[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1032076: marked as done (libass: upstream bugfix release 0.17.1)



Your message dated Wed, 01 Mar 2023 23:02:04 +0000
with message-id <E1pXVSW-00021W-7P@fasolo.debian.org>
and subject line Bug#1032076: fixed in libass 1:0.17.1-1
has caused the Debian Bug report #1032076,
regarding libass: upstream bugfix release 0.17.1
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1032076: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1032076
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Source: libass
Version: 1:0.16.0-1
Severity: normal

Hi,

a buffer overread bug affecting 0.17.0 and 0.16.0 was discovered
and we released a new bug-fix-only release 0.17.1 to address it.

  https://github.com/libass/libass/releases/tag/0.17.1

It appears as if no Debian distribution currently includes 0.16.0
(anymore), but 0.17.0 ofc is.

I’m aware the Bookworm freeze started already and apologise for
additional trouble this might cause. But given this upstream release
itself is a small, targeted fix for 0.17.0 and it resolves a memory bug,
I believe it is both suitable and advisable to include 0.17.1 in Bookworm.
(Or bookworm-security if that’s more appropiate.)

Not including the release commit itself, the difference to 0.17.0
are only two bugfix commits changing but a couple lines of code.
One of those commits fixing the aforementioned memory bug, the other a
configuration failure on GNU Hurd if ASM is not disabled (ref. #1027750).

Cheers

Oneric

Attachment: signature.asc
Description: PGP signature


--- End Message ---
--- Begin Message ---
Source: libass
Source-Version: 1:0.17.1-1
Done: Sebastian Ramacher <sramacher@debian.org>

We believe that the bug you reported is fixed in the latest version of
libass, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1032076@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sebastian Ramacher <sramacher@debian.org> (supplier of updated libass package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 01 Mar 2023 23:41:21 +0100
Source: libass
Architecture: source
Version: 1:0.17.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Multimedia Maintainers <debian-multimedia@lists.debian.org>
Changed-By: Sebastian Ramacher <sramacher@debian.org>
Closes: 1027750 1032076
Changes:
 libass (1:0.17.1-1) unstable; urgency=medium
 .
   * New upstream version 0.17.1 (Closes: #1032076)
     - Fix assembly on hurd-i386 (Closes: #1027750)
Checksums-Sha1:
 79e56a626614dafb2da3e8efd340494f0b1b798b 2353 libass_0.17.1-1.dsc
 ae942a675f808b6a0d0b10bd38e8dc6bf669a716 546658 libass_0.17.1.orig.tar.gz
 c5eba29aff5fca33f76ab831f713a59857b2902d 228 libass_0.17.1.orig.tar.gz.asc
 fe12667c4f0461c0eacf422a01551773deb44826 15656 libass_0.17.1-1.debian.tar.xz
Checksums-Sha256:
 0e2eb1006f5fc9ecbec4cea66cad9047dd12b6fb9fae20394de0eb80b2de365f 2353 libass_0.17.1-1.dsc
 d653be97198a0543c69111122173c41a99e0b91426f9e17f06a858982c2fb03d 546658 libass_0.17.1.orig.tar.gz
 699d1ba876d7bac95dbac56bac0f00126473e8588759a4ec13cdf52ae03d8483 228 libass_0.17.1.orig.tar.gz.asc
 277581e18b2ee091f338f81d1645da5bf774097e0d1ba669dee8556992ea5869 15656 libass_0.17.1-1.debian.tar.xz
Files:
 b013bce6ee967b9b5d06b73e124534df 2353 libs optional libass_0.17.1-1.dsc
 3a0e357a4334bd48e58d063624b36303 546658 libs optional libass_0.17.1.orig.tar.gz
 c7c7a9faeb5486a1e5550064858afb83 228 libs optional libass_0.17.1.orig.tar.gz.asc
 0301a18e07570c0f6761a5339e4657f2 15656 libs optional libass_0.17.1-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE94y6B4F7sUmhHTOQafL8UW6nGZMFAmP/1SQACgkQafL8UW6n
GZPN4w/9EihX9QND58HCj0cGbs+9BMY2+1UX2QrzcZnKUsRQZREJYlOhbvOTinwv
Olg8MabsuYEaae5dup1Z/XETFSY7TnThgF1MjdTQE2/+OEDGc1tmNuH5azrbchrD
P9n3vLGxf91xLXI8hljchtjb+rfKcUiIxmhB+mU9IQfnwJzE354zFkZan/6KMR9f
eGbyTwbreQR49Jqgc3unUxsxvhAp54tvBqfhOnMAvU1QDFdhDNvpN3MiH0QSv0lU
cNx6bgbeYK3khLdF5UMlUAQlGd0QDD3GXX8y6vtfEr77A6kxx6aDMV4+D/RLc6v5
3/JlJIK03cOcFnC5/t8hiZSrfDmz2j8qenvrLn1+3GyS2mAyP2FiLjnOlVDnU8ru
BUf7fgUoiCaE2IoJnxvgE4g9Rh7WssgdyoNkjoKK/OkbeV+bVaDHqaxOGPbl95l4
LvShVb5pNoNOMfsqJsUVwOlS0V1Cay2QlmSd6D/Y3eH2kHUuvOnhg8qmsYQURvFx
yhoNhH1GbgbxZRzqvq2taeQ5ktlHJh7Lw8R7kOQLlWqxLqqKRm71r4hW2oJzlp2G
ptJ4Pp9DQn5DpCUb0hZGJPhpI6DULrFr/rAopkegRg/7OZCF8eMiP5gsg1wrFDti
PnphntmfCUZC3g8MESgWVbuh4DSuXVWwM+PQkbDJ9FEqWXjxZgc=
=fYbw
-----END PGP SIGNATURE-----

--- End Message ---

Reply to: