Debian Bug report logs - #560940
CVE-2009-3560 and CVE-2009-3720 denial-of-services

version graph

Package: tla; Maintainer for tla is Debian QA Group <packages@qa.debian.org>; Source for tla is src:tla.

Reported by: Michael Gilbert <michael.s.gilbert@gmail.com>

Date: Sun, 13 Dec 2009 04:09:56 UTC

Severity: serious

Tags: patch, security

Fixed in versions tla/1.3.5+dfsg-15, tla/1.3.5+dfsg-14+lenny1

Done: Sylvain Beucler <beuc@beuc.net>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#560940; Package tla. (Sun, 13 Dec 2009 04:09:59 GMT) Full text and rfc822 format available.

Acknowledgement sent to Michael Gilbert <michael.s.gilbert@gmail.com>:
New Bug report received and forwarded. Copy sent to Debian QA Group <packages@qa.debian.org>. (Sun, 13 Dec 2009 04:09:59 GMT) Full text and rfc822 format available.

Message #5 received at submit@bugs.debian.org (full text, mbox):

From: Michael Gilbert <michael.s.gilbert@gmail.com>
To: submit@bugs.debian.org
Subject: CVE-2009-3560 and CVE-2009-3720 denial-of-services
Date: Sat, 12 Dec 2009 22:54:57 -0500
package: tla
severity: serious
tags: security

Hi,

The following CVE (Common Vulnerabilities & Exposures) ids were
published for expat.  I have determined that this package embeds a
vulnerable copy of xmlparse.c and xmltok_impl.c.  However, since this is
a mass bug filing (due to so many packages embedding expat), I have
not had time to determine whether the vulnerable code is actually
present in any of the binary packages derived from this source package.
Please determine whether this is the case. If the binary packages are
not affected, please feel free to close the bug with a message
containing the details of what you did to check.

CVE-2009-3560[0]:
| The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1,
| as used in the XML-Twig module for Perl, allows context-dependent
| attackers to cause a denial of service (application crash) via an XML
| document with malformed UTF-8 sequences that trigger a buffer
| over-read, related to the doProlog function in lib/xmlparse.c, a
| different vulnerability than CVE-2009-2625 and CVE-2009-3720.

CVE-2009-3720[1]:
| The updatePosition function in lib/xmltok_impl.c in libexpat in Expat
| 2.0.1, as used in Python, PyXML, w3c-libwww, and other software,
| allows context-dependent attackers to cause a denial of service
| (application crash) via an XML document with crafted UTF-8 sequences
| that trigger a buffer over-read, a different vulnerability than
| CVE-2009-2625.

These issues also affect old versions of expat, so this package in etch
and lenny is very likely affected.  This is a low-severity security
issue, so DSAs will not be issued to correct these problems.  However,
you can optionally submit a proposed-update to the release team for
inclusion in the next stable point releases.  If you plan to do this, 
please open new bugs and include the security tag so we are aware that
you are working on that.

For further information see [0],[1],[2],[3].  In particular, [2] and [3]
are links to the patches for CVE-2009-3560 and CVE-2009-3720
respectively. Note that the ideal solution would be to make use of the
system expat so only one package will need to be updated for future
security issues. Preferably in your update to unstable, alter your
package to make use of the system expat.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3560
    http://security-tracker.debian.org/tracker/CVE-2009-3560
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3720
    http://security-tracker.debian.org/tracker/CVE-2009-3720
[2]
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.165
[3]
http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&r2=1.15&view=patch




Information forwarded to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#560940; Package tla. (Sun, 13 Dec 2009 15:33:54 GMT) Full text and rfc822 format available.

Acknowledgement sent to Michael Gilbert <michael.s.gilbert@gmail.com>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>. (Sun, 13 Dec 2009 15:33:54 GMT) Full text and rfc822 format available.

Message #10 received at 560940@bugs.debian.org (full text, mbox):

From: Michael Gilbert <michael.s.gilbert@gmail.com>
To: 560912@bugs.debian.org, 560913@bugs.debian.org, 560914@bugs.debian.org, 560915@bugs.debian.org, 560916@bugs.debian.org, 560917@bugs.debian.org, 560918@bugs.debian.org, 560919@bugs.debian.org, 560920@bugs.debian.org, 560921@bugs.debian.org, 560922@bugs.debian.org, 560923@bugs.debian.org, 560924@bugs.debian.org, 560925@bugs.debian.org, 560926@bugs.debian.org, 560927@bugs.debian.org, 560928@bugs.debian.org, 560929@bugs.debian.org, 560930@bugs.debian.org, 560931@bugs.debian.org, 560932@bugs.debian.org, 560933@bugs.debian.org, 560934@bugs.debian.org, 560935@bugs.debian.org, 560936@bugs.debian.org, 560937@bugs.debian.org, 560938@bugs.debian.org, 560939@bugs.debian.org, 560940@bugs.debian.org, 560941@bugs.debian.org, 560942@bugs.debian.org, 560943@bugs.debian.org, 560944@bugs.debian.org, 560945@bugs.debian.org, 560946@bugs.debian.org, 560947@bugs.debian.org, 560948@bugs.debian.org, 560949@bugs.debian.org, 560950@bugs.debian.org, 560951@bugs.debian.org
Subject: Expat issues update
Date: Sun, 13 Dec 2009 10:29:27 -0500
Hi all,

In order to guarantee that the system expat is used, the
'--with-expat=sys' configure argument must be used.  If you think
your package is already using the system expat, or if you are updating
your package to use the system expat, please check to make sure that
this option is being used. Thanks.

Mike




Information forwarded to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#560940; Package tla. (Sun, 13 Dec 2009 16:28:05 GMT) Full text and rfc822 format available.

Acknowledgement sent to Matthias Klose <doko@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>. (Sun, 13 Dec 2009 16:28:05 GMT) Full text and rfc822 format available.

Message #15 received at 560940@bugs.debian.org (full text, mbox):

From: Matthias Klose <doko@debian.org>
To: Michael Gilbert <michael.s.gilbert@gmail.com>, 560912@bugs.debian.org
Cc: 560913@bugs.debian.org, 560914@bugs.debian.org, 560915@bugs.debian.org, 560916@bugs.debian.org, 560917@bugs.debian.org, 560918@bugs.debian.org, 560919@bugs.debian.org, 560920@bugs.debian.org, 560921@bugs.debian.org, 560922@bugs.debian.org, 560923@bugs.debian.org, 560924@bugs.debian.org, 560925@bugs.debian.org, 560926@bugs.debian.org, 560927@bugs.debian.org, 560928@bugs.debian.org, 560929@bugs.debian.org, 560930@bugs.debian.org, 560931@bugs.debian.org, 560932@bugs.debian.org, 560933@bugs.debian.org, 560934@bugs.debian.org, 560935@bugs.debian.org, 560936@bugs.debian.org, 560937@bugs.debian.org, 560938@bugs.debian.org, 560939@bugs.debian.org, 560940@bugs.debian.org, 560941@bugs.debian.org, 560942@bugs.debian.org, 560943@bugs.debian.org, 560944@bugs.debian.org, 560945@bugs.debian.org, 560946@bugs.debian.org, 560947@bugs.debian.org, 560948@bugs.debian.org, 560949@bugs.debian.org, 560950@bugs.debian.org, 560951@bugs.debian.org
Subject: Re: Bug#560912: Expat issues update
Date: Sun, 13 Dec 2009 17:21:26 +0100
On 13.12.2009 16:29, Michael Gilbert wrote:
> Hi all,
>
> In order to guarantee that the system expat is used, the
> '--with-expat=sys' configure argument must be used.  If you think
> your package is already using the system expat, or if you are updating
> your package to use the system expat, please check to make sure that
> this option is being used. Thanks.

there's no such option for python, which uses a modified copy of expat.





Information forwarded to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#560940; Package tla. (Mon, 14 Dec 2009 07:57:56 GMT) Full text and rfc822 format available.

Acknowledgement sent to Mike Hommey <mh@glandium.org>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>. (Mon, 14 Dec 2009 07:57:56 GMT) Full text and rfc822 format available.

Message #20 received at 560940@bugs.debian.org (full text, mbox):

From: Mike Hommey <mh@glandium.org>
To: 560932@bugs.debian.org
Cc: Michael Gilbert <michael.s.gilbert@gmail.com>, 560912@bugs.debian.org, 560913@bugs.debian.org, 560914@bugs.debian.org, 560915@bugs.debian.org, 560916@bugs.debian.org, 560917@bugs.debian.org, 560918@bugs.debian.org, 560919@bugs.debian.org, 560920@bugs.debian.org, 560921@bugs.debian.org, 560922@bugs.debian.org, 560923@bugs.debian.org, 560924@bugs.debian.org, 560925@bugs.debian.org, 560926@bugs.debian.org, 560927@bugs.debian.org, 560928@bugs.debian.org, 560929@bugs.debian.org, 560930@bugs.debian.org, 560931@bugs.debian.org, 560933@bugs.debian.org, 560934@bugs.debian.org, 560935@bugs.debian.org, 560936@bugs.debian.org, 560937@bugs.debian.org, 560938@bugs.debian.org, 560939@bugs.debian.org, 560940@bugs.debian.org, 560941@bugs.debian.org, 560942@bugs.debian.org, 560943@bugs.debian.org, 560944@bugs.debian.org, 560945@bugs.debian.org, 560946@bugs.debian.org, 560947@bugs.debian.org, 560948@bugs.debian.org, 560949@bugs.debian.org, 560950@bugs.debian.org, 560951@bugs.debian.org
Subject: Re: Bug#560932: Bug#560912: Expat issues update
Date: Mon, 14 Dec 2009 08:55:03 +0100
On Sun, Dec 13, 2009 at 05:21:26PM +0100, Matthias Klose wrote:
> On 13.12.2009 16:29, Michael Gilbert wrote:
> >Hi all,
> >
> >In order to guarantee that the system expat is used, the
> >'--with-expat=sys' configure argument must be used.  If you think
> >your package is already using the system expat, or if you are updating
> >your package to use the system expat, please check to make sure that
> >this option is being used. Thanks.
> 
> there's no such option for python, which uses a modified copy of expat.

Likewise with mozilla, which uses a heavily modified copy of expat.




Information forwarded to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#560940; Package tla. (Mon, 14 Dec 2009 12:15:53 GMT) Full text and rfc822 format available.

Acknowledgement sent to Ove Kaaven <ovek@arcticnet.no>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>. (Mon, 14 Dec 2009 12:15:53 GMT) Full text and rfc822 format available.

Message #25 received at 560940@bugs.debian.org (full text, mbox):

From: Ove Kaaven <ovek@arcticnet.no>
To: Mike Hommey <mh@glandium.org>, 560937@bugs.debian.org
Cc: 560932@bugs.debian.org, 560948@bugs.debian.org, 560945@bugs.debian.org, 560935@bugs.debian.org, 560946@bugs.debian.org, 560921@bugs.debian.org, 560939@bugs.debian.org, 560949@bugs.debian.org, 560917@bugs.debian.org, 560924@bugs.debian.org, 560938@bugs.debian.org, 560919@bugs.debian.org, 560913@bugs.debian.org, 560916@bugs.debian.org, 560943@bugs.debian.org, 560920@bugs.debian.org, 560912@bugs.debian.org, 560931@bugs.debian.org, Michael Gilbert <michael.s.gilbert@gmail.com>, 560918@bugs.debian.org, 560930@bugs.debian.org, 560940@bugs.debian.org, 560951@bugs.debian.org, 560933@bugs.debian.org, 560914@bugs.debian.org, 560922@bugs.debian.org, 560941@bugs.debian.org, 560926@bugs.debian.org, 560923@bugs.debian.org, 560942@bugs.debian.org, 560936@bugs.debian.org, 560915@bugs.debian.org, 560950@bugs.debian.org, 560927@bugs.debian.org, 560928@bugs.debian.org, 560947@bugs.debian.org, 560929@bugs.debian.org, 560944@bugs.debian.org, 560934@bugs.debian.org, 560925@bugs.debian.org
Subject: Re: [pkg-fgfs-crew] Bug#560937: Bug#560932: Bug#560912: Expat issues update
Date: Mon, 14 Dec 2009 12:17:17 +0100
Mike Hommey skrev:
> On Sun, Dec 13, 2009 at 05:21:26PM +0100, Matthias Klose wrote:
>> On 13.12.2009 16:29, Michael Gilbert wrote:
>>> Hi all,
>>>
>>> In order to guarantee that the system expat is used, the
>>> '--with-expat=sys' configure argument must be used.  If you think
>>> your package is already using the system expat, or if you are updating
>>> your package to use the system expat, please check to make sure that
>>> this option is being used. Thanks.
>> there's no such option for python, which uses a modified copy of expat.
> 
> Likewise with mozilla, which uses a heavily modified copy of expat.

And I think the xml parser in simgear was ripped from some version of
mozilla. (Of course, I wouldn't consider a security flaw in a flight
simulator library as critical as one in an actual web browser or
anything, so I'm not sure how much I need to worry...)




Information forwarded to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#560940; Package tla. (Mon, 14 Dec 2009 23:00:02 GMT) Full text and rfc822 format available.

Acknowledgement sent to Sylvain Beucler <beuc@beuc.net>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>. (Mon, 14 Dec 2009 23:00:02 GMT) Full text and rfc822 format available.

Message #30 received at 560940@bugs.debian.org (full text, mbox):

From: Sylvain Beucler <beuc@beuc.net>
To: 560940@bugs.debian.org
Subject: Re: CVE-2009-3560 and CVE-2009-3720 denial-of-services
Date: Mon, 14 Dec 2009 23:58:36 +0100
[Message part 1 (text/plain, inline)]
I'm having a look at this.

I had worked on this package a while ago, and I'm currently doing a NM
Tasks&Skills, so it's a pleasure ;)

-- 
Sylvain
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#560940; Package tla. (Mon, 14 Dec 2009 23:42:06 GMT) Full text and rfc822 format available.

Acknowledgement sent to Sylvain Beucler <beuc@beuc.net>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>. (Mon, 14 Dec 2009 23:42:06 GMT) Full text and rfc822 format available.

Message #35 received at 560940@bugs.debian.org (full text, mbox):

From: Sylvain Beucler <beuc@beuc.net>
To: 560940@bugs.debian.org
Cc: Ben Hutchings <ben@decadent.org.uk>
Subject: Re: Bug#560940: CVE-2009-3560 and CVE-2009-3720 denial-of-services
Date: Tue, 15 Dec 2009 00:39:23 +0100
[Message part 1 (text/plain, inline)]
Here's the patch.

I'll also ask my AM to have a look at it.

 interdiff tla_1.3.5+dfsg-14.diff tla_1.3.5+dfsg-15.diff|diffstat
 debian/patches/06-disable_builtin_expat.dpatch |   40 
 debian/patches/06-relibtoolize.dpatch          |46129 -------------------------
 tla-1.3.5+dfsg/debian/changelog                |    7 
 tla-1.3.5+dfsg/debian/control                  |    2 
 tla-1.3.5+dfsg/debian/patches/00list           |    2 
 tla-1.3.5+dfsg/debian/rules                    |    7 
 6 files changed, 54 insertions(+), 46133 deletions(-)

-- 
Sylvain
[tla.diff (text/x-diff, attachment)]
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#560940; Package tla. (Tue, 15 Dec 2009 12:36:05 GMT) Full text and rfc822 format available.

Acknowledgement sent to Sylvain Beucler <beuc@beuc.net>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>. (Tue, 15 Dec 2009 12:36:05 GMT) Full text and rfc822 format available.

Message #40 received at 560940@bugs.debian.org (full text, mbox):

From: Sylvain Beucler <beuc@beuc.net>
To: 560940@bugs.debian.org
Cc: Ben Hutchings <ben@decadent.org.uk>
Subject: Re: Bug#560940: CVE-2009-3560 and CVE-2009-3720 denial-of-services
Date: Tue, 15 Dec 2009 13:31:30 +0100
[Message part 1 (text/plain, inline)]
Patched package available at:
http://mentors.debian.net/cgi-bin/sponsor-pkglist?action=details;package=tla

-- 
Sylvain
[signature.asc (application/pgp-signature, inline)]

Added tag(s) patch. Request was from Sylvain Beucler <beuc@beuc.net> to control@bugs.debian.org. (Fri, 18 Dec 2009 11:03:13 GMT) Full text and rfc822 format available.

Information forwarded to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#560940; Package tla. (Thu, 24 Dec 2009 11:39:02 GMT) Full text and rfc822 format available.

Acknowledgement sent to Sylvain Beucler <beuc@beuc.net>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>. (Thu, 24 Dec 2009 11:39:03 GMT) Full text and rfc822 format available.

Message #47 received at 560940@bugs.debian.org (full text, mbox):

From: Sylvain Beucler <beuc@beuc.net>
To: 560940@bugs.debian.org
Cc: Ben Hutchings <ben@decadent.org.uk>
Subject: Re: Bug#560940: CVE-2009-3560 and CVE-2009-3720 denial-of-services
Date: Thu, 24 Dec 2009 12:35:41 +0100
[Message part 1 (text/plain, inline)]
On Tue, Dec 15, 2009 at 01:31:30PM +0100, Sylvain Beucler wrote:
> Patched package available at:
> http://mentors.debian.net/cgi-bin/sponsor-pkglist?action=details;package=tla

Ben noticed that part of the bundled libexpat was still used.

I missed 2 "-I ../lib/expat" occurrences, I'll upload a new version in
a bit.

-- 
Sylvain
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#560940; Package tla. (Thu, 24 Dec 2009 14:48:06 GMT) Full text and rfc822 format available.

Acknowledgement sent to Sylvain Beucler <beuc@beuc.net>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>. (Thu, 24 Dec 2009 14:48:06 GMT) Full text and rfc822 format available.

Message #52 received at 560940@bugs.debian.org (full text, mbox):

From: Sylvain Beucler <beuc@beuc.net>
To: 560940@bugs.debian.org
Cc: Ben Hutchings <ben@decadent.org.uk>
Subject: Re: Bug#560940: CVE-2009-3560 and CVE-2009-3720 denial-of-services
Date: Thu, 24 Dec 2009 15:46:50 +0100
[Message part 1 (text/plain, inline)]
> > Patched package available at:
> > http://mentors.debian.net/cgi-bin/sponsor-pkglist?action=details;package=tla

The fixed version is up.

$ interdiff tla1.diff tla2.diff | diffstat
 patches/06-disable_builtin_expat.dpatch |   50 +++++++++++++++++++-------------
 rules                                   |    5 +--
 2 files changed, 34 insertions(+), 21 deletions(-)


diff -u tla-1.3.5+dfsg/debian/rules tla-1.3.5+dfsg/debian/rules
--- tla-1.3.5+dfsg/debian/rules
+++ tla-1.3.5+dfsg/debian/rules
@@ -56,8 +56,9 @@
 
        # Disable builtin expat
        # See also patches/06-disable_builtin_expat.dpatch
-       rm -f src/expat/PLUGIN/AUTOCONF
-       rm -f src/expat/PLUGIN/REQ
+       #rm -f src/expat/PLUGIN/AUTOCONF
+       #rm -f src/expat/PLUGIN/REQ
+       rm -rf src/expat/  # Let's play safe
        rm -f src/libneon/PLUGIN/REQ
 
        # Cleaning package
diff -u tla-1.3.5+dfsg/debian/patches/06-disable_builtin_expat.dpatch tla-1.3.5+dfsg/debian/patches/06-disable_builtin_expat.dpatch
--- tla-1.3.5+dfsg/debian/patches/06-disable_builtin_expat.dpatch
+++ tla-1.3.5+dfsg/debian/patches/06-disable_builtin_expat.dpatch
@@ -2,22 +2,12 @@
 ## 06-disable_builtin_expat.dpatch by Sylvain Beucler <beuc@beuc.net>
 ##
 ## All lines beginning with `## DP:' are a description of the patch.
-## DP: use system expat to address CVE-2009-3560 and CVE-2009-3720 DoS
-## DP: see also debian/rules, target 'clean'
+## DP: No description.
 
---- tla-1.3.5+dfsg.orig/src/tla/tla/Makefile.in
-+++ tla-1.3.5+dfsg/src/tla/tla/Makefile.in
-@@ -21,7 +21,7 @@
- endif
- 
- $(programs):%$(cfg__exec_suffix):%.o $(thelib) $(filter-out -L%, $(filter-out -l%, $(libs)))
--      $(SHELL) $(objroot)/libneon/libtool --mode=link $(CC) $(CFLAGS) -L../../expat -o $@ $< $(thelib) $(libs)
-+      $(SHELL) $(objroot)/libneon/libtool --mode=link $(CC) $(CFLAGS) -o $@ $< $(thelib) $(libs)
- 
- clean: clean-prog
- 
---- tla-1.3.5+dfsg.orig/src/libneon/Makefile.in
-+++ tla-1.3.5+dfsg/src/libneon/Makefile.in
+@DPATCH@
+diff -urNad tla-1.3.5+dfsg~/src/libneon/Makefile.in tla-1.3.5+dfsg/src/libneon/Makefile.in
+--- tla-1.3.5+dfsg~/src/libneon/Makefile.in    2009-12-24 12:30:27.000000000 +0100
++++ tla-1.3.5+dfsg/src/libneon/Makefile.in     2009-12-24 12:30:41.000000000 +0100
 @@ -33,7 +33,7 @@
  
  @SET_MAKE@
@@ -30,11 +20,33 @@
---- tla-1.3.5+dfsg.orig/src/libneon/src/Makefile.in
-+++ tla-1.3.5+dfsg/src/libneon/src/Makefile.in
-@@ -26,7 +26,7 @@
+diff -urNad tla-1.3.5+dfsg~/src/libneon/src/Makefile.in tla-1.3.5+dfsg/src/libneon/src/Makefile.in
+--- tla-1.3.5+dfsg~/src/libneon/src/Makefile.in        2009-12-24 12:30:27.000000000 +0100
++++ tla-1.3.5+dfsg/src/libneon/src/Makefile.in 2009-12-24 12:31:28.000000000 +0100
+@@ -25,14 +25,14 @@
+ 
  # Flags
  CPPFLAGS = @DEFS@ @CPPFLAGS@
- CFLAGS = @CFLAGS@  -I$(top_builddir) -I$(top_srcdir)/../expat/lib @NEON_CFLAGS@
+-CFLAGS = @CFLAGS@  -I$(top_builddir) -I$(top_srcdir)/../expat/lib @NEON_CFLAGS@
 -LDFLAGS = -L$(top_builddir)/../expat @LDFLAGS@
++CFLAGS = @CFLAGS@  -I$(top_builddir) @NEON_CFLAGS@
 +LDFLAGS = @LDFLAGS@
  NEON_LINK_FLAGS = @NEON_LINK_FLAGS@
  # Note: don't substitute @LIBS@ in here; during a bundled
  # build of this directory, @LIBS@ may include -lneon.
+ LIBS = @NEON_LIBS@ @NEON_LTLIBS@
+ 
+-COMPILE = $(CC) $(CPPFLAGS) $(CFLAGS)  -I$(top_builddir) -I$(top_srcdir)/../expat/lib @NEON_CFLAGS@
++COMPILE = $(CC) $(CPPFLAGS) $(CFLAGS)  -I$(top_builddir) @NEON_CFLAGS@
+ LINK = $(LIBTOOL) --quiet --mode=link $(CC) $(LDFLAGS)
+ 
+ NEON_BASEOBJS = ne_request.@NEON_OBJEXT@ ne_session.@NEON_OBJEXT@         \
+diff -urNad tla-1.3.5+dfsg~/src/tla/tla/Makefile.in tla-1.3.5+dfsg/src/tla/tla/Makefile.in
+--- tla-1.3.5+dfsg~/src/tla/tla/Makefile.in    2009-12-24 12:30:27.000000000 +0100
++++ tla-1.3.5+dfsg/src/tla/tla/Makefile.in     2009-12-24 12:30:41.000000000 +0100
+@@ -21,7 +21,7 @@
+ endif
+ 
+ $(programs):%$(cfg__exec_suffix):%.o $(thelib) $(filter-out -L%, $(filter-out -l%, $(libs)))
+-      $(SHELL) $(objroot)/libneon/libtool --mode=link $(CC) $(CFLAGS) -L../../expat -o $@ $< $(thelib) $(libs)
++      $(SHELL) $(objroot)/libneon/libtool --mode=link $(CC) $(CFLAGS) -o $@ $< $(thelib) $(libs)
+ 
+ clean: clean-prog
+ 
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian QA Group <packages@qa.debian.org>:
Bug#560940; Package tla. (Mon, 04 Jan 2010 10:03:13 GMT) Full text and rfc822 format available.

Acknowledgement sent to Daniel Leidert <daniel.leidert@wgdd.de>:
Extra info received and forwarded to list. Copy sent to Debian QA Group <packages@qa.debian.org>. (Mon, 04 Jan 2010 10:03:13 GMT) Full text and rfc822 format available.

Message #57 received at 560940@bugs.debian.org (full text, mbox):

From: Daniel Leidert <daniel.leidert@wgdd.de>
To: 560912@bugs.debian.org, 560913@bugs.debian.org, 560914@bugs.debian.org, 560915@bugs.debian.org, 560916@bugs.debian.org, 560917@bugs.debian.org, 560918@bugs.debian.org, 560919@bugs.debian.org, 560920@bugs.debian.org, 560921@bugs.debian.org, 560922@bugs.debian.org, 560923@bugs.debian.org, 560924@bugs.debian.org, 560925@bugs.debian.org, 560926@bugs.debian.org, 560927@bugs.debian.org, 560928@bugs.debian.org, 560929@bugs.debian.org, 560930@bugs.debian.org, 560931@bugs.debian.org, 560932@bugs.debian.org, 560933@bugs.debian.org, 560934@bugs.debian.org, 560935@bugs.debian.org, 560936@bugs.debian.org, 560937@bugs.debian.org, 560938@bugs.debian.org, 560939@bugs.debian.org, 560940@bugs.debian.org, 560941@bugs.debian.org, 560942@bugs.debian.org, 560943@bugs.debian.org, 560944@bugs.debian.org, 560945@bugs.debian.org, 560946@bugs.debian.org, 560947@bugs.debian.org, 560948@bugs.debian.org, 560949@bugs.debian.org, 560950@bugs.debian.org, 560951@bugs.debian.org
Subject: CVE-2009-3560: Revised patch
Date: Mon, 04 Jan 2010 08:40:26 +0100
[Message part 1 (text/plain, inline)]
Hi,

After fixing CVE-2009-3560 in the expat package [1] I was informed, that
it broke parsing [2] in some documents. After talking to upstream [3],
the fix for CVE-2009-3560 has been adjusted [4][5].

[1] http://bugs.debian.org/560901
[2] http://bugs.debian.org/561658
[3] http://mail.libexpat.org/pipermail/expat-discuss/2009-December/002644.html
[4] http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.166
[5] http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?view=log#rev1.166

Please note, that I just copied the bug-addresses from the mass bug
filing. I did not check, if you already fixed the issue or if this
information applies to you.

Regards, Daniel
[signature.asc (application/pgp-signature, inline)]

Reply sent to Sylvain Beucler <beuc@beuc.net>:
You have taken responsibility. (Sun, 10 Jan 2010 05:21:04 GMT) Full text and rfc822 format available.

Notification sent to Michael Gilbert <michael.s.gilbert@gmail.com>:
Bug acknowledged by developer. (Sun, 10 Jan 2010 05:21:04 GMT) Full text and rfc822 format available.

Message #62 received at 560940-close@bugs.debian.org (full text, mbox):

From: Sylvain Beucler <beuc@beuc.net>
To: 560940-close@bugs.debian.org
Subject: Bug#560940: fixed in tla 1.3.5+dfsg-15
Date: Sun, 10 Jan 2010 05:17:14 +0000
Source: tla
Source-Version: 1.3.5+dfsg-15

We believe that the bug you reported is fixed in the latest version of
tla, which is due to be installed in the Debian FTP archive:

tla-doc_1.3.5+dfsg-15_all.deb
  to main/t/tla/tla-doc_1.3.5+dfsg-15_all.deb
tla_1.3.5+dfsg-15.diff.gz
  to main/t/tla/tla_1.3.5+dfsg-15.diff.gz
tla_1.3.5+dfsg-15.dsc
  to main/t/tla/tla_1.3.5+dfsg-15.dsc
tla_1.3.5+dfsg-15_i386.deb
  to main/t/tla/tla_1.3.5+dfsg-15_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 560940@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sylvain Beucler <beuc@beuc.net> (supplier of updated tla package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 14 Dec 2009 17:27:55 +0100
Source: tla
Binary: tla tla-doc
Architecture: source all i386
Version: 1.3.5+dfsg-15
Distribution: unstable
Urgency: low
Maintainer: Debian QA Group <packages@qa.debian.org>
Changed-By: Sylvain Beucler <beuc@beuc.net>
Description: 
 tla        - GNU Arch revision control system
 tla-doc    - GNU Arch revision control system (documentation)
Closes: 560940
Changes: 
 tla (1.3.5+dfsg-15) unstable; urgency=low
 .
   * QA upload.
   * Use system libexpat instead of bundled one (closes: #560940).
Checksums-Sha1: 
 6833f0f593dfdcfefbd11fe1f4e865fad5197296 1647 tla_1.3.5+dfsg-15.dsc
 99fca620f480935297b0adfe962990d9252ee427 33359 tla_1.3.5+dfsg-15.diff.gz
 0e696755b39966f0869a6caa0e90db02e5ac910c 50462 tla-doc_1.3.5+dfsg-15_all.deb
 be389e59b732b80a150f71292f13991a837e81bc 348136 tla_1.3.5+dfsg-15_i386.deb
Checksums-Sha256: 
 b1a45d3e9f68ff1078f237ee102249f253f5b3c6abf14fc4cfa19e7860d21539 1647 tla_1.3.5+dfsg-15.dsc
 544415b17f25823fd113152e8867b0a794ecd2fa2ebd595d8dceb0e675de67a0 33359 tla_1.3.5+dfsg-15.diff.gz
 39f08a96422e55d98966b8e9824585c535d30502d858053c1eb8a5b52d207a06 50462 tla-doc_1.3.5+dfsg-15_all.deb
 2c093cd62dd36ca73b6d4cfd2d26f42de6bc71aa1c3148fbe4fbae961486a295 348136 tla_1.3.5+dfsg-15_i386.deb
Files: 
 7206016e241c16d8ca931493638c4b78 1647 devel optional tla_1.3.5+dfsg-15.dsc
 b57bb44c2be1ff6d59c8553e6ac91bb2 33359 devel optional tla_1.3.5+dfsg-15.diff.gz
 4f2eb8e07faa93b59da5d63548ed2eef 50462 doc optional tla-doc_1.3.5+dfsg-15_all.deb
 76a5950836ec9f192cd1464b598f9af6 348136 devel optional tla_1.3.5+dfsg-15_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQIVAwUBS0lgP+e/yOyVhhEJAQrYgxAAn6oJiii9W3lhiRspy+yqtEMIMzL3NPag
i7RyhnMwszWUIsGPVCUYZ7wZCOYKg+dBGAnDRenUA7Wuy3ZAyCMHuLG5AnuY1MBR
BKm0MESy1vcedFOghDEqT2FbtaFiKaYgmjxn95ueYa2bxjNhoVkRvOpPIMJu4q8v
kjizgYQSyTumsrW8aERVd/HpJJjKpJMvDfi9GI5PjLgYwwLWJUFUdUfh5USwDS5h
uik7qByjoKfX8COPpm2co7Sx5/QmrkrBwY2LKJN7KrUsAk+soEZGUkkGs6ro+fam
DAfyUe01SIW/w/MYgvQ5o+I/MHdvAC3W6/k0o+wgA1nEhIpFXOVjHchqhWuru8fh
E5AsX1XDNRkYAZpxICHhLO1khxUgz/H+j8k1GXSBab1fP6Dz7r55Qqc6EkgxIg9/
ksAjni1Nwyd3dsUlzGWeZHdlzgMqK4vjIRMT8x7adC13P6RMsE4EjxfAJSzl+UaG
J9gUILW0vD55Jhi9En/+UhufP/85R04YN5rsgGB4IovOXapYrucsF+Q1NwV/DfO0
tg7hj6pkOCTWuzWer7KKrG8oqMralPB9/EN1zkn1RKYGwhE9yVHCLG8h49BBQqVG
dInehn4H3dtCznh0eb5lc0zhG2waDvQAyRhlszoUn5fzqZTKDmxoFSEO4IIBeaW+
vIR12/EOgNo=
=o45x
-----END PGP SIGNATURE-----





Reply sent to Sylvain Beucler <beuc@beuc.net>:
You have taken responsibility. (Fri, 16 Apr 2010 20:00:04 GMT) Full text and rfc822 format available.

Notification sent to Michael Gilbert <michael.s.gilbert@gmail.com>:
Bug acknowledged by developer. (Fri, 16 Apr 2010 20:00:04 GMT) Full text and rfc822 format available.

Message #67 received at 560940-close@bugs.debian.org (full text, mbox):

From: Sylvain Beucler <beuc@beuc.net>
To: 560940-close@bugs.debian.org
Subject: Bug#560940: fixed in tla 1.3.5+dfsg-14+lenny1
Date: Fri, 16 Apr 2010 19:57:49 +0000
Source: tla
Source-Version: 1.3.5+dfsg-14+lenny1

We believe that the bug you reported is fixed in the latest version of
tla, which is due to be installed in the Debian FTP archive:

tla-doc_1.3.5+dfsg-14+lenny1_all.deb
  to main/t/tla/tla-doc_1.3.5+dfsg-14+lenny1_all.deb
tla_1.3.5+dfsg-14+lenny1.diff.gz
  to main/t/tla/tla_1.3.5+dfsg-14+lenny1.diff.gz
tla_1.3.5+dfsg-14+lenny1.dsc
  to main/t/tla/tla_1.3.5+dfsg-14+lenny1.dsc
tla_1.3.5+dfsg-14+lenny1_i386.deb
  to main/t/tla/tla_1.3.5+dfsg-14+lenny1_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 560940@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sylvain Beucler <beuc@beuc.net> (supplier of updated tla package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 13 Apr 2010 17:55:51 +0200
Source: tla
Binary: tla tla-doc
Architecture: source all i386
Version: 1.3.5+dfsg-14+lenny1
Distribution: stable
Urgency: low
Maintainer: Debian QA Group <packages@qa.debian.org>
Changed-By: Sylvain Beucler <beuc@beuc.net>
Description: 
 tla        - GNU Arch revision control system
 tla-doc    - GNU Arch revision control system (documentation)
Closes: 560940
Changes: 
 tla (1.3.5+dfsg-14+lenny1) stable; urgency=low
 .
   * QA upload.
   * Fix CVE-2009-3560 and CVE-2009-3720 denial-of-services by patching
     bundled libexpat (closes: #560940).
Checksums-Sha1: 
 66add203ec04b2c7914d0021f55af3eb5f55e85a 1663 tla_1.3.5+dfsg-14+lenny1.dsc
 7d1cbfe4a1eab9316dc4f11f3b7c53bf7f96b227 368092 tla_1.3.5+dfsg-14+lenny1.diff.gz
 adc55825fe575569cc072a6c18691dfda8ec4e27 44864 tla-doc_1.3.5+dfsg-14+lenny1_all.deb
 1b962b68fab671a6874750dec73cbd5c111cc697 399790 tla_1.3.5+dfsg-14+lenny1_i386.deb
Checksums-Sha256: 
 a68565a885d3f84e28f4575f8faa2910edadab51e310b0853081853eae102538 1663 tla_1.3.5+dfsg-14+lenny1.dsc
 e76a0afe09294cf5e205e6aa99e08d008e03414da88d771c1be806f10d65a2ec 368092 tla_1.3.5+dfsg-14+lenny1.diff.gz
 7bbb6c692428c271b8d0c82f95e8cdd25f31dc75a2f38dfdd6c7e7d82b6bee1a 44864 tla-doc_1.3.5+dfsg-14+lenny1_all.deb
 d03459263508f4db4505b7405206207c4bb1290553e86bd15d86f0b6f00e2e6a 399790 tla_1.3.5+dfsg-14+lenny1_i386.deb
Files: 
 c2e4273185130b6f9f29581448261da8 1663 devel optional tla_1.3.5+dfsg-14+lenny1.dsc
 7d841cdc13ac1decdf7ffa21fc458699 368092 devel optional tla_1.3.5+dfsg-14+lenny1.diff.gz
 02c6da50a9bed56de80fd57c636b7415 44864 doc optional tla-doc_1.3.5+dfsg-14+lenny1_all.deb
 4c18338be72c6e1bb782c032f77d8eb9 399790 devel optional tla_1.3.5+dfsg-14+lenny1_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQIVAwUBS8edM+e/yOyVhhEJAQr7ThAAnbsl2aKZDjSKT5X9gZp5bPEbXbs7FIKP
Xa6jcUAkPniebd3IohSKat2dELq889IkrhD0+du/LEznIlWg2cpXg7nlsInKaXua
snpTp5jtAz7hHCC9XWtgqf28uTNJ+X/QjM3eptUqC+VgkXLdWOlt5vElIw8op9bI
NtViewN6eZdCi0N8jExDVqg5qzH4dHlJmagJHOsENsen7eNMx1AgfVzW96YMpy6y
MqdX0fIC2EsKVFwcpMzkcrocmntQPynQSkqQs66TjSTml19Dymr/zgudB4Fc0bWY
ip5TmAu1+xsToYnM0r5Ozbdq+mf/X3dDSamcHxYlG6+L7p4dtdUxva+IpNKnziPG
tSO6sI1PdRfLWlyLNkbUJAs6cz/LPdu2Pg4Drvv3VkUG10H3k5HRBpl2uMTmoN8c
XWSxT/W+c2hPu1h4fei2JV73AVk3AB7vX2ByYvu86tiZq8TGka+GT8pnEqZ1QoGJ
8lnmRTTwF71P3nMDTjMW7bgX54/r5xU4+qUABRCCuXZoH35V0fQlbduB5BLLrt82
7YlAC7MSJ2e/GkxhvG/pzKItrFmaSrdoYfinSLO6oZF5zCj09Xbxx/wiwm6wA2Oq
Z4qpQoPt4kfFX8PH2EpUdBCcGOQVkmlOVN67UNmV1hjJIcIW8QIPk0oLQ6YdT+/S
CqryFJI3aks=
=7x2C
-----END PGP SIGNATURE-----





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 27 Jun 2010 07:36:41 GMT) Full text and rfc822 format available.

Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Fri Apr 18 14:16:28 2014; Machine Name: buxtehude.debian.org

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.