Backport is based on wrong version.
- stable has libhtp 1:0.5.50-1+deb13u1, including a fix for CVE-2025-53537
- the base version you used for backporting (1:0.5.50-1) is missing this fix

As a result the backported package is missing the CVE fix.

A proper backport of 1:0.5.50-1+deb13u1 targeting bookworm-backports will have
version 1:0.5.50-1+deb13u1~bpo12+1.



===

Please feel free to respond to this email if you don't understand why
your files were rejected, or if you upload new files which address our
concerns.

Attachment: pgpjMzTXT5ZLY.pgp
Description: PGP signature

Reply via email to