#1147105 trixie-pu: package libhtml-formhandler-perl/0.40068-3~deb13u1

#1147105#5
Date:
2026-09-07 20:01:30 UTC
From:
To:
Hi SRM'ers

This is out of scope for 13.7 now, but please consider it for 13.8.

libhtml-formhandler-perl in trixie is vulenerable to CVE-2022-4993,
allowing an attacker selected method dispatch and resource exhaustion.
We did mark it as no-dsa, but would be nice to have it fixed in trixie
as well.

The unstable upload on purpose back in august did only apply the patch
for the CVE, so trixie's upload will be a rebuild of the unstable
version to trixie.

Attached the debdiff for the upload.

QA testing has as well been performed on reverse dependencies as per
https://debusine.debian.net/debian/developers/work-request/1232972/

Regards,
Salvatore