[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#945831: RFS: libonig/6.9.4-1 --



Hello Adam,

Am Freitag, den 29.11.2019, 19:03 +0100 schrieb Adam Borowski:
> Hi!
> 
> On Fri, Nov 29, 2019 at 02:16:34PM +0100, Jörg Frings-Fürst wrote:
> >    Package name    : libonig
> >    Version         : 6.9.4-1
> > Changes since the last upload:
> > 
> >    * Neu upstream release.
> >      - Refresh symbols file and add Build-Depends-Package field.
> >      - Remove upstream applied patches:
> >        + 0105-CVE-2019-13224.patch
> >        + 0110-CVE-2019-13225.patch
> >      - Refresh debain/copyright.
> >      - Fixes CVE-2019-19204: heap-buffer-overflow in
> > fetch_interval_quantifier
> >          due to double PFETCH (Closes: #945313).
> >      - Fixes CVE-2019-19203: heap-buffer-overflow in
> > gb18030_mbc_enc_len
> >          (Closes: #945312).
> >      - Fixes CVE-2019-19012: Out of bounds read in mbc_to_code()
> >          (Closes: #944959).
> >      - Fixes CVE-2019-16163: Stack Exhaustion Problem (Closes:
> > #939988).
> >      - Fixes CVE-2019-19246: heap-based buffer over-read in
> > str_lower_case_match.
> >    * debian/watch:_Correct typo.
> >    * Declare compliance with Debian Policy 4.4.1.1 (No changes
> > needed).
> >    * Switch to debhelper-compat:
> >      - debian/control: change to debhelper-compat (=12)
> >      - remove debian/compat
> >    * debian/control:
> >      - Add Rules-Requires-Root: binary-targets.
> 
> Is there a reason for binary-targets?  None of the binary packages
> ship any
> files with non-standard owner, and I don't see anything else that
> would
> require fakeroot.  Also, I've tried building the package with R³: no,
> and it
> seems to build ok.  Am I missing something?
> 

Thanks for your review.

I have change Rules-Requires-Root to no.

Uploaded to mentors ans into git.


> 
> Meow!

CU
Jörg
-- 
New:
GPG Fingerprint: 63E0 075F C8D4 3ABB 35AB  30EE 09F8 9F3C 8CA1 D25D
GPG key (long) : 09F89F3C8CA1D25D
GPG Key        : 8CA1D25D
CAcert Key S/N : 0E:D4:56

Old pgp Key: BE581B6E (revoked since 2014-12-31).

Jörg Frings-Fürst
D-54470 Lieser


git:      https://jff.email/cgit/

Threema:  SYR8SJXB
Wire:     @joergfringsfuerst
Skype:    joergpenguin
Ring:     jff
Telegram: @joergfringsfuerst


My wish list: 
 - Please send me a picture from the nature at your home.

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: