Discussion:
Bug#1091084: bookworm-pu: package libxstream-java 1.4.20-1+deb12u1
(too old to reply)
Bastien Roucariès
2024-12-22 10:50:01 UTC
Permalink
Package: release.debian.org
Severity: normal
Tags: bookworm
User: ***@packages.debian.org
Usertags: pu
X-Debbugs-CC: Pierre Gruet <***@debian.org>

(Please provide enough information to help the release team
to judge the request efficiently. E.g. by filling in the
sections below.)

[Reason]
CVE-2024-47072: stack overflow

[ Impact ]
Remote DoS is likely possible

[ Tests ]
Manual test test does not backport

[ Risks ]
Code is simple.

[ Checklist ]
[X] *all* changes are documented in the d/changelog
[X] I reviewed all changes and I approve them
[X] attach debdiff against the package in (old)stable
[X] the issue is verified as fixed in unstable

[ Changes ]

* Team upload
* Fix CVE-2024-47072: XStream is vulnerable to a
Denial of Service attack due to stack overflow
from a manipulated binary input stream.
(Closes: #1087274)

[ Other info ]
pgt will likely review
Adam D. Barratt
2025-01-04 12:10:02 UTC
Permalink
Control: tags -1 + confirmed
Post by Bastien Roucariès
CVE-2024-47072: stack overflow
Please go ahead.

Regards,

Adam
Debian Bug Tracking System
2025-01-04 12:10:02 UTC
Permalink
Post by Adam D. Barratt
tags -1 + confirmed
Bug #1091084 [release.debian.org] bookworm-pu: package libxstream-java 1.4.20-1+deb12u1
Added tag(s) confirmed.
--
1091084: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1091084
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Adam D Barratt
2025-01-04 17:50:02 UTC
Permalink
package release.debian.org
tags 1091084 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==============

Package: libxstream-java
Version: 1.4.20-1+deb12u1

Explanation: fix denial of service issue [CVE-2024-47072]
Debian Bug Tracking System
2025-01-11 11:20:01 UTC
Permalink
Your message dated Sat, 11 Jan 2025 11:03:09 +0000
with message-id <E1tWZGn-009jZI-***@coccia.debian.org>
and subject line Close 1091084
has caused the Debian Bug report #1091084,
regarding bookworm-pu: package libxstream-java 1.4.20-1+deb12u1
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ***@bugs.debian.org
immediately.)
--
1091084: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1091084
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Loading...