Re: [SECURITY] libapt-pkg: wild pointer dereference and daemon crash via versionless stanza in debDebFileParser::UsePackage
David Kalnischkies <[email protected]>
| Newsgroups | gmane.linux.debian.apt.devel |
|---|---|
| Message-ID | <aoREVma55rDdlm1f@crossbow> |
(not commenting at this moment on your actual report) Am Tue, Aug 18, 2026 at 10:19:54AM +0300, schrieb Christos Papakonstantinou: > We are always committed to responsible disclosure in accordance with your > security policy. Note that by mailing [email protected] you have publicly disclosed your report already as that mail forwards to the maintainer(s) of that package in Debian, which in this case (and in many others as well) is a publicly archived mailing list. Reference: https://lists.debian.org/deity/2026/08/msg00015.html If you want to make a report against a Debian package its usually best to contact Debians security team ~ they will know which and how to contact the maintainers as well as fellow teams in downstream distributions like Ubuntu and the rest of the large Debian family. See also: https://www.debian.org/security/faq#contact Of course, contacting Ubuntus security team only would have worked as well, given you seem focused on Ubuntu, as they would have looped in Debian and the rest if needed. Best regards David Kalnischkies
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE5sn+Q4uCja/tn0GrMRvlz3HQeIMFAmqES3MACgkQMRvlz3HQ eIOeSxAAlMy8YL9bPuam1kiseiAA2o/5Vld8lp/uT0/HE/jU2JieAxV0u1/A8DPL IqtV4Rd/lbfKv8uVxWHUcMEJxiZmwr224fdl1YUpFMOCvUqXtKEDBq7Z1AVrxjMg X8EUoidn+GxTM+espNl0soTNTXG6rqvoz6U2Zi9rpQQD6dv2JClR86EBu5p5VD5H 2ZeW31I6R51nFpcAbcwaUGdmqh/vALzvk14y3bHTC/uPQ+Z9P6poZjXEmApDEC8U yYvIOiFZ+gmZPadDyy+fJsAokvL9ziirnr8X9yK6GMCXH4yz8ggl8v4IYQUYSUlS XNpWfva346BC98n1vrLulSQp1I2cvKfbg3wFR6oEN84CzK1Sxy5QOhxpRuAEyIZi TfrKtVn6T9XXlr2QMRp87plJWzjS4F1oPAkiJ1RF006YXIm1H4aZg0PLsD4b8c3m r3YtSK/yOaJv1EvZZMjkx2kE5RyYGVlPpbULW7gTlOR5yCL+683f8HTQAhKMAeqM S0oSl/tE/QHRGnfVK7/B80Khsb0j1jfksnN9SHkkYXikMkfr+79aU6iFNIownmoZ veHY+9RuJp/w1i0MJbXGdI10FprJO/wG0u6mATdv2m0wrPlQjv4XHRFFt9CN1JFF BkAS52fWcn9F9mM2maD+3nTDqA0N19ZXgb+UEdxDq3wGWettEgk= =0BSY -----END PGP SIGNATURE-----