Merge version 1.0.11-0+deb10u5+rpi1 and 1.0.11-0+deb10u6 to produce 1.0.11-0+deb10u6... buster-staging archive/raspbian/1.0.11-0+deb10u6+rpi1 raspbian/1.0.11-0+deb10u6+rpi1
authorRaspbian automatic forward porter <root@raspbian.org>
Thu, 4 Jan 2024 22:53:15 +0000 (22:53 +0000)
committerRaspbian automatic forward porter <root@raspbian.org>
Thu, 4 Jan 2024 22:53:15 +0000 (22:53 +0000)
1  2 
debian/changelog
debian/patches/series

index a2c351256c5129ec44652428d909e710a40063fa,08bac600ebd52ffd094b9d567f5f43dcd377d674..40967aebe3d6d901d2f6ac2a37b3d72d1c3aef3e
@@@ -1,9 -1,14 +1,21 @@@
- libde265 (1.0.11-0+deb10u5+rpi1) buster-staging; urgency=medium
++libde265 (1.0.11-0+deb10u6+rpi1) buster-staging; urgency=medium
 +
 +  [changes brought forward from 1.0.2-1+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Sun, 04 Oct 2015 21:44:10 +0000]
 +  * Disable neon.
 +
-  -- Raspbian forward porter <root@raspbian.org>  Fri, 01 Dec 2023 04:27:57 +0000
++ -- Raspbian forward porter <root@raspbian.org>  Thu, 04 Jan 2024 22:53:14 +0000
++
+ libde265 (1.0.11-0+deb10u6) buster-security; urgency=high
+   * Non-maintainer upload by the LTS Team.
+   * CVE-2023-49465
+     heap-buffer-overflow in derive_spatial_luma_vector_prediction()
+   * CVE-2023-49467
+     heap-buffer-overflow in derive_combined_bipredictive_merging_candidates()
+   * CVE-2023-49468
+     global buffer overflow in read_coding_unit()
+  -- Thorsten Alteholz <debian@alteholz.de>  Fri, 29 Dec 2023 23:03:02 +0100
  
  libde265 (1.0.11-0+deb10u5) buster-security; urgency=medium
  
index 6a0e03015d2e3593ce87f1bccb64e77728d41382,7fc88c4758c61ddd6987b8337faff22b211cdfa3..40e275b32687f59594d5338c70edb2f2096d38d9
@@@ -7,4 -7,8 +7,8 @@@ CVE-2023-27102.patc
  CVE-2023-27103.patch
  CVE-2023-43887.patch
  CVE-2023-47471.patch
 -
+ CVE-2023-49465.patch
+ CVE-2023-49467.patch
+ CVE-2023-49468.patch
 +disable-neon.patch