librsvg ftbfs in the jammy release pocket
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
librsvg (Ubuntu) |
Fix Released
|
High
|
Sebastien Bacher |
Bug Description
as seen in a test rebuild, this package fails to build in the jammy release pocket (note the log behind the link might go away):
test url_resolver:
failures:
---- transform:
thread 'transform:
---- transform:
thread 'transform:
failures:
transform:
transform:
test result: FAILED. 254 passed; 2 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
error: test failed, to rerun pass '--lib'
make[5]: *** [Makefile:1537: check-local] Error 101
CVE References
tags: | added: ftbfs rls-jj-incoming |
Changed in librsvg (Ubuntu): | |
importance: | Undecided → High |
status: | New → Triaged |
Changed in librsvg (Ubuntu): | |
assignee: | nobody → Sebastien Bacher (seb128) |
tags: | removed: rls-jj-incoming |
This bug was fixed in the package librsvg - 2.52.5+ dfsg-3ubuntu0. 2
--------------- dfsg-3ubuntu0. 2) jammy-security; urgency=medium
librsvg (2.52.5+
* SECURITY UPDATE: Arbitrary file read when xinclude href has special patches/ CVE-2023- 38633.patch: validate URLs in librsvg/ rsvg.h, src/error.rs, src/lib.rs, url_resolver. rs, tests/*.
characters
- debian/
include/
src/
- CVE-2023-38633
* Don't fail the build on tests error for i386 (LP: #1976259)
-- Marc Deslauriers <email address hidden> Fri, 28 Jul 2023 08:55:53 -0400