qtbase-opensource-src (5.15.2+dfsg-9+deb11u1) bullseye; urgency=medium
authorThorsten Alteholz <debian@alteholz.de>
Sun, 28 Apr 2024 20:48:02 +0000 (22:48 +0200)
committerThorsten Alteholz <debian@alteholz.de>
Sun, 28 Apr 2024 20:48:02 +0000 (22:48 +0200)
commitabc6dd42a208d33bac9a0b16747706ab26f3e830
treef0b67a8d8463ea2faa47543e9086f24ffd32e523
parent18b5d1c7605a108d3f96f69a652ed139c244016c
parent9d07e211b939a5f79239daa5e133b585ce545b3c
qtbase-opensource-src (5.15.2+dfsg-9+deb11u1) bullseye; urgency=medium

  * Non-maintainer upload by the LTS Team.
  * CVE-2024-25580 (Closes: #1064053)
    fix buffer overflow due to crafted KTX image file
  * CVE-2023-32763 (Closes: #1036702)
    fix QTextLayout buffer overflow due to crafted SVG file
  * CVE-2022-25255
    prevent QProcess from execution of a binary from the current working
    directory when not found in the PATH
  * CVE-2023-24607 (Closes: #1031872)
    fix denial of service via a crafted string when the SQL ODBC driver
    plugin is used
  * fix regression caused by patch for CVE-2023-24607
  * CVE-2023-32762
    prevent incorrect parsing of the strict-transport-security (HSTS) header
  * CVE-2023-51714 (Closes: #1060694)
    fix incorrect HPack integer overflow check.
  * CVE-2023-38197 (Closes: #1041105)
    fix infinite loop in recursive entity expansion
  * CVE-2023-37369 (Closes: #1059302)
    fix crash of application in QXmlStreamReader due to crafted XML string
  * CVE-2023-34410 (Closes: #1037210)
    fix checking during TLS whether root of the chain really is a
    configured CA certificate
  * CVE-2023-33285 (Closes: #1036848)
    fix buffer overflow in QDnsLookup

[dgit import unpatched qtbase-opensource-src 5.15.2+dfsg-9+deb11u1]
119 files changed:
debian/README.source
debian/changelog
debian/control
debian/copyright
debian/generateTLDs.sh
debian/libqt5concurrent5.install
debian/libqt5concurrent5.lintian-overrides
debian/libqt5concurrent5.symbols
debian/libqt5core5a.install
debian/libqt5core5a.links
debian/libqt5core5a.lintian-overrides
debian/libqt5core5a.maintscript
debian/libqt5core5a.postinst
debian/libqt5core5a.symbols
debian/libqt5dbus5.install
debian/libqt5dbus5.lintian-overrides
debian/libqt5dbus5.symbols
debian/libqt5gui5.install
debian/libqt5gui5.lintian-overrides
debian/libqt5gui5.maintscript
debian/libqt5gui5.symbols
debian/libqt5network5.install
debian/libqt5network5.lintian-overrides
debian/libqt5network5.symbols
debian/libqt5opengl5-dev.install
debian/libqt5opengl5.install
debian/libqt5opengl5.lintian-overrides
debian/libqt5opengl5.symbols
debian/libqt5printsupport5.install
debian/libqt5printsupport5.lintian-overrides
debian/libqt5printsupport5.symbols
debian/libqt5sql5-ibase.install
debian/libqt5sql5-mysql.install
debian/libqt5sql5-odbc.install
debian/libqt5sql5-psql.install
debian/libqt5sql5-sqlite.install
debian/libqt5sql5-tds.install
debian/libqt5sql5.install
debian/libqt5sql5.lintian-overrides
debian/libqt5sql5.symbols
debian/libqt5test5.install
debian/libqt5test5.lintian-overrides
debian/libqt5test5.symbols
debian/libqt5widgets5.install
debian/libqt5widgets5.lintian-overrides
debian/libqt5widgets5.symbols
debian/libqt5xml5.install
debian/libqt5xml5.lintian-overrides
debian/libqt5xml5.symbols
debian/manpages/moc-qt5.1
debian/manpages/qmake-qt5.1
debian/patches/CVE-2022-25255.diff
debian/patches/CVE-2023-24607.diff
debian/patches/CVE-2023-32762.diff
debian/patches/CVE-2023-32763.diff
debian/patches/CVE-2023-33285.diff
debian/patches/CVE-2023-34410.diff
debian/patches/CVE-2023-37369.diff
debian/patches/CVE-2023-38197.diff
debian/patches/CVE-2023-51714.diff
debian/patches/CVE-2024-25580.diff
debian/patches/armv4.diff
debian/patches/cross_build_mysql.diff
debian/patches/fix-invalid-pointer-return-with-QGridLayout.diff
debian/patches/gcc_11_limits.diff
debian/patches/gnukfreebsd.diff
debian/patches/gnukfreebsd_linker_warnings.diff
debian/patches/link_fbclient.diff
debian/patches/mime_globs.diff
debian/patches/no_htmlinfo_example.diff
debian/patches/nonlinux_utime.diff
debian/patches/path_max.diff
debian/patches/qdoc_default_incdirs.diff
debian/patches/qiodevice_readline_memory.diff
debian/patches/qnam_connect_memory_leak.diff
debian/patches/qstorageinfo_linux.diff
debian/patches/remove_privacy_breaches.diff
debian/patches/series
debian/patches/sql_odbc_fix_unicode_check.diff
debian/patches/sql_odbc_more_unicode_checks.diff
debian/patches/xcb_screens_uaf.patch
debian/qmake-cross-wrapper.in
debian/qt.conf.in
debian/qt5-gtk-platformtheme.install
debian/qt5-qmake-bin.install
debian/qt5-qmake-bin.manpages
debian/qt5-qmake.install
debian/qt5-qmake.links
debian/qt5-xdgdesktopportal-platformtheme.install
debian/qtbase5-dev-tools.install
debian/qtbase5-dev-tools.manpages
debian/qtbase5-dev.install
debian/qtbase5-dev.links
debian/qtbase5-doc-dev.install
debian/qtbase5-doc-html.doc-base.qmake
debian/qtbase5-doc-html.doc-base.qtconcurrent
debian/qtbase5-doc-html.doc-base.qtcore
debian/qtbase5-doc-html.doc-base.qtdbus
debian/qtbase5-doc-html.doc-base.qtgui
debian/qtbase5-doc-html.doc-base.qtnetwork
debian/qtbase5-doc-html.doc-base.qtopengl
debian/qtbase5-doc-html.doc-base.qtplatformheaders
debian/qtbase5-doc-html.doc-base.qtprintsupport
debian/qtbase5-doc-html.doc-base.qtsql
debian/qtbase5-doc-html.doc-base.qttest
debian/qtbase5-doc-html.doc-base.qtwidgets
debian/qtbase5-doc-html.doc-base.qtxml
debian/qtbase5-doc-html.install
debian/qtbase5-doc-html.links
debian/qtbase5-doc.install
debian/qtbase5-examples.install
debian/qtbase5-examples.lintian-overrides
debian/qtbase5-private-dev.install
debian/quiltrc
debian/rules
debian/scripts/update-copyright
debian/source/format
debian/upstreamignore
debian/watch