fontforge (1:20201107~dfsg-4+deb11u1) bullseye-security; urgency=medium
authorAdrian Bunk <bunk@debian.org>
Fri, 15 Mar 2024 20:56:38 +0000 (22:56 +0200)
committerAdrian Bunk <bunk@debian.org>
Fri, 15 Mar 2024 20:56:38 +0000 (22:56 +0200)
commit78e64cbc5a9ff5a61f82853daf240806f8fc4e2a
tree53f891f289cb672516f016309344932758ce5c20
parentd59992ac35ff4e26bee1e0aeb5740d7dc400ea2f
parent492e0ae82e91315c6646a629f979b7be7f19f756
fontforge (1:20201107~dfsg-4+deb11u1) bullseye-security; urgency=medium

  * Non-maintainer upload.
  * CVE-2024-25081: Spline Font command injection via crafted filenames
  * CVE-2024-25082: Spline Font command injection via crafted archives
    or compressed files
  * Closes: #1064967

[dgit import unpatched fontforge 1:20201107~dfsg-4+deb11u1]
37 files changed:
debian/README.source
debian/changelog
debian/clean
debian/control
debian/copyright
debian/copyright-check
debian/copyright_hints
debian/fontforge-common.install
debian/fontforge-common.manpages
debian/fontforge-doc.doc-base
debian/fontforge-doc.install
debian/fontforge-doc.links
debian/fontforge-extras.install
debian/fontforge-extras.manpages
debian/fontforge-nox.install
debian/fontforge.install
debian/gbp.conf
debian/libfontforge4.install
debian/libfontforge4.lintian-overrides
debian/not-installed
debian/patches/0001-add-extra-cmake-install-rules.patch
debian/patches/0001-fix-splinefont-shell-command-injection-5367.patch
debian/patches/0002-remove-custom-library-search-path.patch
debian/patches/0003-use-local-libjs-mathjax.patch
debian/patches/0004-hurd-PATH_MAX-and-MAXPATHLEN.patch
debian/patches/0005-hurd-rename-extended-to-avoid-conflict-with-gnumach-dev.patch
debian/patches/2003_avoid_privacy_breach.patch
debian/patches/2004-fix-privacy-breach-logo.patch
debian/patches/series
debian/python3-fontforge.install
debian/python3-fontforge.lintian-overrides
debian/rules
debian/salsa-ci.yml
debian/source/format
debian/source/lintian-overrides
debian/upstream/metadata
debian/watch