Please merge db5.3 5.3.28+dfsg1-0.8 from Debian unstable

Bug #1927978 reported by Dave Jones
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
db5.3 (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Please merge db5.3 5.3.28+dfsg1-0.8 from Debian unstable.

Updated changelog and diff against Debian unstable to be attached below.

Tags: patch

CVE References

Revision history for this message
Dave Jones (waveform) wrote :

Attaching patch against Debian unstable. Test builds available from the following PPA:

https://launchpad.net/~waveform/+archive/ubuntu/db/+packages

tags: added: patch
Revision history for this message
Lukas Märdian (slyon) wrote :

Thank you, LGTM!

$ dput ubuntu ../db5.3_5.3.28+dfsg1-0.8ubuntu1_source.changes
D: Setting host argument.
Checking signature on .changes
gpg: ../db5.3_5.3.28+dfsg1-0.8ubuntu1_source.changes: Valid signature from 5889C17AB1C8D890
Checking signature on .dsc
gpg: ../db5.3_5.3.28+dfsg1-0.8ubuntu1.dsc: Valid signature from 5889C17AB1C8D890
Uploading to ubuntu (via sftp to upload.ubuntu.com):
  Uploading db5.3_5.3.28+dfsg1-0.8ubuntu1.dsc: done.
  Uploading db5.3_5.3.28+dfsg1-0.8ubuntu1.debian.tar.xz: done.
  Uploading db5.3_5.3.28+dfsg1-0.8ubuntu1_source.buildinfo: done.
  Uploading db5.3_5.3.28+dfsg1-0.8ubuntu1_source.changes: done.
Successfully uploaded packages.

Lukas Märdian (slyon)
Changed in db5.3 (Ubuntu):
status: New → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package db5.3 - 5.3.28+dfsg1-0.8ubuntu1

---------------
db5.3 (5.3.28+dfsg1-0.8ubuntu1) impish; urgency=low

  * Merge from Debian unstable (LP: #1927978). Remaining changes:
    - SECURITY UPDATE: Heap out-of-bounds read
      - debian/patches/CVE-2019-8457.patch: enhance the rtreenode
        function in lang/sql/sqlite/ext/rtree/rtree.c.
      - CVE-2019-8457
  * Removed patches obsoleted/merged by upstream:
    - Fix FTBFS due to multiple definitions of progname, switch one of them
      to glibc provided program_invocation_name.
    - Test-suite sh_list segfaults when db5.3 built with gcc-10, switch to
      gcc-9.
    - Build everything with gcc-9.

 -- Dave Jones <email address hidden> Tue, 23 Mar 2021 15:15:50 +0000

Changed in db5.3 (Ubuntu):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.