#1011022 bullseye-pu: package htmldoc/1.9.11-4+deb11u3

#1011022#5
Date:
2022-05-15 14:40:16 UTC
From:
To:
Fixes three CVE's CVE-2022-24191, CVE-2022-27114 and CVE-2022-28085

[ Reason ]
One minor issue, two unimportant, still nice to have them all fixed at
the same time.

[ Impact ]
Images is now limited to 4GiB of memory usage (37837x37837 pixels).
Shouldn't really be any issue.

[ Tests ]
All CVE's comes with POC, have tested before and after, and can confirm
that the provided patches actually fixes the CVE's.

[ Risks ]
Most of the patches is more comparison and size checking.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
Three patches, all taken from upstream.

#1011022#10
Date:
2022-05-28 19:00:23 UTC
From:
To:
Control: tags -1 + confirmed

Please go ahead.

Regards,

Adam

#1011022#17
Date:
2022-05-29 18:19:19 UTC
From:
To:
package release.debian.org
tags 1011022 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: htmldoc
Version: 1.9.11-4+deb11u3

Explanation: fix infinite loop [CVE-2022-24191], integer overflow issues [CVE-2022-27114] and heap buffer overflow issue [CVE-2022-28085]

#1011022#22
Date:
2022-05-29 18:19:19 UTC
From:
To:
package release.debian.org
tags 1011022 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: htmldoc
Version: 1.9.11-4+deb11u3

Explanation: fix infinite loop [CVE-2022-24191], integer overflow issues [CVE-2022-27114] and heap buffer overflow issue [CVE-2022-28085]

#1011022#27
Date:
2022-07-09 10:47:43 UTC
From:
To:
(re-sending with fixed bug numbers)

Hi,

The updates discussed in these bugs were included in today's bullseye
point release.

Regards,

Adam