Your message dated Fri, 31 Jul 2026 05:49:54 +0000
with message-id <[email protected]>
and subject line Bug#1143152: fixed in libgd2 2.3.3-14
has caused the Debian Bug report #1143152,
regarding libgd2: CVE-2026-9672
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1143152: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143152
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libgd2
Version: 2.3.3-13
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team 
<[email protected]>, [email protected]

Hi Ondrej,

This appeared in the PHP changelog of the recent releases, and was
fixed in PHP embedded copy as
https://github.com/php/php-src/commit/fcd691b377d02285740744bee17c0f298be227d5
but I do not see upstream related informations or changes in the libgd
project itself.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: libgd2
Source-Version: 2.3.3-14
Done: Ondřej Surý <[email protected]>

We believe that the bug you reported is fixed in the latest version of
libgd2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ondřej Surý <[email protected]> (supplier of updated libgd2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 31 Jul 2026 07:09:41 +0200
Source: libgd2
Architecture: source
Version: 2.3.3-14
Distribution: unstable
Urgency: medium
Maintainer: GD Team <[email protected]>
Changed-By: Ondřej Surý <[email protected]>
Closes: 1143151 1143152
Changes:
 libgd2 (2.3.3-14) unstable; urgency=medium
 .
   * Change the homepage to https://libgd.github.io (Closes: #1143151)
   * libgd patch for CVE-2026-9672 (Closes: #1143152)
Checksums-Sha1:
 d6073972c9ec9def3d8ab65f174316b2e27f2bc7 2440 libgd2_2.3.3-14.dsc
 a275344fb56161df6a06679bf0bf29c30930d8eb 3593182 libgd2_2.3.3.orig.tar.gz
 30f563aead1dfb0b7d27a4363575b75aa95e4a01 33032 libgd2_2.3.3-14.debian.tar.xz
 190dc64cc7558287f26248c58bf4553391bdcfe0 8953 libgd2_2.3.3-14_amd64.buildinfo
Checksums-Sha256:
 9ccef3efe55777d872685fefddfa50e6f0750476b1e35e4d0ba40c74165ac153 2440 
libgd2_2.3.3-14.dsc
 dd3f1f0bb016edcc0b2d082e8229c822ad1d02223511997c80461481759b1ed2 3593182 
libgd2_2.3.3.orig.tar.gz
 2f6f843e4cb4888f8320939326f274c45b1b17e986339c80709f2744b6b08df2 33032 
libgd2_2.3.3-14.debian.tar.xz
 65bda6798f20322e114b0d0d01c924421b444a97b5d0fb35ca1524b298eeba70 8953 
libgd2_2.3.3-14_amd64.buildinfo
Files:
 5afe02387432febf5cf2fed36c12a2dc 2440 graphics optional libgd2_2.3.3-14.dsc
 bf6d41ecb3148a6238a3058eb3d6224a 3593182 graphics optional 
libgd2_2.3.3.orig.tar.gz
 957497de689cac885842f6959c627b30 33032 graphics optional 
libgd2_2.3.3-14.debian.tar.xz
 a077bc04fcd28944138f361a5b0dd6f1 8953 graphics optional 
libgd2_2.3.3-14_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEw2Gx4wKVQ+vGJel9g3Kkd++uWcIFAmpsMPNfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEMz
NjFCMUUzMDI5NTQzRUJDNjI1RTk3RDgzNzJBNDc3RUZBRTU5QzIACgkQg3Kkd++u
WcJlBhAAm7vlJ6lq+zFFB0J3i9CkluKodL63I/AQLMlD1IDAhP6k7DDjRXJBGiAP
rTOdWYz5dtTg++1iBFZ7HrVC05HWzeUQVZoy5q0zrpOF5oNAegjevP4CfOWfjy9C
1hm+9lSZY7lwibGqkakepidK3kYcoulc1IL3F7eINX7m4RErtfv9PH+EJlOoid/d
oiIFMxeln7BCcOwLA+EJXY4bhKw7rpCXB6p4uoD1GVthgiBEFkfmJ5C5h8rlfc+4
5Vf09K6FY0dmA90fHo+UIp/eBKqUw858Ms5UBnwNTLWi7qC+lJ+mh6kYUgva1mLq
QZdBm/i+kFKcW6eYkiIubOrX83QY/eCAjydK79wKLOqE6hvUvwUZg+OAuOKFZtcu
UuvPVlLu5DPa3iYKhnUalEZWLUG3crlZS6O7W3xE590nOM5yOUt1hSwTvcEW01NH
AnozlFixTBLfv4sCMVywCy2r6Xrse7B6XZiGuMXclmMiPDzdy9pCk/Y/WFu6JETU
fezntyCl4bMNOQUkyU5BYR5geL8OumpuVcUebzrrGWhi8+CQ9av/NEOO7SI1bZDv
kZoR8iVDXvH/YQ4tWieFP4VrhoxNvPQmmRWMETlLng8rB6C/sBJ/wO5OpDsjtGew
Di+8GqShbvWMAiHs9We89rNInoFMBlfz2PHQWoUTEvoEtwVbKsI=
=p2HN
-----END PGP SIGNATURE-----

Attachment: pgp8UMscgWAKS.pgp
Description: PGP signature


--- End Message ---

Reply via email to