There are 2 open security issues in trixie.
There are 2 open security issues in sid.
commit b5c2aad795be6b770793322b51bba90fa02658b4 Author: Barak A. Pearlmutter <barak+git@pearlmutter.net> Date: Tue Mar 22 22:02:42 2022 +0000 approved way of snarfing DEB_HOST_MULTARCH commit 1b3abdc78d799756494de8d66dfeebec91b19970 Author: Barak A. Pearlmutter <barak+git@pearlmutter.net> Date: Wed Jul 26 21:02:53 2023 +0100 Update standards version to 4.6.2, no changes needed. Changes-By: lintian-brush Fixes: lintian: out-of-date-standards-version See-also: https://lintian.debian.org/tags/out-of-date-standards-version.html commit 646e08bf470debac77cc44666c06d31492a9ef91 Merge: 58afe62 6a1e5ba Author: Barak A. Pearlmutter <barak+git@pearlmutter.net> Date: Wed Jul 26 21:00:24 2023 +0100 Merge branch 'master' into debian commit 58afe620206653054d163e63325b9c9081eafb5f Merge: 8a7c725 2d77098 Author: Jelmer Vernooij <jelmer@debian.org> Date: Sat Nov 19 11:52:46 2022 +0000 Merge branch 'lintian-fixes' into 'debian' Fix some issues reported by lintian See merge request debian/djvulibre!2 commit 2d770986c5b1a97153eeda91b3f1c87c7de3fa0a Author: Debian Janitor <janitor@jelmer.uk> Date: Mon Nov 14 23:48:47 2022 +0000 Update standards version to 4.6.1, no changes needed. Changes-By: lintian-brush Fixes: lintian: out-of-date-standards-version See-also: https://lintian.debian.org/tags/out-of-date-standards-version.html commit eb64cda0e7d1f38e72986ba608439288c99b295b Author: Debian Janitor <janitor@jelmer.uk> Date: Mon Nov 14 23:48:34 2022 +0000 Use secure URI in Homepage field. Changes-By: lintian-brush Fixes: lintian: homepage-field-uses-insecure-uri See-also: https://lintian.debian.org/tags/homepage-field-uses-insecure-uri.html commit 6a1e5ba1c9ef81c205a4b270c3f121a1e106f4fc Author: Leon Bottou <leonb@fb.com> Date: Thu Aug 4 19:06:51 2022 -0400 Add navm fix to djvuchanges. Fix -bpp limit in c44. commit 1a47fd3a6396efcbcba892bb415185ddeb6d3535 Author: Leon Bottou <leon@bottou.org> Date: Sun Dec 5 19:17:49 2021 -0500 Improved merge_and_split_ccs does not join large cc pieces. See https://sourceforge.net/p/djvu/discussion/103286/thread/3898bf84bf/?limit=25#b26f commit 8a7c7253ad2a1a8c64f09c81d4b72fd0d8e28024 Author: Barak A. Pearlmutter <barak+git@pearlmutter.net> Date: Thu Sep 2 14:17:17 2021 +0100 bump policy commit d0b5e196b0417cce836ce606df9dd5691f1fe2d1 Merge: 2bec685 2ad2b70 Author: Barak A. Pearlmutter <barak+git@pearlmutter.net> Date: Fri Jul 23 14:14:49 2021 +0100 Merge remote-tracking branch 'upstream/master' into debian commit 2ad2b702d864d1974f0c569a7594b27e67c64a40 Author: Leon Bottou <leon@bottou.org> Date: Sun Jul 11 09:38:52 2021 -0400 fixed typo in previous commit commit 254b3f3f3824960eb1eed5f3d5683c30365ff95c Author: Leon Bottou <leon@bottou.org> Date: Sun Jul 11 08:48:31 2021 -0400 Tentative fix for bug #302 commit 9d00916b06a54bb8ce2807f2d6faeb4f1a6aa118 Author: Leon Bottou <leon@bottou.org> Date: Tue Jun 15 18:38:23 2021 -0400 tentative fix for incorrect resolution in tiff tags commit eec7b7228d2c4d8f95d824fc3911f2a5ff57ffa9 Author: Leon Bottou <leon@bottou.org> Date: Wed Jun 2 09:50:37 2021 -0400 DjVuToPS fix for images without foreground. commit 2bec685223379e3ab590318f0d2600d822f78aca Author: Barak A. Pearlmutter <barak+git@pearlmutter.net> Date: Fri May 28 11:37:56 2021 +0100 All Hail the Multiarch Hinter Toad! commit 0a984511acc1e7cbfa34bcee23d9fdd3de07febb Author: Barak A. Pearlmutter <barak+git@pearlmutter.net> Date: Tue May 11 23:13:07 2021 +0100 remove upstreamed or unnecessary patches commit 5613eca9d98aa7a2eaf2143f415dd7294db6b646 Merge: 098c818 cd8b5c9 Author: Barak A. Pearlmutter <barak+git@pearlmutter.net> Date: Tue May 11 23:08:08 2021 +0100 Merge remote-tracking branch 'upstream/master' into debian commit cd8b5c97b27a5c1dc83046498b6ca49ad20aa9b6 Author: Leon Bottou <leon@bottou.org> Date: Tue May 11 14:44:09 2021 -0400 Reviewed Fedora patches and adopted some of them (or variants thereof) - Patch0: djvulibre-3.5.22-cdefs.patch (forward ported) Does not make imuch sense. GSmartPointer.h already includes "stddef.h" - Patch6: djvulibre-3.5.27-export-file.patch (forward ported) Incorrect: inkscape command is --export-png, not --export-filename. - Patch8: djvulibre-3.5.27-check-image-size.patch (forward ported) Correct: adopted a variant of this - Patch9: djvulibre-3.5.27-integer-overflow.patch (forward ported) Correct: adopted a variant of this - Patch10: djvulibre-3.5.27-check-input-pool.patch (forward ported) Adopted: input validation never hurts - Patch11: djvulibre-3.5.27-djvuport-stack-overflow.patch (forward ported) Dubious: Instead I changed djvufile to prevent a file from including itself which is the only way I can imagine to create an file creation loop. - Patch12: djvulibre-3.5.27-unsigned-short-overflow.patch (forward ported) Adopted: but without including limits.h
Among the 7 debian patches available in version 3.5.28-2 of the package, we noticed the following issues:
There are 2 open security issues in bookworm.