Merge version 25.03.0-5+rpi1+deb13u2 and 25.03.0-5+deb13u3 to produce 25.03.0-5+rpi1... archive/raspbian/25.03.0-5+rpi1+deb13u3 raspbian/25.03.0-5+rpi1+deb13u3
authorRaspbian automatic forward porter <root@raspbian.org>
Fri, 19 Jun 2026 07:15:30 +0000 (08:15 +0100)
committerRaspbian automatic forward porter <root@raspbian.org>
Fri, 19 Jun 2026 07:15:30 +0000 (08:15 +0100)
1  2 
debian/changelog

index dd0941783d0d4848017921004f9d698f70a235f9,beae67de665f0ee81af5eb6a83b5c47e2d8cb80a..9681462dfdc4e6ec131821ecb092bdc78e7a1e89
@@@ -1,9 -1,13 +1,20 @@@
- poppler (25.03.0-5+rpi1+deb13u2) trixie-staging; urgency=medium
++poppler (25.03.0-5+rpi1+deb13u3) trixie-staging; urgency=medium
 +
 +  [changes brought forward from 24.08.0-2+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Tue, 17 Sep 2024 22:18:17 +0000]
 +  * Update symbols file for raspbian.
 +
-  -- Raspbian forward porter <root@raspbian.org>  Fri, 09 Jan 2026 07:57:24 +0000
++ -- Raspbian forward porter <root@raspbian.org>  Fri, 19 Jun 2026 07:15:30 +0000
++
+ poppler (25.03.0-5+deb13u3) trixie-security; urgency=high
+   * Non-maintainer upload by the Security Team.
+   * SplashOutputDev: Fix integer overflow in tilingPatternFill (CVE-2026-10118)
+     (Closes: #1138708)
+   * Make sure regex doesn't stack overflow by limiting it (CVE-2025-43718)
+     (Closes: #1117046)
+   * Check for duplicate entries (CVE-2025-52885) (Closes: #1117853)
+  -- Salvatore Bonaccorso <carnil@debian.org>  Sat, 06 Jun 2026 11:07:43 +0200
  
  poppler (25.03.0-5+deb13u2) trixie; urgency=high