-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 26 Jan 2024 20:34:16 +0100 Source: libspreadsheet-parsexlsx-perl Architecture: source Version: 0.27-2.1+deb11u2 Distribution: bullseye Urgency: medium Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org> Changed-By: gregor herrmann <gregoa@debian.org> Closes: 1061098 Changes: libspreadsheet-parsexlsx-perl (0.27-2.1+deb11u2) bullseye; urgency=medium . * Team upload. * Add a patch to fix an xml external entity (XEE) injection bug. [CVE-2024-23525] Patch taken from an upstream Git commit contained in the 0.30 release. (Closes: #1061098) . libspreadsheet-parsexlsx-perl (0.27-2.1+deb11u1) bullseye; urgency=medium . * Team upload. * Add a patch to fix a possible memory bomb. [CVE-2024-22368] Patch taken from two upstream Git commits contained in the 0.28 release. Checksums-Sha1: 1adf305a5e41a1a67b6140a86344fa09f22fbb94 2703 libspreadsheet-parsexlsx-perl_0.27-2.1+deb11u2.dsc 54342304f614214a48e1a3914a15b8dbc801bc41 4156 libspreadsheet-parsexlsx-perl_0.27-2.1+deb11u2.debian.tar.xz Checksums-Sha256: 72c9dcf67d1d73bdc26e492defca05f347dfd68e79f9295e475af5d17935e62d 2703 libspreadsheet-parsexlsx-perl_0.27-2.1+deb11u2.dsc 325b250f39ade1d3b5b0584c75939535d31c607565cb3c8043831572453baaac 4156 libspreadsheet-parsexlsx-perl_0.27-2.1+deb11u2.debian.tar.xz Files: 697c7f0a2c9b5884b30f4d8a929fdad0 2703 perl optional libspreadsheet-parsexlsx-perl_0.27-2.1+deb11u2.dsc eee5b947ed22dc79e66d82d43b179007 4156 perl optional libspreadsheet-parsexlsx-perl_0.27-2.1+deb11u2.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmW0CeNfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ qgaQrA//ZyjV/N8zjCR0fRFp50GwobZh3RRQ1JZV6jg+AagtbbFWif8ekVibBTaM ZtIZTNe5oisiZ3KzIDiZiccAqMrzqzI0r5g2cnrxPtPA+4rcNw+p6q+xzbt8k3Og B0cnrlUpRmMF3knxMe1fC++i0HYECtGvhQe2zaXwKn1bW8pcM6MpOwPqtRqUxzVf FXWBHpSnOUDgrO4+2+73R+l7FWm9n3p+131FAHEhshJ2Bgj+b7Wm7zfDOOM130Ug AVtPHyg3Gl3E49taU7pHEuzeNhvo32XVOO0SOWlytUR9HTqn/XCHIkONc2InN1TU FmTFqY2DRbdGZOZy/ycxzK9J/pRIWIo795TM//cstIM0HTOLQSPuoiNh+Qr5Ek1j hqUe1MjrMAIsGY3ttZYk3UxFz4KEGq9tWpZg0y5//hJ3N+q4BzIYz7/GuluRwEtO K2lrJqIgmx1KVj3pvFTP4T+/jvnXBiVy2PM/t4h5Xs3VrjeWY7B1IS+bLQLXfjNk NjSVSL8aJhS3Zp+CtLipJ4suW1TtuF/QAjRnNY+tH07xTO8tvGffEEvyraRT2QBd crig9KlhkWNtBsDyy1CI42l7vIseXHNqBN25jx1KBJuPM+gTY/1qc/H/20n3RlL9 /iDD/SHzMxgAUPTiSvIMlz50mkJUsvlC0L2iLisQHBkJbp+1Uf4= =i+QW -----END PGP SIGNATURE-----