Debian Bug report logs - #84451
String vun. in m4 macro processor (same as in man)

version graph

Package: m4; Maintainer for m4 is Santiago Vila <sanvila@debian.org>; Source for m4 is src:m4.

Reported by: Cesar Eduardo Barros <cesarb@nitnet.com.br>

Date: Fri, 2 Feb 2001 12:03:01 UTC

Severity: normal

Tags: patch, security

Merged with 84453

Found in version 1.4-11

Fixed in version m4/1.4-12

Done: Santiago Vila <sanvila@debian.org>

Bug is archived. No further changes may be made.

Forwarded to Rene Seindal <rene@seindal.dk>

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Santiago Vila <sanvila@debian.org>:
Bug#84451; Package m4. Full text and rfc822 format available.

Acknowledgement sent to Cesar Eduardo Barros <cesarb@nitnet.com.br>:
New Bug report received and forwarded. Copy sent to Santiago Vila <sanvila@debian.org>. Full text and rfc822 format available.

Message #5 received at submit@bugs.debian.org (full text, mbox):

From: Cesar Eduardo Barros <cesarb@nitnet.com.br>
To: submit@bugs.debian.org
Subject: String vun. in m4 macro processor (same as in man)
Date: Fri, 2 Feb 2001 09:57:28 -0200
Package: m4
Severity: normal
Tags: security

Just saw this on bugtraq...

> Hi,
> bug same as provious in man on debian (suse also?).
> Just look:
> mezon@beata$ m4 -G %x%x%x%x
> m4: 40012a48380491e00: No such file or directory
> mezon@beata$
> 
> or
> 
> mezon@beata$ m4 -G %p
> m4: 0x40012a48: No such file or directory




Noted your statement that Bug has been forwarded to Ren=E9 Seindal <rene@seindal.dk>. Request was from Santiago Vila <sanvila@unex.es> to control@bugs.debian.org. Full text and rfc822 format available.

Forwarded-to-address changed from Ren=E9 Seindal <rene@seindal.dk> to Rene Seindal <rene@seindal.dk>. Request was from Santiago Vila <sanvila@unex.es> to control@bugs.debian.org. Full text and rfc822 format available.

Merged 84451 84453. Request was from Santiago Vila <sanvila@unex.es> to control@bugs.debian.org. Full text and rfc822 format available.

Reply sent to Santiago Vila <sanvila@debian.org>:
You have taken responsibility. Full text and rfc822 format available.

Notification sent to Cesar Eduardo Barros <cesarb@nitnet.com.br>:
Bug acknowledged by developer. Full text and rfc822 format available.

Message #16 received at 84451-close@bugs.debian.org (full text, mbox):

From: Santiago Vila <sanvila@debian.org>
To: 84451-close@bugs.debian.org
Subject: Bug#84451: fixed in m4 1.4-12
Date: Mon, 05 Feb 2001 15:04:06 -0500
We believe that the bug you reported is fixed in the latest version of
m4, which has been installed in the Debian FTP archive:

m4_1.4-12.dsc
  to pool/main/m/m4/m4_1.4-12.dsc
m4-doc_1.4-12_all.deb
  to pool/main/m/m4/m4-doc_1.4-12_all.deb
m4_1.4-12.diff.gz
  to pool/main/m/m4/m4_1.4-12.diff.gz
m4_1.4-12_i386.deb
  to pool/main/m/m4/m4_1.4-12_i386.deb
A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 84451@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Santiago Vila <sanvila@debian.org> (supplier of updated m4 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.6
Date: Mon,  5 Feb 2001 18:47:57 +0100
Source: m4
Binary: m4 m4-doc
Architecture: source i386 all
Version: 1.4-12
Distribution: unstable
Urgency: low
Maintainer: Santiago Vila <sanvila@debian.org>
Description: 
 m4         - a macro processing language
 m4-doc     - Documentation for GNU m4.
Closes: 84416 84451
Changes: 
 m4 (1.4-12) unstable; urgency=low
 .
   * Modified maketemp macro to behave like OpenBSD version (Closes: #84416).
   * Fixed format string vulnerability (Closes: #84451).
   * Build-Depends: texinfo, since the .texi source is now modified.
   * Build-Depends-Indep: texi2html, not tetex-bin.
Files: 
 12164dc7c9c82a4a6aac93e1d772e84e 607 interpreters standard m4_1.4-12.dsc
 0bf261d93e2d3511404e8afc8bb1365e 4925 interpreters standard m4_1.4-12.diff.gz
 4275d83460b79118bee07201bbc660b8 57604 doc optional m4-doc_1.4-12_all.deb
 d125c3de73b440b10a3aefcba932d30b 105710 interpreters standard m4_1.4-12_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.4 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE6fugDd9Uuvj7yPNYRAmTYAKCZRHF9988WseqPCSHGiYX6XjmPigCglX20
FjJzlLl/I7Yyunqz0N8Jp30=
=qE/y
-----END PGP SIGNATURE-----



Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Apr 23 21:10:03 2014; Machine Name: beach.debian.org

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.