Discussion:
Processed: bookworm-pu: package opensc/0.23.0-0.3+deb12u2
(too old to reply)
Debian Bug Tracking System
2024-12-23 14:20:02 UTC
Permalink
affects -1 + src:opensc
Bug #1091207 [release.debian.org] bookworm-pu: package opensc/0.23.0-0.3+deb12u2
Added indication that 1091207 affects src:opensc
--
1091207: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1091207
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Debian Bug Tracking System
2025-01-02 20:50:02 UTC
Permalink
tags -1 + confirmed
Bug #1091207 [release.debian.org] bookworm-pu: package opensc/0.23.0-0.3+deb12u2
Added tag(s) confirmed.
--
1091207: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1091207
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Adam D. Barratt
2025-01-02 20:50:02 UTC
Permalink
Control: tags -1 + confirmed
Fix 9 no-dsa vulnerabilities (CVE-2023-5992, CVE-2024-1454, -8443 and
-45615 to -45620).
Please go ahead.

Regards,

Adam
Jonathan Wiltshire
2025-01-04 14:10:01 UTC
Permalink
package release.debian.org
tags 1091207 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==============

Package: opensc
Version: 0.23.0-0.3+deb12u2

Explanation: fix data leak issue [CVE-2023-5992]; fix use-after-free issue [CVE-2024-1454]; fix missing initialisation issue [CVE-2024-45615]; fix various issues with APDU buffer handling [CVE-2024-45616]; fix missing or incorrect function return value checks [CVE-2024-45617 CVE-2024-45618]; fix "incorrect handling of length of buffers or files" issues [CVE-2024-45619 CVE-2024-45620]; fix arbitary code execution issue [CVE-2024-8443]
Debian Bug Tracking System
2025-01-11 11:20:08 UTC
Permalink
Your message dated Sat, 11 Jan 2025 11:03:09 +0000
with message-id <E1tWZGn-009ja1-***@coccia.debian.org>
and subject line Close 1091207
has caused the Debian Bug report #1091207,
regarding bookworm-pu: package opensc/0.23.0-0.3+deb12u2
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ***@bugs.debian.org
immediately.)
--
1091207: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1091207
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Loading...