Debian Package Tracker
Register | Log in
Subscribe

azure-uamqp-python

Choose email to subscribe with

general
  • source: azure-uamqp-python (main)
  • version: 1.6.11-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Luca Boccassi [DMD]
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 1.2.13-1
  • stable: 1.5.3-1
  • testing: 1.6.11-1
  • unstable: 1.6.11-1
versioned links
  • 1.2.13-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.5.3-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.11-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-uamqp
action needed
4 low-priority security issues in bookworm low

There are 4 open security issues in bookworm.

4 issues left for the package maintainer to handle:
  • CVE-2024-21646: (needs triaging) Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP protocol communication. When clients using this library receive a crafted binary type data, an integer overflow or wraparound or memory safety issue can occur and may cause remote code execution. This vulnerability has been patched in release 2024-01-01.
  • CVE-2024-25110: (needs triaging) The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to update the submodule with commit `30865c9c`. There are no known workarounds for this vulnerability.
  • CVE-2024-27099: (needs triaging) The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` failed state, may cause a double free problem. This may cause a RCE. Update submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987.
  • CVE-2024-29195: (needs triaging) The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparound or under-allocation or heap buffer overflow due to vulnerabilities in parameter checking mechanism, by exploiting the buffer length parameter in Azure C SDK, which may lead to remote code execution. Requirements for RCE are 1. Compromised Azure account allowing malformed payloads to be sent to the device via IoT Hub service, 2. By passing IoT hub service max message payload limit of 128KB, and 3. Ability to overwrite code space with remote code. Fixed in commit https://github.com/Azure/azure-c-shared-utility/commit/1129147c38ac02ad974c4c701a1e01b2141b9fe2.

You can find information about how to handle these issues in the security team's documentation.

Created: 2024-02-16 Last update: 2025-02-27 05:02
debian/patches: 2 patches to forward upstream low

Among the 2 debian patches available in version 1.6.11-1 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2024-03-11 Last update: 2024-10-30 07:01
Build log checks report 1 warning low
Build log checks report 1 warning
Created: 2021-08-18 Last update: 2021-08-18 04:53
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.7.0).
Created: 2025-02-21 Last update: 2025-02-27 13:25
news
[rss feed]
  • [2024-11-01] azure-uamqp-python 1.6.11-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-29] Accepted azure-uamqp-python 1.6.11-1 (source) into unstable (Michael R. Crusoe)
  • [2024-10-27] azure-uamqp-python 1.6.10-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-25] Accepted azure-uamqp-python 1.6.10-1 (source) into unstable (Luca Boccassi)
  • [2024-08-09] azure-uamqp-python 1.6.9-3 MIGRATED to testing (Debian testing watch)
  • [2024-08-06] Accepted azure-uamqp-python 1.6.9-3 (source) into unstable (Thomas Goirand)
  • [2024-04-25] azure-uamqp-python 1.6.9-2 MIGRATED to testing (Debian testing watch)
  • [2024-04-17] Accepted azure-uamqp-python 1.6.9-2 (source) into unstable (Thomas Goirand)
  • [2024-03-21] Accepted azure-uamqp-python 1.6.9-1 (source) into unstable (Michael R. Crusoe)
  • [2024-03-10] Accepted azure-uamqp-python 1.6.8-2 (source) into unstable (Michael R. Crusoe)
  • [2024-02-13] azure-uamqp-python 1.6.8-1 MIGRATED to testing (Debian testing watch)
  • [2024-02-13] azure-uamqp-python 1.6.8-1 MIGRATED to testing (Debian testing watch)
  • [2024-02-08] Accepted azure-uamqp-python 1.6.8-1 (source) into unstable (Luca Boccassi)
  • [2024-01-04] azure-uamqp-python 1.6.5-2 MIGRATED to testing (Debian testing watch)
  • [2024-01-01] Accepted azure-uamqp-python 1.6.5-2 (source) into unstable (Luca Boccassi)
  • [2023-08-03] azure-uamqp-python 1.6.5-1 MIGRATED to testing (Debian testing watch)
  • [2023-08-03] azure-uamqp-python 1.6.5-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-31] Accepted azure-uamqp-python 1.6.5-1 (source) into unstable (Luca Boccassi)
  • [2023-07-10] azure-uamqp-python 1.6.4-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-07] Accepted azure-uamqp-python 1.6.4-1 (source) into unstable (Luca Boccassi)
  • [2022-04-02] azure-uamqp-python 1.5.3-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-30] Accepted azure-uamqp-python 1.5.3-1 (source) into unstable (Luca Boccassi)
  • [2022-03-23] azure-uamqp-python 1.5.2-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-21] Accepted azure-uamqp-python 1.5.2-1 (source) into unstable (Luca Boccassi)
  • [2022-01-17] azure-uamqp-python 1.5.1-1 MIGRATED to testing (Debian testing watch)
  • [2022-01-14] Accepted azure-uamqp-python 1.5.1-1 (source) into unstable (Luca Boccassi)
  • [2022-01-12] azure-uamqp-python 1.5.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-01-10] Accepted azure-uamqp-python 1.5.0-1 (source) into unstable (Luca Boccassi)
  • [2021-10-28] azure-uamqp-python 1.4.3-1 MIGRATED to testing (Debian testing watch)
  • [2021-10-25] Accepted azure-uamqp-python 1.4.3-1 (source) into unstable (Luca Boccassi)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, checks, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.6.11-1build2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing