- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- HÃ¥vard Flaget Aasen
- Date:
- 2022-07-09 10:52:26 UTC
- Severity:
- normal
- Tags:
Fixes three CVE's CVE-2022-24191, CVE-2022-27114 and CVE-2022-28085 [ Reason ] One minor issue, two unimportant, still nice to have them all fixed at the same time. [ Impact ] Images is now limited to 4GiB of memory usage (37837x37837 pixels). Shouldn't really be any issue. [ Tests ] All CVE's comes with POC, have tested before and after, and can confirm that the provided patches actually fixes the CVE's. [ Risks ] Most of the patches is more comparison and size checking. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable [ Changes ] Three patches, all taken from upstream.
Control: tags -1 + confirmed Please go ahead. Regards, Adam
package release.debian.org tags 1011022 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: htmldoc Version: 1.9.11-4+deb11u3 Explanation: fix infinite loop [CVE-2022-24191], integer overflow issues [CVE-2022-27114] and heap buffer overflow issue [CVE-2022-28085]
package release.debian.org tags 1011022 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: htmldoc Version: 1.9.11-4+deb11u3 Explanation: fix infinite loop [CVE-2022-24191], integer overflow issues [CVE-2022-27114] and heap buffer overflow issue [CVE-2022-28085]
(re-sending with fixed bug numbers) Hi, The updates discussed in these bugs were included in today's bullseye point release. Regards, Adam