Bug#788064: wheezy-pu: package gamera/3.3.3-2
Control: tags -1 + pending
On Sun, 2015-06-21 at 12:08 +0200, Daniel Stender wrote:
> On 20.06.2015 21:40, Adam D. Barratt wrote:
> > Control: tags -1 + confirmed
> >
> > On Mon, 2015-06-08 at 11:07 +0200, Daniel Stender wrote:
> >> I propose an update of gamera in wheezy, 3.3.3-2+deb7u1.
> >>
> >> The new patch is a fix of CVE-2014-1937 [1].
> >>
> >> Please see the attached debdiff for details.
> >
> > diff -Nru gamera-3.3.3/debian/changelog gamera-3.3.3/debian/changelog
> > --- gamera-3.3.3/debian/changelog 2015-06-07 10:02:47.000000000 +0200
> > +++ gamera-3.3.3/debian/changelog 2012-07-04 16:50:40.000000000 +0200
> > @@ -1,10 +1,3 @@
> > -gamera (3.3.3-2+deb7u1) oldstable; urgency=medium
> > -
> > - * add avoid_mktexmp.diff to fix CVE-2014-1937 (related bug #737324
> > - was closed in Sid by 3.4.1-1).
> >
> > I assume you're actually proposing the reverse of that. :-)
[...]
> gamera_3.3.3-2+deb7u1_amd64.changes ACCEPTED into oldstable-proposed-updates->oldstable-new
Flagged for acceptance.
One thing I unfortunately didn't spot originally was the typo of
"mktemp" in the changelog. That's not worth a re-upload at this point
but could be included if a +deb7u2 is ever needed.
Regards,
Adam
Reply to: