[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#1122926: [Debian-med-packaging] Bug#1123584: Bug#1122926: dcmtk: CVE-2025-14607 and CVE-2025-14841



Hi Mathieu:
> Could you confirm your intention to upload "libdcmtk19" for DCMTK
> 3.7.0 ? I am surprised that there are no ABI changes.

Uugh, so that's what I have forgotten.  :(

libdcmtk19 is aligned to version 3.7.0 by now, but I see the
soversion was actually bumped to 20 upstream:

	$ grep set\(DCMTK_ABI_VERSION CMake/dcmtkPrepare.cmake
	set(DCMTK_ABI_VERSION 20)

Now to:

  * rollback unstable to 3.7.0+really3.6.9 (and close #1127756),
  * upload 3.7.0+really3.7.0 with bumped soname to experimental
    New and coordinate a transition with the Release Team,
  * finally wrap up some guard against future similar
    mishandling; normally dpkg-gensymbols does it alright, but
    there are no symbols files for this one.

Let's see if I can act on one or more points tonight.

Thanks for raising this!
-- 
  .''`.  Étienne Mollier <emollier@debian.org>
 : :' :  pgp: 8f91 b227 c7d6 f2b1 948c  8236 793c f67e 8f0d 11da
 `. `'   sent from /dev/pts/3, please excuse my verbosity
   `-

Attachment: signature.asc
Description: PGP signature


Reply to: