Merge version 1:7.0.4-4+rpi1 and 1:7.0.4-4+deb11u1 to produce 1:7.0.4-4+rpi1+deb11u1 archive/raspbian/1%7.0.4-4+rpi1+deb11u1 raspbian/1%7.0.4-4+rpi1+deb11u1
authorRaspbian automatic forward porter <root@raspbian.org>
Thu, 21 Oct 2021 04:23:28 +0000 (05:23 +0100)
committerRaspbian automatic forward porter <root@raspbian.org>
Thu, 21 Oct 2021 04:23:28 +0000 (05:23 +0100)
1  2 
debian/changelog

index 8cc5d44abb54c7b680efb338d6f19d85154fb1a0,bdd1d14907f1da0ed0f39ce7ecba954c842dd193..83e35ca89589daa05162a25d679a0670a22d0527
@@@ -1,12 -1,17 +1,27 @@@
- libreoffice (1:7.0.4-4+rpi1) bullseye-staging; urgency=medium
++libreoffice (1:7.0.4-4+rpi1+deb11u1) bullseye-staging; urgency=medium
 +
 +  [changes brought forward from 1:6.0.2-1+rpi2 by Peter Michael Green <plugwash@raspbian.org> at Fri, 27 Apr 2018 02:14:18 +0000]
 +  * Disable testsuite.
 +
 +  [changes introduced in 1:5.4.0-1+rpi1 by Peter Michael Green]
 +  * Disable pdfium, it fails to build for armv6
 +
-  -- Raspbian forward porter <root@raspbian.org>  Thu, 27 May 2021 20:37:32 +0000
++ -- Raspbian forward porter <root@raspbian.org>  Thu, 21 Oct 2021 04:23:26 +0000
++
+ libreoffice (1:7.0.4-4+deb11u1) bullseye-security; urgency=high
+   * backport fixes from libreoffice-7-0 branch:
+     - xmlsecurity-replace-XSecParser-implementation.diff 
+     - xmlsecurity-improve-handling-of-multiple-X509Data-elements.diff: 
+     (fixes CVE-2021-25633 "Double Certificate Attack")
+     - xmlsecurity-XSecParser-confused-about-multiple-timestamps.diff,
+       xmlsecurity-ignore-elements-in-ds:Object-that-arent-signed.diff: 
+     (fixes CVE-2021-25634 "Timestamp Manipulation with Signature Wrapping")
+     - default-to-CertificateValidity::INVALID.diff:
+     (fixes CVE-2021-25635 "Content Manipulation with Certificate Validation
+      Attack")
+  -- Rene Engelhard <rene@debian.org>  Sun, 10 Oct 2021 12:37:28 +0200
  
  libreoffice (1:7.0.4-4) unstable; urgency=medium