CVE-2017-9433

Related Vulnerabilities: CVE-2017-9433  

Debian Bug report logs - #864366
CVE-2017-9433

version graph

Reported by: Moritz Muehlenhoff <jmm@debian.org>

Date: Wed, 7 Jun 2017 16:15:01 UTC

Severity: grave

Tags: fixed-upstream, security, upstream

Found in version libmwaw/0.3.1-2

Fixed in versions libmwaw/0.3.9-2, libmwaw/0.3.11-2, libmwaw/0.3.1-2+deb8u1

Done: Rene Engelhard <rene@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>:
Bug#864366; Package src:libmwaw. (Wed, 07 Jun 2017 16:15:04 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>. (Wed, 07 Jun 2017 16:15:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2017-9433
Date: Wed, 07 Jun 2017 18:13:05 +0200
Source: libmwaw
Severity: grave
Tags: security

Please see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9433

Cheers,
        Moritz



Marked as found in versions libmwaw/0.3.1-2. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 07 Jun 2017 18:18:05 GMT) (full text, mbox, link).


Added tag(s) upstream and fixed-upstream. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 07 Jun 2017 19:24:02 GMT) (full text, mbox, link).


Added tag(s) pending. Request was from rene@rene-engelhard.de (Rene Engelhard) to control@bugs.debian.org. (Wed, 07 Jun 2017 20:06:07 GMT) (full text, mbox, link).


Message sent on to Moritz Muehlenhoff <jmm@debian.org>:
Bug#864366. (Wed, 07 Jun 2017 20:06:15 GMT) (full text, mbox, link).


Message #14 received at 864366-submitter@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@debian.org>
To: 864366-submitter@bugs.debian.org
Subject: Bug#864366 marked as pending
Date: Wed, 07 Jun 2017 20:05:54 +0000
tag 864366 pending
thanks

Hello,

Bug #864366 reported by you has been fixed in the Git repository. You can
see the changelog below, and you can check the diff of the fix at:

    https://anonscm.debian.org/cgit/pkg-openoffice/libmwaw.git/commit/?id=47a8c95

---
commit 47a8c958189654693d0436cd7ee1af3908b9a40d
Author: Rene Engelhard <rene@debian.org>
Date:   Wed Jun 7 22:05:32 2017 +0200

    actually commit changelog...

diff --git a/debian/changelog b/debian/changelog
index 26887e9..3c19e98 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,9 @@
+libmwaw (0.3.9-2) unstable; urgency=medium
+
+  * apply upstream patch to fix CVE-2017-9433 (closes: #864366)
+
+ -- Rene Engelhard <rene@debian.org>  Wed, 07 Jun 2017 21:47:49 +0200
+
 libmwaw (0.3.9-1) unstable; urgency=medium
 
   * Imported Upstream version 0.3.9



Message sent on to Moritz Muehlenhoff <jmm@debian.org>:
Bug#864366. (Wed, 07 Jun 2017 20:21:06 GMT) (full text, mbox, link).


Message #17 received at 864366-submitter@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@debian.org>
To: 864366-submitter@bugs.debian.org
Subject: Bug#864366 marked as pending
Date: Wed, 07 Jun 2017 20:17:35 +0000
tag 864366 pending
thanks

Hello,

Bug #864366 reported by you has been fixed in the Git repository. You can
see the changelog below, and you can check the diff of the fix at:

    https://anonscm.debian.org/cgit/pkg-openoffice/libmwaw.git/commit/?id=58d91e5

---
commit 58d91e5a5c303a66acccc9b5653e451c65fbc48c
Merge: ece60c3 47a8c95
Author: Rene Engelhard <rene@debian.org>
Date:   Wed Jun 7 22:08:34 2017 +0200

    Merge branch 'master' into experimental

diff --cc debian/changelog
index 3d4b639,3c19e98..81cbb85
--- a/debian/changelog
+++ b/debian/changelog
@@@ -1,15 -1,9 +1,21 @@@
 -libmwaw (0.3.9-2) unstable; urgency=medium
++libmwaw (0.3.11-2) experimental; urgency=medium
+ 
+   * apply upstream patch to fix CVE-2017-9433 (closes: #864366)
+ 
+  -- Rene Engelhard <rene@debian.org>  Wed, 07 Jun 2017 21:47:49 +0200
+ 
 +libmwaw (0.3.11-1) experimental; urgency=medium
 +
 +  * New upstream version 0.3.11
 +
 + -- Rene Engelhard <rene@debian.org>  Sat, 01 Apr 2017 21:51:21 +0200
 +
 +libmwaw (0.3.10-1) experimental; urgency=medium
 +
 +  * New upstream version 0.3.10
 +
 + -- Rene Engelhard <rene@debian.org>  Tue, 31 Jan 2017 21:17:13 +0100
 +
  libmwaw (0.3.9-1) unstable; urgency=medium
  
    * Imported Upstream version 0.3.9



Information forwarded to debian-bugs-dist@lists.debian.org, Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>:
Bug#864366; Package src:libmwaw. (Wed, 07 Jun 2017 21:09:06 GMT) (full text, mbox, link).


Acknowledgement sent to Rene Engelhard <rene@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>. (Wed, 07 Jun 2017 21:09:06 GMT) (full text, mbox, link).


Message #22 received at 864366@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@debian.org>
To: Moritz Muehlenhoff <jmm@debian.org>, 864366@bugs.debian.org
Cc: team@security.debian.org
Subject: Re: Bug#864366: CVE-2017-9433
Date: Wed, 7 Jun 2017 23:07:02 +0200
Hi,

On Wed, Jun 07, 2017 at 06:13:05PM +0200, Moritz Muehlenhoff wrote:
> Source: libmwaw
> Severity: grave
> Tags: security
> 
> Please see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9433

sid (and thus hopefully stretch assuming will be unblocked, see # -
otherwise we'd need stretch-security) and experimental done.

stable diff is here:

diff -Nru libmwaw-0.3.1/debian/changelog libmwaw-0.3.1/debian/changelog
--- libmwaw-0.3.1/debian/changelog	2014-08-07 23:53:29.000000000 +0200
+++ libmwaw-0.3.1/debian/changelog	2017-06-07 22:47:24.000000000 +0200
@@ -1,3 +1,9 @@
+libmwaw (0.3.1-2+deb8u1) jessie-security; urgency=medium
+
+  * backport upstream patch to fix CVE-2017-9433 (closes: #864366)
+
+ -- Rene Engelhard <rene@debian.org>  Wed, 07 Jun 2017 22:47:10 +0200
+
 libmwaw (0.3.1-2) unstable; urgency=low
 
   * upload to unstable 
diff -Nru libmwaw-0.3.1/debian/patches/CVE-2017-9433.diff libmwaw-0.3.1/debian/patches/CVE-2017-9433.diff
--- libmwaw-0.3.1/debian/patches/CVE-2017-9433.diff	1970-01-01 01:00:00.000000000 +0100
+++ libmwaw-0.3.1/debian/patches/CVE-2017-9433.diff	2017-06-07 22:46:57.000000000 +0200
@@ -0,0 +1,11 @@
+--- a/src/lib/MsWrd1Parser.cxx
++++ b/src/lib/MsWrd1Parser.cxx
+@@ -902,7 +902,7 @@
+     int id = fIt++->second;
+     fPos[1] = fIt==footnoteMap.end() ? m_state->m_eot : fIt->first;
+     if (id >= int(m_state->m_footnotesList.size()))
+-      m_state->m_footnotesList.resize(size_t(id),0);
++      m_state->m_footnotesList.resize(size_t(id)+1,0);
+     m_state->m_footnotesList[size_t(id)]=fPos;
+   }
+   ascii().addDelimiter(input->tell(),'|');
diff -Nru libmwaw-0.3.1/debian/patches/series libmwaw-0.3.1/debian/patches/series
--- libmwaw-0.3.1/debian/patches/series	1970-01-01 01:00:00.000000000 +0100
+++ libmwaw-0.3.1/debian/patches/series	2017-06-07 22:13:15.000000000 +0200
@@ -0,0 +1 @@
+CVE-2017-9433.diff

Should I upload?

Regards,

Rene



Reply sent to Rene Engelhard <rene@debian.org>:
You have taken responsibility. (Wed, 07 Jun 2017 21:09:08 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@debian.org>:
Bug acknowledged by developer. (Wed, 07 Jun 2017 21:09:08 GMT) (full text, mbox, link).


Message #27 received at 864366-close@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@debian.org>
To: 864366-close@bugs.debian.org
Subject: Bug#864366: fixed in libmwaw 0.3.9-2
Date: Wed, 07 Jun 2017 21:04:12 +0000
Source: libmwaw
Source-Version: 0.3.9-2

We believe that the bug you reported is fixed in the latest version of
libmwaw, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 864366@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Rene Engelhard <rene@debian.org> (supplier of updated libmwaw package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 07 Jun 2017 21:47:49 +0200
Source: libmwaw
Binary: libmwaw-dev libmwaw-doc libmwaw-0.3-3 libmwaw-tools
Architecture: source
Version: 0.3.9-2
Distribution: unstable
Urgency: medium
Maintainer: Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>
Changed-By: Rene Engelhard <rene@debian.org>
Description:
 libmwaw-0.3-3 - import library for some old Mac text documents
 libmwaw-dev - import library for some old Mac text documents -- development
 libmwaw-doc - import library for some old Mac text documents -- documentation
 libmwaw-tools - import library for some old Mac text documents -- tools
Closes: 864366
Changes:
 libmwaw (0.3.9-2) unstable; urgency=medium
 .
   * apply upstream patch to fix CVE-2017-9433 (closes: #864366)
Checksums-Sha1:
 2346ffd4a2466f75d9194cc3e2cdbf81262dcb71 2068 libmwaw_0.3.9-2.dsc
 f595f2998f9283be7fc2ed5d8b2e20473c49e645 8300 libmwaw_0.3.9-2.debian.tar.xz
 c3d59f3bc7da0139613917b4bde5ea47d3fb93a8 5278 libmwaw_0.3.9-2_source.buildinfo
Checksums-Sha256:
 2a7768051a60c31ffd71ef4c0424e93beda7a303e7a179556b686ec4d98ca5f7 2068 libmwaw_0.3.9-2.dsc
 7a8b398acf11115a6e08576afd97ac49ac201f4367584e51059e49c9d735349c 8300 libmwaw_0.3.9-2.debian.tar.xz
 0afe583e9b1c8018fbfb4e379b73c6239506994911bcfc66278e40837e0ebfb1 5278 libmwaw_0.3.9-2_source.buildinfo
Files:
 b6f90d2f9253a8673f5772c77ee4609c 2068 libs optional libmwaw_0.3.9-2.dsc
 3926712b45a014a9e4215a1610341295 8300 libs optional libmwaw_0.3.9-2.debian.tar.xz
 9f7226cc0a8a557d016bb6d26c850521 5278 libs optional libmwaw_0.3.9-2_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE4S3qRnUGcM+pYIAdCqBFcdA+PnAFAlk4WiAACgkQCqBFcdA+
PnBBeg//QXr6+HyVZTCxYT0/mBLM1pSboHGWqvIpPOMWm30tDVTWLGCbLAntFHI7
2OpmQR6xCfaS7iIorR756vZA0bseIjX979BEEEpi17PoMZoP+FUTeJ7ZYf707bFT
PEk0z9JRNM6qZOCgpY/q8LYFDoOKzoZl5rVTti7SsluECnhtbINLSzmsYLqMd6OP
STRMPEj5oEv0pgAe15xwZCf+T6Hk1Wh74LPmDUJc3td72ciRrqghNPqElEke3HXP
DWO5sxyPqwmd3NjNCj1Un9h0z2PKszEQse/sndIxxklyP07G2RvtBDdorpzJSKha
u2lFyMubHV7tfajpe7VlKhflMcGCI3Ngj+c3FUXS2pQoey/QTPpENoPsIpiV43Cq
iauvMtXmOspljK/9PpLeODLJdu0ig0bqG1YnUMBM+3v72jVJ2/n+aHhXuRPY2yXP
vfG2cYsal/i8YuErRYykvGCpsX/BNtaF/jKLJ93kgnvqCzzUxBEXCkQVGSPNlVcZ
oi8oFtiPsNejAW9DbqhxC+f7KkXMTpj+kBZ2U9KTf4Uvxe3pow6ffER/RA9wTMCD
tRVakwoAqf3wO7DUuZJlLIK+c+BsXHZoYdAyeQyC3MsAyhjYxmeQqIYk7/joqBd2
n3l9ZpOcxHzQDOY541f9M/WqeHrlvw2kicxrTXzIzoygpE0F9U0=
=ECPj
-----END PGP SIGNATURE-----




Reply sent to Rene Engelhard <rene@debian.org>:
You have taken responsibility. (Wed, 07 Jun 2017 21:09:10 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@debian.org>:
Bug acknowledged by developer. (Wed, 07 Jun 2017 21:09:10 GMT) (full text, mbox, link).


Message #32 received at 864366-close@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@debian.org>
To: 864366-close@bugs.debian.org
Subject: Bug#864366: fixed in libmwaw 0.3.11-2
Date: Wed, 07 Jun 2017 21:04:19 +0000
Source: libmwaw
Source-Version: 0.3.11-2

We believe that the bug you reported is fixed in the latest version of
libmwaw, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 864366@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Rene Engelhard <rene@debian.org> (supplier of updated libmwaw package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 07 Jun 2017 21:47:49 +0200
Source: libmwaw
Binary: libmwaw-dev libmwaw-doc libmwaw-0.3-3 libmwaw-tools
Architecture: source
Version: 0.3.11-2
Distribution: experimental
Urgency: medium
Maintainer: Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>
Changed-By: Rene Engelhard <rene@debian.org>
Description:
 libmwaw-0.3-3 - import library for some old Mac text documents
 libmwaw-dev - import library for some old Mac text documents -- development
 libmwaw-doc - import library for some old Mac text documents -- documentation
 libmwaw-tools - import library for some old Mac text documents -- tools
Closes: 864366
Changes:
 libmwaw (0.3.11-2) experimental; urgency=medium
 .
   * apply upstream patch to fix CVE-2017-9433 (closes: #864366)
Checksums-Sha1:
 b9af53ee4f30c97d4d808d27074d840911ff522e 2072 libmwaw_0.3.11-2.dsc
 5daf50649d92662757aa5234318c2a839d5e8fc5 8348 libmwaw_0.3.11-2.debian.tar.xz
 d240371831c6ec87d96d704503c2a5a778f64c75 5272 libmwaw_0.3.11-2_source.buildinfo
Checksums-Sha256:
 9a190dc32cc7127a71cab0aec492dc83bf76f2f44ac160833ad8c3c4a66106f6 2072 libmwaw_0.3.11-2.dsc
 0eb138a9b0048657aabd5377f67f95c8993b6e8da758317e56cb5d7b607efb2f 8348 libmwaw_0.3.11-2.debian.tar.xz
 f6df6b7c745bf37a4322126aeda856d30c05944a8d1622c3b2dea59c8ca20783 5272 libmwaw_0.3.11-2_source.buildinfo
Files:
 76a28e0424f34f9447b2118fd1a18483 2072 libs optional libmwaw_0.3.11-2.dsc
 fb25860744471bc22c900a16b060345b 8348 libs optional libmwaw_0.3.11-2.debian.tar.xz
 618945e5bdf55c87564ad133c6d8d4d7 5272 libs optional libmwaw_0.3.11-2_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE4S3qRnUGcM+pYIAdCqBFcdA+PnAFAlk4XZgACgkQCqBFcdA+
PnB5qhAAldB5/f4m02OCmCMGPgD5I/fh4t3Tk9ZldARobnTIv59KV8WanHExBeTq
YnmajQJUWx1YAE9Uy/+5GvTuGaftjpSED8d9t9C/cjHe6FXTpk5tEsamS8+KOYFg
tufAfsHsP4wSR54C50yrLJsUOytX8FLhNGLAgLnV8wHhEmHfwUTxQUwqjLBiqhFW
BxnFAL3zFdZHCvNg/CXtKq4+MaRUaqu26jmW2IEqEsGKDxJZCTwC/gypq7BEGP0B
Hex9rwkXPJARFJgk3IbC7wSJfppwhfmmmqkUZ73TgvCJYyxwJoyAvRw1GIAICgqx
JKOIGrKQDHEYdM1AcOqzKFrLDeDG1y29NsSpm9qJ5uZ0d7Sv0a4K5AUk00Y278JN
7un42EBSUiRhy3n33kss/fIu8a5rlTiXdkx8L8Gp2jU+DkONwPur6omzdpiB8Bp3
JoYdQ8xyr3hdV5rvbLD8gJtSp2tXomEqoatEHvH6QIobz7vdk7b87/onKQNJMChi
YPoSiPcYf947OIbg+iJemUCYifWKggnFDFj7gJIVdp8SPwxTL3wO8nEjfAna8Clh
1CNi7qp+cRtA1qMFDKYIRKfyOfro20zckTZ7F8PDhXZCudEw00dmwN11rBDOTtYI
/G3WEmw32adUAlXKs2qgwB8uYoc0X2LhezR3j19vDRF1YB5166g=
=Ims0
-----END PGP SIGNATURE-----




Information forwarded to debian-bugs-dist@lists.debian.org, Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>:
Bug#864366; Package src:libmwaw. (Wed, 07 Jun 2017 21:27:07 GMT) (full text, mbox, link).


Acknowledgement sent to Rene Engelhard <rene@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>. (Wed, 07 Jun 2017 21:27:07 GMT) (full text, mbox, link).


Message #37 received at 864366@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@debian.org>
To: Moritz Muehlenhoff <jmm@debian.org>, 864366@bugs.debian.org
Cc: team@security.debian.org
Subject: Re: Bug#864366: CVE-2017-9433
Date: Wed, 7 Jun 2017 23:22:16 +0200
On Wed, Jun 07, 2017 at 11:07:02PM +0200, Rene Engelhard wrote:
> Hi,
> 
> On Wed, Jun 07, 2017 at 06:13:05PM +0200, Moritz Muehlenhoff wrote:
> > Source: libmwaw
> > Severity: grave
> > Tags: security
> > 
> > Please see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9433
> 
> sid (and thus hopefully stretch assuming will be unblocked, see # -

Oops.

#864384

Regards,

Rene



Information forwarded to debian-bugs-dist@lists.debian.org, Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>:
Bug#864366; Package src:libmwaw. (Wed, 07 Jun 2017 21:57:02 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Mühlenhoff <jmm@inutil.org>:
Extra info received and forwarded to list. Copy sent to Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>. (Wed, 07 Jun 2017 21:57:02 GMT) (full text, mbox, link).


Message #42 received at 864366@bugs.debian.org (full text, mbox, reply):

From: Moritz Mühlenhoff <jmm@inutil.org>
To: Rene Engelhard <rene@debian.org>
Cc: 864366@bugs.debian.org, team@security.debian.org
Subject: Re: Bug#864366: CVE-2017-9433
Date: Wed, 7 Jun 2017 23:54:26 +0200
On Wed, Jun 07, 2017 at 11:07:02PM +0200, Rene Engelhard wrote:
> Hi,
> 
> On Wed, Jun 07, 2017 at 06:13:05PM +0200, Moritz Muehlenhoff wrote:
> > Source: libmwaw
> > Severity: grave
> > Tags: security
> > 
> > Please see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9433
> 
> sid (and thus hopefully stretch assuming will be unblocked, see # -
> otherwise we'd need stretch-security) and experimental done.
> 
> stable diff is here:
> 
> diff -Nru libmwaw-0.3.1/debian/changelog libmwaw-0.3.1/debian/changelog
> --- libmwaw-0.3.1/debian/changelog	2014-08-07 23:53:29.000000000 +0200
> +++ libmwaw-0.3.1/debian/changelog	2017-06-07 22:47:24.000000000 +0200
> @@ -1,3 +1,9 @@
> +libmwaw (0.3.1-2+deb8u1) jessie-security; urgency=medium
> +
> +  * backport upstream patch to fix CVE-2017-9433 (closes: #864366)
> +
> + -- Rene Engelhard <rene@debian.org>  Wed, 07 Jun 2017 22:47:10 +0200
> +
>  libmwaw (0.3.1-2) unstable; urgency=low
>  
>    * upload to unstable 
> diff -Nru libmwaw-0.3.1/debian/patches/CVE-2017-9433.diff libmwaw-0.3.1/debian/patches/CVE-2017-9433.diff
> --- libmwaw-0.3.1/debian/patches/CVE-2017-9433.diff	1970-01-01 01:00:00.000000000 +0100
> +++ libmwaw-0.3.1/debian/patches/CVE-2017-9433.diff	2017-06-07 22:46:57.000000000 +0200
> @@ -0,0 +1,11 @@
> +--- a/src/lib/MsWrd1Parser.cxx
> ++++ b/src/lib/MsWrd1Parser.cxx
> +@@ -902,7 +902,7 @@
> +     int id = fIt++->second;
> +     fPos[1] = fIt==footnoteMap.end() ? m_state->m_eot : fIt->first;
> +     if (id >= int(m_state->m_footnotesList.size()))
> +-      m_state->m_footnotesList.resize(size_t(id),0);
> ++      m_state->m_footnotesList.resize(size_t(id)+1,0);
> +     m_state->m_footnotesList[size_t(id)]=fPos;
> +   }
> +   ascii().addDelimiter(input->tell(),'|');
> diff -Nru libmwaw-0.3.1/debian/patches/series libmwaw-0.3.1/debian/patches/series
> --- libmwaw-0.3.1/debian/patches/series	1970-01-01 01:00:00.000000000 +0100
> +++ libmwaw-0.3.1/debian/patches/series	2017-06-07 22:13:15.000000000 +0200
> @@ -0,0 +1 @@
> +CVE-2017-9433.diff
> 
> Should I upload?

Please go ahead (needs -sa since orig tarball is new)

Cheers,
        Moritz



Information forwarded to debian-bugs-dist@lists.debian.org, Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>:
Bug#864366; Package src:libmwaw. (Wed, 07 Jun 2017 22:24:02 GMT) (full text, mbox, link).


Acknowledgement sent to Rene Engelhard <rene@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>. (Wed, 07 Jun 2017 22:24:02 GMT) (full text, mbox, link).


Message #47 received at 864366@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@debian.org>
To: Moritz Mühlenhoff <jmm@inutil.org>
Cc: 864366@bugs.debian.org, team@security.debian.org
Subject: Re: Bug#864366: CVE-2017-9433
Date: Thu, 8 Jun 2017 00:20:37 +0200
Hi,

On Wed, Jun 07, 2017 at 11:54:26PM +0200, Moritz Mühlenhoff wrote:
> Please go ahead (needs -sa since orig tarball is new)

Ah, right. Almost forgot, thanks.

Done.

Regards,

Rene



Reply sent to Rene Engelhard <rene@debian.org>:
You have taken responsibility. (Sun, 11 Jun 2017 21:03:10 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@debian.org>:
Bug acknowledged by developer. (Sun, 11 Jun 2017 21:03:10 GMT) (full text, mbox, link).


Message #52 received at 864366-close@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@debian.org>
To: 864366-close@bugs.debian.org
Subject: Bug#864366: fixed in libmwaw 0.3.1-2+deb8u1
Date: Sun, 11 Jun 2017 21:02:15 +0000
Source: libmwaw
Source-Version: 0.3.1-2+deb8u1

We believe that the bug you reported is fixed in the latest version of
libmwaw, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 864366@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Rene Engelhard <rene@debian.org> (supplier of updated libmwaw package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 07 Jun 2017 22:47:10 +0200
Source: libmwaw
Binary: libmwaw-dev libmwaw-doc libmwaw-0.3-3 libmwaw-tools
Architecture: source amd64 all
Version: 0.3.1-2+deb8u1
Distribution: jessie-security
Urgency: medium
Maintainer: Rene Engelhard <rene@debian.org>
Changed-By: Rene Engelhard <rene@debian.org>
Description:
 libmwaw-0.3-3 - import library for some old Mac text documents
 libmwaw-dev - import library for some old Mac text documents -- development
 libmwaw-doc - import library for some old Mac text documents -- documentation
 libmwaw-tools - import library for some old Mac text documents -- tools
Closes: 864366
Changes:
 libmwaw (0.3.1-2+deb8u1) jessie-security; urgency=medium
 .
   * backport upstream patch to fix CVE-2017-9433 (closes: #864366)
Checksums-Sha1:
 d97e376ba3d419e92f1709b2130a98231a48fb21 1996 libmwaw_0.3.1-2+deb8u1.dsc
 02b6949b5d9fcd7ec3b0b686b1f8ab921fcdf033 1147351 libmwaw_0.3.1.orig.tar.bz2
 721b92e180e2fad1bf85d24802c4139e8b321047 7912 libmwaw_0.3.1-2+deb8u1.debian.tar.xz
 dd1a35ab5b0679b42bf7e264c316e9ab0c4cc0bf 18960 libmwaw-dev_0.3.1-2+deb8u1_amd64.deb
 6067c6e268e4996f005c93baf436f2bd488e4eb0 1928742 libmwaw-doc_0.3.1-2+deb8u1_all.deb
 5b912d27f329e34dc9eb527fb0598afda9dba14f 1808078 libmwaw-0.3-3_0.3.1-2+deb8u1_amd64.deb
 0ac25d4785d8bac6353ead2f26b40583f6c81173 19372 libmwaw-tools_0.3.1-2+deb8u1_amd64.deb
Checksums-Sha256:
 4ca2853bf1490b7b58ffcea295c06ead6aa1b654aedf0556b5c061f527214df3 1996 libmwaw_0.3.1-2+deb8u1.dsc
 66d3dbc4421daa628326204b5d14bb99f2b9d4423184027aabe207d677c89845 1147351 libmwaw_0.3.1.orig.tar.bz2
 18a5d88c6fd911bb0c98ae9cabf378c421724ae8598571a026b5cb9cc416e0bc 7912 libmwaw_0.3.1-2+deb8u1.debian.tar.xz
 f11add702d338885719a26ba1b714d20433b7458fb1bd12b3119f258ab81ef3f 18960 libmwaw-dev_0.3.1-2+deb8u1_amd64.deb
 af171349cea6faa60dc9fbceea9ac530dbcaab82b05423f602cdd45812eef8d6 1928742 libmwaw-doc_0.3.1-2+deb8u1_all.deb
 0d8fe8bf431ffb1eb08f11433064279092c63a861795713dd08c378cd8a7dabd 1808078 libmwaw-0.3-3_0.3.1-2+deb8u1_amd64.deb
 9978e91aac5cb0960e18d9111b694050a510f3e823213aa17324843c9cbae379 19372 libmwaw-tools_0.3.1-2+deb8u1_amd64.deb
Files:
 a376a941a87ac8d21c44ef060f3cdd7a 1996 libs optional libmwaw_0.3.1-2+deb8u1.dsc
 6f1ac4a0e24131c422e1e91f07718fb6 1147351 libs optional libmwaw_0.3.1.orig.tar.bz2
 71e4885c0a463ea00ce9107b20d1375e 7912 libs optional libmwaw_0.3.1-2+deb8u1.debian.tar.xz
 03444b5eea36e062f806ce4f66641389 18960 libdevel optional libmwaw-dev_0.3.1-2+deb8u1_amd64.deb
 4cb6f9f8e19afb60360c9a0f8efa8ec9 1928742 doc optional libmwaw-doc_0.3.1-2+deb8u1_all.deb
 76d6480c6d0a7c2577f5939daf79845b 1808078 libs optional libmwaw-0.3-3_0.3.1-2+deb8u1_amd64.deb
 406b17e8d0450f24173e45262fd5b104 19372 utils optional libmwaw-tools_0.3.1-2+deb8u1_amd64.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE4S3qRnUGcM+pYIAdCqBFcdA+PnAFAlk4e90ACgkQCqBFcdA+
PnDv4A/9HdZuxMxNoZf3PrVLYQHP05ByXrJK1NGn4JW/5vhBiqC6CQLm8Isclbx1
Q0ZBoQeda1hoIPMJwADbmKYxaFObHz6y+Eb4u0+whmuNB9YQ6Q+HCzj44XYPgpKQ
O267csBI7rzB8KDKPDZod6o67qu1du/w5gYbIDov7v5Up2hLwrb6k9Co3TMAOyis
BO3/mY7JHf3iLfo5Rop6LjxtlhweODQ52RGLNsWdoqeY/2k9vzKEnpDC5NiyJmZq
E1XKQlyUl/F9isDlOMkh8vvLcngVEgKAoQFohnem4imPS2BV0xRScnV/5zS/PJv1
8cKen2H6asLlx5vjBY217vjsXHMwFX6uXhT7Y6u1FNfDQu0k08hk0/d/vqdgQ420
cahL4jRkhiOuRf3xCzFDV5ELFaeWnt48UbD0EHOL/ffoYEVE6H61ugLxHhptQ8iA
5ycLJ+AV2v6ZhUA4G4i86A6lHZDMEEyG2AVQqSIWL9j5UXSOh5OwXi5FXE+upCwD
UcLmobPQpYrfJOg8Q9nBfYNWl8iVfnglye+U98FHevm23BeDr+no4wSHYYeR1H3d
ZNl/VAfucBBqGs36HlA7jmfo2dEyEbay3BeDpiOF7Vyu+wekI9F04WEAj904/hcK
O4RoQS8divzk9sbqRiO+iKRYwrBHujkRojVipTU4gnokt79GH80=
=eQmY
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 10 Jul 2017 07:25:32 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 18:52:23 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.