Commits on Source (2)
-
Salvatore Bonaccorso authored
Previously https://cgit.freedesktop.org/poppler/poppler/commit/?id=a3a98a6d83dfbf49f565f5aa2d7c07153a7f62fc was referenced but is now invalid commit for the cgit faced instance. The change is covered by the two commits https://gitlab.freedesktop.org/poppler/poppler/commit/55db66c69fd56826b8523710046deab1a8d14ba2 https://gitlab.freedesktop.org/poppler/poppler/commit/22c4701d5f7be0010ee4519daa546fba5ab7ac13
-
Salvatore Bonaccorso authored
Both might be considered duplicates for CVE-2017-9776 or really meant to be associated only for src:xpdf (in later case then the source package xpdf just marked affected but unimportant as the poppler library is used from the system). For now, until clarfied what to do with CVE-2019-14288 and CVE-2019-14289 track the fix for src:poppler for every suite which had the fix. Note for stretch we mark it with the version from DSA-4079-2 as the patch in DSA-4079-1 was broken and required a followup update.