-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 26 Jan 2024 20:37:26 +0100 Source: libspreadsheet-parsexlsx-perl Architecture: source Version: 0.27-3+deb12u2 Distribution: bookworm Urgency: medium Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org> Changed-By: gregor herrmann <gregoa@debian.org> Closes: 1061098 Changes: libspreadsheet-parsexlsx-perl (0.27-3+deb12u2) bookworm; urgency=medium . * Team upload. * Add a patch to fix an xml external entity (XEE) injection bug. [CVE-2024-23525] Patch taken from an upstream Git commit contained in the 0.30 release. (Closes: #1061098) . libspreadsheet-parsexlsx-perl (0.27-3+deb12u1) bookworm; urgency=medium . * Team upload. * Add a patch to fix a possible memory bomb. [CVE-2024-22368] Patch taken from two upstream Git commits contained in the 0.28 release. Checksums-Sha1: d72a16cfec08a13039c1eab7dbaba9d768c762f9 2689 libspreadsheet-parsexlsx-perl_0.27-3+deb12u2.dsc a8065da892d76543dc56448168ce546353bbb777 4352 libspreadsheet-parsexlsx-perl_0.27-3+deb12u2.debian.tar.xz Checksums-Sha256: 2d6bffab2f99b3526fa9f3fba1875e2647fd44c4e259cbcd200311a3413f50ab 2689 libspreadsheet-parsexlsx-perl_0.27-3+deb12u2.dsc 6e75d6153572445c669c1d36746633a6ec1f6b5bf66e052afd327ce39467a728 4352 libspreadsheet-parsexlsx-perl_0.27-3+deb12u2.debian.tar.xz Files: 66e1feb233466ffed40945530a3b2f9b 2689 perl optional libspreadsheet-parsexlsx-perl_0.27-3+deb12u2.dsc 806513d3154a9acb527157e140e43950 4352 perl optional libspreadsheet-parsexlsx-perl_0.27-3+deb12u2.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmW0CydfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ qgZG2RAAm6IJqmHnsdFvvGFP4Rsw1zCk2Uhadb4g3TGO9ernq5sFSqJk4mw8+m9c tBJ1vEL1aya9cQAncagGSk7tVSy1+hhZDRe3OILPkglqnKUejrANhwWhd4QIj+Eo O0mC8vWzdEIeR6/GB0ChNXRGGIeYhAU0SZ7+zCgGC4HTdGpktgssq0yTAmTiRxly AEVmxZtJD0wLF3mo38PExAthPA/nqQ7xjNTceSF4qJyTiZBZfbyM9SjUoTHx4Dt9 YzaCHW9Kg4wbNSwUhIkFop0Tde0JCEFdyvlhWm2Cj7l4OhKaDcMeSNMuP1BC4kqI Z26UOryKMOnp4EYKE9FXj5ARMH+sIPFeKyp2k6nwgyeFozURDsui6jHUo82/68Ea BqETx+NTLeHs8jr1wKDg/6zPUY1uks3+cweO0Mfb9R5RgYMVz/3iJg40BT37Kwu3 M2K1gxnG6Ntae8vWCqOV/xMG1y6bZbPeApMJ7zyXk+baaLWrGmBQdB7RlScfjYJV uv/MdvRMneAOoZf97RBpBh8EFIgfEUvKrW4gmiT1hqbgq58SFZLuLqZzmj+j8kYb zHYQjx4eOsw56+r4D8P9Dhx2JtDRC3zYIsCMIiSZi10z46PS1u/BzF192L8Od+BC ujQdoozE/PczLQGrNIX0B/op8Ninp7jK3tm/RpQRBcwxJch9TJM= =vkkC -----END PGP SIGNATURE-----