Bug#1021130: bullseye-pu: package tinyexr/1.0.1+dfsg-1+deb11u1

2022-10-14 Thread Timo Röhling
* Adam D. Barratt [2022-10-14 13:04]: Assuming the diff would be similar to that initially proposed, you can simply prepare and upload 1.0.0+dfsg-1+deb11u1 and we can sort things out from there. It is, so I uploaded the correct version now. Sorry for the screw-up, I should have noticed that

Bug#1021130: bullseye-pu: package tinyexr/1.0.1+dfsg-1+deb11u1

2022-10-14 Thread Timo Röhling
* Adam D. Barratt [2022-10-14 12:53]: On Fri, 2022-10-14 at 11:53 +0100, Adam D. Barratt wrote: Control: tags -1 + confirmed On Sun, 2022-10-02 at 19:38 +0200, Timo Röhling wrote: > The update fixes two vulnerabilities with low priority, i.e. > the security team has decided not to issue a

Bug#1021130: bullseye-pu: package tinyexr/1.0.1+dfsg-1+deb11u1

2022-10-14 Thread Adam D. Barratt
On Fri, 2022-10-14 at 13:58 +0200, Timo Röhling wrote: > * Adam D. Barratt [2022-10-14 12:53]: > > On Fri, 2022-10-14 at 11:53 +0100, Adam D. Barratt wrote: > > > Control: tags -1 + confirmed > > > > > > On Sun, 2022-10-02 at 19:38 +0200, Timo Röhling wrote: > > > > The update fixes two

Bug#1021130: bullseye-pu: package tinyexr/1.0.1+dfsg-1+deb11u1

2022-10-14 Thread Adam D. Barratt
On Fri, 2022-10-14 at 11:53 +0100, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Sun, 2022-10-02 at 19:38 +0200, Timo Röhling wrote: > > The update fixes two vulnerabilities with low priority, i.e. > > the security team has decided not to issue a DSA. > > > > [ Impact ] > >

Bug#1021130: bullseye-pu: package tinyexr/1.0.1+dfsg-1+deb11u1

2022-10-14 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-10-02 at 19:38 +0200, Timo Röhling wrote: > The update fixes two vulnerabilities with low priority, i.e. > the security team has decided not to issue a DSA. > > [ Impact ] > CVE-2022-34300: Heap overflow in DecodePixelData > CVE-2022-38529: Heap overflow

Bug#1021130: bullseye-pu: package tinyexr/1.0.1+dfsg-1+deb11u1

2022-10-02 Thread Timo Röhling
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Dear release team, I'd like to update tinyexr in bullseye [ Reason ] The update fixes two vulnerabilities with low priority, i.e.