Debian Bug report logs -
#988289
htmldoc: CVE-2019-19630
Reported by: Andreas Beckmann <anbe@debian.org>
Date: Sun, 9 May 2021 17:36:01 UTC
Severity: serious
Tags: security
Found in version htmldoc/1.8.27-8
Fixed in versions htmldoc/1.9.7-1, htmldoc/1.9.3-1+deb10u1, htmldoc/1.8.27-8+deb8u1, htmldoc/1.8.27-8+deb9u1
Done: Håvard Flaget Aasen <haavard_aasen@yahoo.no>
Bug is archived. No further changes may be made.
Toggle useless messages
Report forwarded
to debian-bugs-dist@lists.debian.org, team@security.debian.org, Håvard Flaget Aasen <haavard_aasen@yahoo.no>:
Bug#988289; Package src:htmldoc.
(Sun, 09 May 2021 17:36:04 GMT) (full text, mbox, link).
Acknowledgement sent
to Andreas Beckmann <anbe@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Håvard Flaget Aasen <haavard_aasen@yahoo.no>.
(Sun, 09 May 2021 17:36:04 GMT) (full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
Source: htmldoc
Version: 1.8.27-8
Severity: serious
Tags: security
User: debian-qa@lists.debian.org
Usertags: piuparts
Control: fixed -1 1.8.27-8+deb8u1
Control: fixed -1 1.9.7-1
Hi,
CVE-2019-19630 is fixed in jessie-lts but not stretch-lts, making
upgrades difficult since jessie-security has a newer version than
stretch(-security).
Please upload the fix to stretch-lts, too.
And as it looks, this is also unfixed in buster.
htmldoc | 1.8.27-8 | jessie | source
htmldoc | 1.8.27-8 | stretch | source
htmldoc | 1.8.27-8+deb8u1 | jessie-security | source
htmldoc | 1.9.3-1 | buster | source
htmldoc | 1.9.11-2 | bullseye | source
htmldoc | 1.9.11-2 | sid | source
Andreas
Marked as fixed in versions htmldoc/1.8.27-8+deb8u1.
Request was from Andreas Beckmann <anbe@debian.org>
to submit@bugs.debian.org.
(Sun, 09 May 2021 17:36:04 GMT) (full text, mbox, link).
Marked as fixed in versions htmldoc/1.9.7-1.
Request was from Andreas Beckmann <anbe@debian.org>
to submit@bugs.debian.org.
(Sun, 09 May 2021 17:36:04 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Håvard Flaget Aasen <haavard_aasen@yahoo.no>:
Bug#988289; Package src:htmldoc.
(Sun, 09 May 2021 19:03:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Utkarsh Gupta <utkarsh@debian.org>:
Extra info received and forwarded to list. Copy sent to Håvard Flaget Aasen <haavard_aasen@yahoo.no>.
(Sun, 09 May 2021 19:03:03 GMT) (full text, mbox, link).
Message #14 received at 988289@bugs.debian.org (full text, mbox, reply):
Hello,
That's pretty unfortunate what happened. Since I fixed this in jessie
(back when it was LTS), I'll take care of stretch (now that it's LTS)
and subsequently buster as well. Thanks!
Added indication that 988289 affects htmldoc-common
Request was from Andreas Beckmann <anbe@debian.org>
to control@bugs.debian.org.
(Sun, 09 May 2021 19:30:04 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org:
Bug#988289; Package src:htmldoc.
(Mon, 10 May 2021 21:42:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Håvard Flaget Aasen <haavard_aasen@yahoo.no>:
Extra info received and forwarded to list.
(Mon, 10 May 2021 21:42:03 GMT) (full text, mbox, link).
Message #21 received at 988289@bugs.debian.org (full text, mbox, reply):
On Mon, 10 May 2021 00:28:43 +0530 Utkarsh Gupta <utkarsh@debian.org> wrote:
> Hello,
>
> That's pretty unfortunate what happened. Since I fixed this in jessie
> (back when it was LTS), I'll take care of stretch (now that it's LTS)
> and subsequently buster as well. Thanks!
>
>
Hi Utkarsh,
I wasn't aware this versioning could be a problem.
I can make a release to buster if you want. I would need a sponsor
though, so if your determined, I won't rip it out of your hands.
Regardless who does it, can we fix CVE-2021-20308 [0] as well? It's
marked as unimportant but since we already is preparing packages...
I'v prepared a release to unstable and bullseye with the fix for
cve-2021-20308 it's on the mentors site now.
Håvard
[0] https://security-tracker.debian.org/tracker/CVE-2021-20308
Information forwarded
to debian-bugs-dist@lists.debian.org, Håvard Flaget Aasen <haavard_aasen@yahoo.no>:
Bug#988289; Package src:htmldoc.
(Tue, 11 May 2021 13:12:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Utkarsh Gupta <utkarsh@debian.org>:
Extra info received and forwarded to list. Copy sent to Håvard Flaget Aasen <haavard_aasen@yahoo.no>.
(Tue, 11 May 2021 13:12:02 GMT) (full text, mbox, link).
Message #26 received at 988289@bugs.debian.org (full text, mbox, reply):
Hi Håvard,
On Tue, May 11, 2021 at 3:09 AM Håvard Flaget Aasen
<haavard_aasen@yahoo.no> wrote:
> I wasn't aware this versioning could be a problem.
Yep, a big one sometimes :)
> I can make a release to buster if you want. I would need a sponsor
> though, so if your determined, I won't rip it out of your hands.
That'd be helpful, thank you! Please let me know when you have a dsc ready?
> Regardless who does it, can we fix CVE-2021-20308 [0] as well? It's
> marked as unimportant but since we already is preparing packages...
Absolutely, by all means!
> I'v prepared a release to unstable and bullseye with the fix for
> cve-2021-20308 it's on the mentors site now.
Since this CVE is "unimportant", uploading to bullseye won't make
sense. Rather we can upload to unstable and file an unblock request,
that'd be a good way out here.
That said, I couldn't find the dsc there, could you sense the link to
dsc for unstable and I'll be very happy to sponsor the upload. Thanks!
:)
- u
Information forwarded
to debian-bugs-dist@lists.debian.org:
Bug#988289; Package src:htmldoc.
(Tue, 11 May 2021 20:45:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Håvard Flaget Aasen <haavard_aasen@yahoo.no>:
Extra info received and forwarded to list.
(Tue, 11 May 2021 20:45:02 GMT) (full text, mbox, link).
Message #31 received at 988289@bugs.debian.org (full text, mbox, reply):
Hi Utkarsh
>
>> I can make a release to buster if you want. I would need a sponsor
>> though, so if your determined, I won't rip it out of your hands.
>
> That'd be helpful, thank you! Please let me know when you have a dsc ready?
I've got the release ready for buster and uploaded it to mentors [0]. I
also sent a request to the RM, for buster-pu, but haven't got any
response yet [1].
>
>> Regardless who does it, can we fix CVE-2021-20308 [0] as well? It's
>> marked as unimportant but since we already is preparing packages...
>
> Absolutely, by all means!
>
>> I'v prepared a release to unstable and bullseye with the fix for
>> cve-2021-20308 it's on the mentors site now.
>
> Since this CVE is "unimportant", uploading to bullseye won't make
> sense. Rather we can upload to unstable and file an unblock request,
> that'd be a good way out here.
>
> That said, I couldn't find the dsc there, could you sense the link to
> dsc for unstable and I'll be very happy to sponsor the upload. Thanks!
> :)
>
I was lucky with the sponsoring to unstable, the package got uploaded
earlier today. I also got it unblocked, so it will migrate to bullseye.
Håvard
[0] https://mentors.debian.net/package/htmldoc/
[1] https://bugs.debian.org/#988365
Information forwarded
to debian-bugs-dist@lists.debian.org, Håvard Flaget Aasen <haavard_aasen@yahoo.no>:
Bug#988289; Package src:htmldoc.
(Tue, 11 May 2021 22:15:04 GMT) (full text, mbox, link).
Acknowledgement sent
to Utkarsh Gupta <utkarsh@debian.org>:
Extra info received and forwarded to list. Copy sent to Håvard Flaget Aasen <haavard_aasen@yahoo.no>.
(Tue, 11 May 2021 22:15:04 GMT) (full text, mbox, link).
Message #36 received at 988289@bugs.debian.org (full text, mbox, reply):
Hi Håvard,
On Wed, May 12, 2021 at 2:11 AM Håvard Flaget Aasen
<haavard_aasen@yahoo.no> wrote:
> I've got the release ready for buster and uploaded it to mentors [0]. I
> also sent a request to the RM, for buster-pu, but haven't got any
> response yet [1].
Thanks for the buster update; uploaded! \o/
You'll not receive any reply to -pu bug unless the release team has
some problem with it. However, you'll receive a reply when someone
from the release team will batch-accept the uploads from the proposed
queue.
So basically, we're all good and set!
> I was lucky with the sponsoring to unstable, the package got uploaded
> earlier today. I also got it unblocked, so it will migrate to bullseye.
Awesome, thank you!
- u
Information forwarded
to debian-bugs-dist@lists.debian.org:
Bug#988289; Package src:htmldoc.
(Wed, 12 May 2021 15:39:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Håvard Flaget Aasen <haavard_aasen@yahoo.no>:
Extra info received and forwarded to list.
(Wed, 12 May 2021 15:39:02 GMT) (full text, mbox, link).
Message #41 received at 988289@bugs.debian.org (full text, mbox, reply):
On 12.05.2021 00:13, Utkarsh Gupta wrote:
> Hi Håvard,
>
> On Wed, May 12, 2021 at 2:11 AM Håvard Flaget Aasen
> <haavard_aasen@yahoo.no> wrote:
>> I've got the release ready for buster and uploaded it to mentors [0]. I
>> also sent a request to the RM, for buster-pu, but haven't got any
>> response yet [1].
>
> Thanks for the buster update; uploaded! \o/
> You'll not receive any reply to -pu bug unless the release team has
> some problem with it. However, you'll receive a reply when someone
> from the release team will batch-accept the uploads from the proposed
> queue.
>
> So basically, we're all good and set!
>
>> I was lucky with the sponsoring to unstable, the package got uploaded
>> earlier today. I also got it unblocked, so it will migrate to bullseye.
>
> Awesome, thank you!
>
>
> - u
>
Thanks for the sponsoring Utkarsh!
I made a package for stretch as well, and uploaded it to mentors. [0]
Though I'm not sure about this lts stuff. So far this package I made
just targets "stretch". else it's quite identical to the package you
sponsored to buster.
If you have your own package it might be better suited.
Håvard
Information forwarded
to debian-bugs-dist@lists.debian.org, Håvard Flaget Aasen <haavard_aasen@yahoo.no>:
Bug#988289; Package src:htmldoc.
(Thu, 13 May 2021 11:27:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Utkarsh Gupta <utkarsh@debian.org>:
Extra info received and forwarded to list. Copy sent to Håvard Flaget Aasen <haavard_aasen@yahoo.no>.
(Thu, 13 May 2021 11:27:03 GMT) (full text, mbox, link).
Message #46 received at 988289@bugs.debian.org (full text, mbox, reply):
Hi Håvard,
On Wed, May 12, 2021 at 9:05 PM Håvard Flaget Aasen
<haavard_aasen@yahoo.no> wrote:
> Thanks for the sponsoring Utkarsh!
You're very welcome! :)
> I made a package for stretch as well, and uploaded it to mentors. [0]
> Though I'm not sure about this lts stuff. So far this package I made
> just targets "stretch". else it's quite identical to the package you
> sponsored to buster.
>
> If you have your own package it might be better suited.
Thanks, again. I have had a patch prepared, too. This will help me
compare and verify that everything's indeed in order.
Further, we have a slightly different workflow, we upload to -security
(since no pu) and have to announce and publish an update for the
website. I'll do them all, just letting you know. Thanks, again!
- u
Reply sent
to Håvard Flaget Aasen <haavard_aasen@yahoo.no>:
You have taken responsibility.
(Sun, 04 Jul 2021 20:45:03 GMT) (full text, mbox, link).
Notification sent
to Andreas Beckmann <anbe@debian.org>:
Bug acknowledged by developer.
(Sun, 04 Jul 2021 20:45:03 GMT) (full text, mbox, link).
Message #51 received at 988289-done@bugs.debian.org (full text, mbox, reply):
Control: fixed -1 1.8.27-8+deb9u1
Control: fixed -1 1.9.3-1+deb10u1
Hi,
Patches from upstream have been applied to fix CVE-2019-19630, in both
stretch and buster.
The version in stretch is now 1.8.27-8+deb9u1, which also eases the
upgrade from jessie.
Regards,
Håvard
Information forwarded
to debian-bugs-dist@lists.debian.org, Håvard Flaget Aasen <haavard_aasen@yahoo.no>:
Bug#988289; Package src:htmldoc.
(Sun, 04 Jul 2021 22:00:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Andreas Beckmann <anbe@debian.org>:
Extra info received and forwarded to list. Copy sent to Håvard Flaget Aasen <haavard_aasen@yahoo.no>.
(Sun, 04 Jul 2021 22:00:02 GMT) (full text, mbox, link).
Message #56 received at 988289@bugs.debian.org (full text, mbox, reply):
Control: fixed -1 1.8.27-8+deb9u1
Control: fixed -1 1.9.3-1+deb10u1
'Control: bts command' does not work on -done@, thus resending the commands.
Andreas
Marked as fixed in versions htmldoc/1.8.27-8+deb9u1.
Request was from Andreas Beckmann <anbe@debian.org>
to 988289-submit@bugs.debian.org.
(Sun, 04 Jul 2021 22:00:03 GMT) (full text, mbox, link).
Marked as fixed in versions htmldoc/1.9.3-1+deb10u1.
Request was from Andreas Beckmann <anbe@debian.org>
to 988289-submit@bugs.debian.org.
(Sun, 04 Jul 2021 22:00:03 GMT) (full text, mbox, link).
Bug archived.
Request was from Debbugs Internal Request <owner@bugs.debian.org>
to internal_control@bugs.debian.org.
(Mon, 02 Aug 2021 07:27:12 GMT) (full text, mbox, link).
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Sun Oct 8 03:06:35 2023;
Machine Name:
buxtehude
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.