CVE-2019-19333 & CVE-2019-19334 in libyang

Related Vulnerabilities: CVE-2019-19333   CVE-2019-19334  

Debian Bug report logs - #946217
CVE-2019-19333 & CVE-2019-19334 in libyang

version graph

Reported by: David Lamparter <equinox-debian@diac24.net>

Date: Thu, 5 Dec 2019 18:00:02 UTC

Severity: grave

Tags: security, upstream

Found in version libyang/0.16.105-1

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org:
Bug#946217; Package libyang0.16. (Thu, 05 Dec 2019 18:00:05 GMT) (full text, mbox, link).


Acknowledgement sent to David Lamparter <equinox-debian@diac24.net>:
New Bug report received and forwarded. (Thu, 05 Dec 2019 18:00:05 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: David Lamparter <equinox-debian@diac24.net>
To: submit@bugs.debian.org
Subject: CVE-2019-19333 & CVE-2019-19334 in libyang
Date: Thu, 5 Dec 2019 18:45:33 +0100
Package: libyang0.16
Version: 0.16.105-1
Tags: security
Severity: grave

This is a security issue tracking bug for CVEs:
- CVE-2019-19333
- CVE-2019-19334

Both issues are bugs in processing YANG models and may affect users
loading or validating untrusted YANG models.  This is a relatively rare
use case as normal application use of libyang would rely on application
supplied models.

Fixes are available upstream.

As the package maintainer, my plan for unstable is to ship a 0.16.105-2
quickly, followed by actually bringing 1.0.x into unstable.

I've contacted the Debian security team wrt. fixing this for buster.


-David



Added tag(s) upstream. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 05 Dec 2019 20:03:02 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Thu Dec 5 20:51:52 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.