- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Thorsten Alteholz
- Date:
- 2022-07-09 10:51:53 UTC
- Severity:
- normal
- Tags:
The attached debdiff for fribidi fixes CVE-2022-25308, CVE-2022-25309 and CVE-2022-25310 in Bullseye. These CVEs have been marked as no-dsa by the security team. The same fixes have been already uploaded to Unstable. Thorsten
Control: tags -1 + confirmed d-i This looks OK to me, thanks, but will need a KiBi-ack as fribidi produces a udeb; CCing and tagging accordingly. Regards, Adam
... and uploaded. Thorsten
package release.debian.org tags 1009250 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: fribidi Version: 1.0.8-2+deb11u1 Explanation: fix buffer overflow issues [CVE-2022-25308 CVE-2022-25309]; fix crash [CVE-2022-25310]
package release.debian.org tags 1009250 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: fribidi Version: 1.0.8-2+deb11u1 Explanation: fix buffer overflow issues [CVE-2022-25308 CVE-2022-25309]; fix crash [CVE-2022-25310]
(re-sending with fixed bug numbers) Hi, The updates discussed in these bugs were included in today's bullseye point release. Regards, Adam