Discussion:
Bug#1084171: bookworm-pu: package 7zip/22.01+dfsg-8+deb12u1
Add Reply
YOKOTA Hiroshi
2024-10-06 04:40:01 UTC
Reply
Permalink
Package: release.debian.org
Severity: normal
Tags: bookworm security
X-Debbugs-Cc: ***@packages.debian.org, ***@security.debian.org, ***@gmail.com
Control: affects -1 + src:7zip
User: ***@packages.debian.org
Usertags: pu


[ Reason ]
Fix CVE-2023-52168 (buffer overflow) and CVE-2023-52169 (buffer over-read)

[ Impact ]
Some vulnerabilities are unfixed.

[ Tests ]
Very trivial NTFS disk image file test was passed.
* list files
* extract files

[ Risks ]
Upstream dose not provide fix patch.
So I extract fix patch from CVE reporter's blog entry.
https://dfir.ru/2024/06/19/vulnerabilities-in-7-zip-and-ntfs3/
I think the fix patch will works, but not confirmed by upstream
because upstream dose not provides fix patch files.

[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable

[ Changes ]
Add fix-ups to NTFS extractor.

[ Other info ]
https://dfir.ru/2024/06/19/vulnerabilities-in-7-zip-and-ntfs3/
https://salsa.debian.org/debian/7zip/-/tree/bookworm-update
https://salsa.debian.org/debian/7zip/-/commits/33950db8e8c9130ac6718fde10515c74f9c6cecc

Roger Shimizu <***@debian.org> provides bookworm-backports package
7zip:24.08+dfsg-1~bpo12+1.
7zip 24.08 already fixed the vulnerabilities by upstream since 24.05.

--
YOKOTA Hiroshi
Jonathan Wiltshire
2024-10-17 12:20:02 UTC
Reply
Permalink
Control: tag -1 confirmed

Please add a bit more detail about what those CVEs refer to in the
changelog, and then go ahead.

Thanks,
--
Jonathan Wiltshire ***@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1
yokota
2024-10-17 17:50:01 UTC
Reply
Permalink
Post by Jonathan Wiltshire
Please add a bit more detail about what those CVEs refer to in the
changelog, and then go ahead.
Thank you.
I was upload with detailed changelog.

--
TOKOTA Hiroshi

Loading...