.westfalen.local>
Source: sox X-Debbugs-CC: team@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for sox. CVE-2023-34318[0]: | A heap buffer overflow vulnerability was found in sox, in the | startread function at sox/src/hcom.c:160:41. This flaw can lead to a | denial of service, code execution, or information disclosure. https://bugzilla.redhat.com/show_bug.cgi?id=2212283 https://sourceforge.net/p/sox/bugs/368/ If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2023-34318 https://www.cve.org/CVERecord?id=CVE-2023-34318 Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
- To: 1041111-done@bugs.debian.org
- Subject: Already fixed:
- From: Bastien Roucariès <rouca@debian.org>
- Date: Sun, 13 Aug 2023 12:57:57 +0000
- Message-id: <8958838.mb39LrW5L8@portable-bastien>
Fixed along CVE-2021-23159Attachment: signature.asc
Description: This is a digitally signed message part.
--- End Message ---