Discussion:
Processed: pagure: CVE-2024-47515
Add Reply
Debian Bug Tracking System
2024-12-25 07:20:01 UTC
Reply
Permalink
found -1 5.11.3+dfsg-2.1
Bug #1091383 [src:pagure] pagure: CVE-2024-47515
Marked as found in versions pagure/5.11.3+dfsg-2.1.
found -1 5.11.3+dfsg-1
Bug #1091383 [src:pagure] pagure: CVE-2024-47515
Marked as found in versions pagure/5.11.3+dfsg-1.
--
1091383: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1091383
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Debian Bug Tracking System
2025-01-01 21:20:01 UTC
Reply
Permalink
tags -1 pending
Bug #1091383 [src:pagure] pagure: CVE-2024-47515
Added tag(s) pending.
--
1091383: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1091383
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Rebecca N. Palmer
2025-01-02 22:00:01 UTC
Reply
Permalink
I suspect that the generate_archive patch has a bug: zf.writestr(zi,
path) sets the file contents of the symlink in the zip (i.e. the
filename it points to) to path (the filename of the original symlink,
not the filename it points to). Hence, it creates a symlink to itself,
not a symlink to whatever the original symlink pointed to. The included
tests don't notice because they don't check where the symlink points to.

However, I don't know whether the obvious way to fix that would
introduce new security problems.
Debian Bug Tracking System
2025-01-20 08:50:01 UTC
Reply
Permalink
Your message dated Mon, 20 Jan 2025 08:41:20 +0000
with message-id <E1tZnLU-00FHON-***@fasolo.debian.org>
and subject line Bug#1091383: fixed in pagure 5.14.1+dfsg-1
has caused the Debian Bug report #1091383,
regarding pagure: CVE-2024-47515 CVE-2024-47516 CVE-2024-4981 CVE-2024-4982
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ***@bugs.debian.org
immediately.)
--
1091383: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1091383
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Loading...