fontforge (1:20230101~dfsg-1.1) unstable; urgency=high
authorAdrian Bunk <bunk@debian.org>
Thu, 7 Mar 2024 23:15:58 +0000 (01:15 +0200)
committerAdrian Bunk <bunk@debian.org>
Thu, 7 Mar 2024 23:15:58 +0000 (01:15 +0200)
commit889b6b49d54a3a7dfb7f43282717e9eeba9038a5
tree90d5956182d8ad306d7967696b6f73e616093a78
parentb94d02380e792a6886d952461e8e7a338fbbd862
parent80c95bdfdcee7a9ec6c1cbbff05fb9151ffc61c3
fontforge (1:20230101~dfsg-1.1) unstable; urgency=high

  * Non-maintainer upload.
  * CVE-2024-25081: Spline Font command injection via crafted filenames
  * CVE-2024-25082: Spline Font command injection via crafted archives
    or compressed files
  * Closes: #1064967

[dgit import unpatched fontforge 1:20230101~dfsg-1.1]
35 files changed:
debian/README.source
debian/changelog
debian/clean
debian/control
debian/copyright
debian/copyright-check
debian/copyright_hints
debian/fontforge-common.install
debian/fontforge-common.manpages
debian/fontforge-doc.doc-base
debian/fontforge-doc.install
debian/fontforge-doc.links
debian/fontforge-doc.lintian-overrides
debian/fontforge-extras.install
debian/fontforge-extras.manpages
debian/fontforge-nox.install
debian/fontforge.install
debian/gbp.conf
debian/libfontforge4.install
debian/libfontforge4.lintian-overrides
debian/not-installed
debian/patches/0001-fix-splinefont-shell-command-injection-5367.patch
debian/patches/0002-remove-custom-library-search-path.patch
debian/patches/0003-use-local-libjs-mathjax.patch
debian/patches/2003_avoid_privacy_breach.patch
debian/patches/2004-fix-privacy-breach-logo.patch
debian/patches/series
debian/python3-fontforge.install
debian/python3-fontforge.lintian-overrides
debian/rules
debian/salsa-ci.yml
debian/source/format
debian/source/lintian-overrides
debian/upstream/metadata
debian/watch