aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorDylan Aïssi <daissi@debian.org>2020-04-05 16:01:32 +0200
committerDylan Aïssi <daissi@debian.org>2020-04-05 16:01:32 +0200
commit48cd83222c42397ea2a1d993886472fe2026269a (patch)
tree4ea581ae403802b390c35f06939c944261e21cc8
parentc065cc15e14564a48b60fa53bedc2eb668666c49 (diff)
DLA-2169-1 advisory
-rw-r--r--english/lts/security/2020/dla-2169.data10
-rw-r--r--english/lts/security/2020/dla-2169.wml39
2 files changed, 49 insertions, 0 deletions
diff --git a/english/lts/security/2020/dla-2169.data b/english/lts/security/2020/dla-2169.data
new file mode 100644
index 00000000000..7ec543feda1
--- /dev/null
+++ b/english/lts/security/2020/dla-2169.data
@@ -0,0 +1,10 @@
+<define-tag pagetitle>DLA-2169-1 libmtp</define-tag>
+<define-tag report_date>2020-04-05</define-tag>
+<define-tag secrefs>CVE-2017-9831 CVE-2017-9832</define-tag>
+<define-tag packages>libmtp</define-tag>
+<define-tag isvulnerable>yes</define-tag>
+<define-tag fixed>yes</define-tag>
+<define-tag fixed-section>no</define-tag>
+
+#use wml::debian::security
+
diff --git a/english/lts/security/2020/dla-2169.wml b/english/lts/security/2020/dla-2169.wml
new file mode 100644
index 00000000000..b7d6bd2243a
--- /dev/null
+++ b/english/lts/security/2020/dla-2169.wml
@@ -0,0 +1,39 @@
+<define-tag description>LTS security update</define-tag>
+<define-tag moreinfo>
+
+<p>libmtp is a library for communicating with MTP aware devices. The Media
+Transfer Protocol (commonly referred to as MTP) is a devised set of custom
+extensions to support the transfer of music files on USB digital audio players
+and movie files on USB portable media players.</p>
+
+<ul>
+
+<li><a href="https://security-tracker.debian.org/tracker/CVE-2017-9831">CVE-2017-9831</a>
+
+ <p>An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx
+ function of the ptp-pack.c file allows attackers to cause a denial of
+ service (out-of-bounds memory access) or maybe remote code execution by
+ inserting a mobile device into a personal computer through a USB cable.</p></li>
+
+<li><a href="https://security-tracker.debian.org/tracker/CVE-2017-9832">CVE-2017-9832</a>
+
+ <p>An integer overflow vulnerability in ptp-pack.c (ptp_unpack_OPL function)
+ allows attackers to cause a denial of service (out-of-bounds memory
+ access) or maybe remote code execution by inserting a mobile device into
+ a personal computer through a USB cable.</p></li>
+
+</ul>
+
+<p>For Debian 8 <q>Jessie</q>, these problems have been fixed in version
+1.1.8-1+deb8u1.</p>
+
+<p>We recommend that you upgrade your libmtp packages.</p>
+
+<p>Further information about Debian LTS security advisories, how to apply
+these updates to your system and frequently asked questions can be
+found at: <a href="https://wiki.debian.org/LTS">https://wiki.debian.org/LTS</a></p>
+</define-tag>
+
+# do not modify the following line
+#include "$(ENGLISHDIR)/lts/security/2020/dla-2169.data"
+# $Id: $

© 2014-2024 Faster IT GmbH | imprint | privacy policy