Your message dated Sun, 26 Feb 2023 09:55:47 -0300 with message-id <5793244.DvuYhMxLoT@minerva> and subject line Closing as not relevant for this package has caused the Debian Bug report #1031873, regarding qtbase-opensource-src-gles: CVE-2023-24607 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact owner@bugs.debian.org immediately.) -- 1031873: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1031873 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
--- Begin Message ---
- To: submit@bugs.debian.org
- Subject: qtbase-opensource-src-gles: CVE-2023-24607
- From: Moritz Mühlenhoff <jmm@inutil.org>
- Date: Fri, 24 Feb 2023 17:03:10 +0100
- Message-id: <Y/jfvluYuDqDgtEA@pisco.westfalen.local>
Source: qtbase-opensource-src-gles X-Debbugs-CC: team@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for qtbase-opensource-src-gles. CVE-2023-24607[0]: When using the Qt SQL ODBC driver plugin, then it is possible to trigger a DOS with a specifically crafted string https://www.qt.io/blog/security-advisory-qt-sql-odbc-driver-plugin https://download.qt.io/official_releases/qt/5.15/CVE-2023-24607-qtbase-5.15.diff If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2023-24607 https://www.cve.org/CVERecord?id=CVE-2023-24607 Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
- To: 1031873-done@bugs.debian.org
- Subject: Closing as not relevant for this package
- From: Lisandro Damian Nicanor Perez Meyer <perezmeyer@gmail.com>
- Date: Sun, 26 Feb 2023 09:55:47 -0300
- Message-id: <5793244.DvuYhMxLoT@minerva>
Hi! I'm closing this bug as qtbase-opensource-src-gles does not produces the SQL plugins used by Qt, only a GLES-enabled libqt5gui5, so CVE-2023-24607 does not applies here. Dmitry already commited a fix for qtbase-opensource-src and Patrick took care of qt6-base. Thanks a lot for your effort and your bug report!!Attachment: signature.asc
Description: This is a digitally signed message part.
--- End Message ---