libde265 (1.0.9-1.1) unstable; urgency=medium
authorTobias Frost <tobi@debian.org>
Sun, 22 Jan 2023 12:19:20 +0000 (12:19 +0000)
committerTobias Frost <tobi@debian.org>
Sun, 22 Jan 2023 12:19:20 +0000 (12:19 +0000)
commit8de36a60071847d105281812acd67c13490ce325
tree3f0d36eba8c6dece427bb57d1cf3a832d0c8263f
parent83e36e47bcfc6f6e08a46130ce577eb28fe359fb
parent300154808409ba136d3a07d6459991df5caf2113
libde265 (1.0.9-1.1) unstable; urgency=medium

  * Non-maintainer upload.
  * Apply patches to mitigate asan failures:
    reject_reference_pics_from_different_sps.patch and
    use_sps_from_the_image.patch.
  * Combined, this two patches fixes:
    - CVE-2022-43243, CVE-2022-43248, CVE-2022-43253 (Closes: #1025816)
    - CVE-2022-43235, CVE-2022-43236, CVE-2022-43237, CVE-2022-43238,
      CVE-2022-43239, CVE-2022-43240, CVE-2022-43241, CVE-2022-43242,
      CVE-2022-43244, CVE-2022-43250, CVE-2022-43252 (Closes: #1027179)
    - CVE-2022-47655
  * Additional patch recycle_sps_if_possible.patch to avoid over-rejecting
    valid video streams due to reject_reference_pics_from_different_sps.patch.
  * Modifying past changelog entries to indicate when vulnerabilities were
    fixed:
    - In 1.0.9-1, in total 11 CVE's. see #1004963 and #1014999
    - In 1.0.3-1, 1 CVE, see #1029396
  * drop unused Build-Depends: libjpeg-dev, libpng-dev and libxv-dev
    (Closes: #981260)

[dgit import unpatched libde265 1.0.9-1.1]
22 files changed:
debian/.gitlab-ci.yml
debian/changelog
debian/control
debian/copyright
debian/gbp.conf
debian/libde265-0.install
debian/libde265-0.symbols
debian/libde265-dev.docs
debian/libde265-dev.install
debian/libde265-examples.install
debian/not-installed
debian/patches/disable_tools.patch
debian/patches/m4-visibility.patch
debian/patches/only_export_decoder_api.patch
debian/patches/recycle_sps_if_possible.patch
debian/patches/reject_reference_pics_from_different_sps.patch
debian/patches/series
debian/patches/use_sps_from_the_image.patch
debian/rules
debian/source/format
debian/upstream/metadata
debian/watch