pspp: CVE-2019-9211

Related Vulnerabilities: CVE-2019-9211  

Debian Bug report logs - #923417
pspp: CVE-2019-9211

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Wed, 27 Feb 2019 21:33:01 UTC

Severity: normal

Tags: security, upstream

Found in version pspp/1.2.0-2

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, team@security.debian.org, Friedrich Beckmann <friedrich.beckmann@gmx.de>:
Bug#923417; Package src:pspp. (Wed, 27 Feb 2019 21:33:04 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, team@security.debian.org, Friedrich Beckmann <friedrich.beckmann@gmx.de>. (Wed, 27 Feb 2019 21:33:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: pspp: CVE-2019-9211
Date: Wed, 27 Feb 2019 22:31:58 +0100
Source: pspp
Version: 1.2.0-2
Severity: normal
Tags: security upstream

Hi,

The following vulnerability was published for pspp.

CVE-2019-9211[0]:
| There is a reachable assertion abort in the function
| write_long_string_missing_values() in data/sys-file-writer.c in
| libdata.a in GNU PSPP 1.2.0 that will lead to denial of service.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-9211
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9211
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1683499

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



Information forwarded to debian-bugs-dist@lists.debian.org, Friedrich Beckmann <friedrich.beckmann@gmx.de>:
Bug#923417; Package src:pspp. (Thu, 28 Feb 2019 04:21:03 GMT) (full text, mbox, link).


Acknowledgement sent to Ben Pfaff <blp@cs.stanford.edu>:
Extra info received and forwarded to list. Copy sent to Friedrich Beckmann <friedrich.beckmann@gmx.de>. (Thu, 28 Feb 2019 04:21:03 GMT) (full text, mbox, link).


Message #10 received at 923417@bugs.debian.org (full text, mbox, reply):

From: Ben Pfaff <blp@cs.stanford.edu>
To: Salvatore Bonaccorso <carnil@debian.org>, 923417@bugs.debian.org
Subject: Re: Bug#923417: pspp: CVE-2019-9211
Date: Wed, 27 Feb 2019 20:17:05 -0800
On Wed, Feb 27, 2019 at 10:31:58PM +0100, Salvatore Bonaccorso wrote:
> Source: pspp
> Version: 1.2.0-2
> Severity: normal
> Tags: security upstream
> 
> Hi,
> 
> The following vulnerability was published for pspp.
> 
> CVE-2019-9211[0]:
> | There is a reachable assertion abort in the function
> | write_long_string_missing_values() in data/sys-file-writer.c in
> | libdata.a in GNU PSPP 1.2.0 that will lead to denial of service.

I fixed this on PSPP master with commit 0b842a843537 ("sys-file-writer:
Remove assertions based on file position.").

As has become usual, this bug was reported to Debian and Red Hat and
MITRE and never to me, the upstream author.  If you know any way to
de-anonymize whoever is actually finding these bugs, I'd appreciate it.
Whoever it is deserves education.



Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 18:23:19 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.