-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 22 Aug 2026 22:43:46 +0200
Source: libdbi-perl
Architecture: source
Version: 1.652-2~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Perl Group <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 1141667 1142072 1144470 1144471 1144851
Changes:
 libdbi-perl (1.652-2~deb13u1) trixie-security; urgency=high
 .
   * Team upload.
   * Rebuild for trixie-security
   * Revert "Remove «Priority: optional», which is the current default."
   * Revert "Remove «Rules-Requires-Root: no», which is the current default."
   * Revert "Declare compliance with Debian Policy 4.7.4."
   * Revert "Reformat debian/control."
 .
 libdbi-perl (1.652-2) unstable; urgency=medium
 .
   * Add patch from upstream Git to fix 32bit test failure.
     Thanks to Adrian Bunk for the bug report. (Closes: #1144851)
 .
 libdbi-perl (1.652-1) unstable; urgency=medium
 .
   * Import upstream version 1.652.
     + Limit statements to 292 Mb in preparse (CVE-2026-73193)
       (Closes: #1144470)
     + Force placeholder limit on :# and :p# too (CVE-2026-73194)
       (Closes: #1144471)
   * Install new SECURITY.md file.
   * Refresh t__40profile.t__NTP.patch (offset).
 .
 libdbi-perl (1.651-1) unstable; urgency=medium
 .
   * Import upstream version 1.651.
     - Fix inverted comparisons for strings in DBI::SQL::Nano
       (CVE-2026-15043)
     - Fix DBD::File to ensure that the table is not a symlink outside of f_dir
       (CVE-2026-15392)
     - Fix an out-of-bounds error when a statement handle has no fields but the
       source row is not empty (CVE-2026-60082)
     - Add an overridable upper bound $MAX_PATH_DEPTH for DBI::ProfileData
       (CVE-2026-60081)
     Closes: #1142072
 .
 libdbi-perl (1.650-1) unstable; urgency=medium
 .
   * Import upstream version 1.650.
     - Set a hard limit of 99999 on '?' placeholders
       (CVE-2026-14739)
     - Fix out-of-bounds read in preparse of SQL that starts with a comment
       (CVE-2026-14740)
     - Fix code injection via Profile DSN attribute or DBI_PROFILE variable
       (CVE-2026-14380)
     Closes: #1141667
   * Install new upstream document.
 .
 libdbi-perl (1.649-1) unstable; urgency=medium
 .
   * Import upstream version 1.649.
 .
 libdbi-perl (1.648-1) unstable; urgency=medium
 .
   * Import upstream version 1.648.
     Fixes CVE-2026-9698 and CVE-2026-10879.
   * Update years of upstream and packaging copyright.
   * Declare compliance with Debian Policy 4.7.4.
   * Remove «Rules-Requires-Root: no», which is the current default.
   * Remove «Priority: optional», which is the current default.
Checksums-Sha1: 
 e84a20877081f9a4158d67ef2b30ee72751105e0 2373 libdbi-perl_1.652-2~deb13u1.dsc
 5fc073e859390f07b06ddd0a26020ef52d02e78e 734177 libdbi-perl_1.652.orig.tar.gz
 45c0c4a18716c4de2562d7f643e7a3c69e2f3333 15296 
libdbi-perl_1.652-2~deb13u1.debian.tar.xz
Checksums-Sha256: 
 9820de2e2b5767d80492b7dba575ed8df10edfa71bce3a04b35fdf41a20822ce 2373 
libdbi-perl_1.652-2~deb13u1.dsc
 e7981833696d15414bb76c43817d48f9fc3879e1421433116374fbc63e8e78ad 734177 
libdbi-perl_1.652.orig.tar.gz
 3f344c1491c4435e60ec6bc678655c52f34ccc41f3d6813d076b9d128a92f4f6 15296 
libdbi-perl_1.652-2~deb13u1.debian.tar.xz
Files: 
 1b5efbf7f19090e721285a56c15446df 2373 perl optional 
libdbi-perl_1.652-2~deb13u1.dsc
 0d511887cb8b8d2a86c5ef78395b0438 734177 perl optional 
libdbi-perl_1.652.orig.tar.gz
 2076444e9f06e4253a2ac5319207092a 15296 perl optional 
libdbi-perl_1.652-2~deb13u1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmqK4yhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89ExQsP/3v9e8Ao38M6fr2xECDCeZ31cQVkBPk+
v/aYS3fAdS04QBVDiEWkYSh96+pfEUm2Dq6Ha28DnoAxnyNBo182pYZXA6ToilD/
iFMCY7oZSR+1AekbCstbzHMtkvI42BEAzOeO7NEUsNSjoYdIBfiO/crCObxlemAK
xEKp2yIxBgPrlLwxzajBv+EE4rgD8z+ZWQAWnI+fG86B9jbocAP6Wp/oaH65+cj+
hYgZOadv9HhZdOu8rbAujI2kEJn/w35AUcGd5JH4b2dUv61hJab6AZ8QMDme4qlv
DlShVfgRw89SqTeLiEDOkUKPQHxWVVxUI98m9eH1YCRB1NxTSxB1DP1re+fl6Nlm
4/NKP02V9tpzgUeTTRWtTaPm4Kv8SSMfs61oE4Azj3TjIGdr6cfvYWBwyqJKk2+U
rhtEM2fi2EUKhobMyfI24G3VFp3nzWCAojWxQZbi6JuFSY5a2fOpEzO5UhEcfevK
aDPUwIsbRvfYr83EGyceppvQCTIle7HT298jh1eCDjnszC7Pbw1oa0k6dVgaE+4U
kifJDuj8bYu3dM/+qVMlnfDaVokQjeOQ+FSeUE32B6GCs58dstoqHGjawWPVTUn8
DtRZgCuXS9oyXLSHyOl117aWn3OTlwa0uWuhw9ZTt2fmL0EAOvmZOJ7hgPYKfRvz
SbGu2jKWe9fx
=wnr0
-----END PGP SIGNATURE-----

Attachment: pgpnvU7ugbqB9.pgp
Description: PGP signature

Reply via email to