Re: Please fix Debian bug 1032091 "py7zr: CVE-2022-44900"

2023-03-24 Thread yokota
Hello, Sandro. > feel free to provide a patch to fix it. upgrading to newer upstream > releases is prohibitive given the increasing amount of > additional/frivolous dependencies upstream decided to rely on. Thanks for your quick response. I was pushed merge request to Debian salsa repository

Re: Please fix Debian bug 1032091 "py7zr: CVE-2022-44900"

2023-03-23 Thread Sandro Tosi
> Debian "py7zr" package has security issue CVE-2022-44900, > and this issue affects Debian "calibre" package because "calibre" depends > this "py7zr" module. > https://tracker.debian.org/pkg/py7zr > > Please examine Debian bug report 1032091, and fix this issue. >

Please fix Debian bug 1032091 "py7zr: CVE-2022-44900"

2023-03-23 Thread yokota
Hello, Python maintainers. Debian "py7zr" package has security issue CVE-2022-44900, and this issue affects Debian "calibre" package because "calibre" depends this "py7zr" module. https://tracker.debian.org/pkg/py7zr Please examine Debian bug report 1032091, and fix this issue.