I adjusted your changelog entry to include the remaining differences in
the changelog message. I think that makes things more clear to the next
person who will work on merging new versions.

I did a second upload because we accidentally missed the symbols file
update when we manually merged later.

I am unsubscribing ubuntu-sponsors now because I have uploaded this to
Ubuntu. Feel free to resubscribe if you have something else that needs
to be sponsored.

I saw that you opened a Debian bug for the security patch. Could you
forward the patch there too?


** Changed in: tiff (Ubuntu)
       Status: In Progress => Fix Committed

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to tiff in Ubuntu.
https://bugs.launchpad.net/bugs/1997278

Title:
  Merge tiff 4.4.0-5 (main) from Debian unstable (main)

Status in tiff package in Ubuntu:
  Fix Committed

Bug description:
  Please merge tiff 4.4.0-5 (main) from Debian unstable (main)

  Changelog entries since current kinetic version 4.4.0-4ubuntu3:

  tiff (4.4.0-5) unstable; urgency=high

    * Backport security fix for CVE-2022-3597, CVE-2022-3626 and CVE-2022-3627,
      out of bounds write and denial of service via a crafted TIFF file.
    * Backport security fix for CVE-2022-3570, multiple heap buffer overflows
      via crafted TIFF file.
    * Backport security fix for CVE-2022-3599, denial-of-service via a crafted
      TIFF file.
    * Backport security fix for CVE-2022-3598, denial-of-service via a crafted
      TIFF file (closes: #1022555).

   -- Laszlo Boszormenyi (GCS) <g...@debian.org>  Sun, 23 Oct 2022
  22:38:15 +0200

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/tiff/+bug/1997278/+subscriptions


-- 
Mailing list: https://launchpad.net/~touch-packages
Post to     : touch-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~touch-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to