[From nobody Sun May 10 11:19:05 2026
Received: (at 1135778-close) by bugs.debian.org; 10 May 2026 10:17:07 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-114.2 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FVGT_m_MULTI_ODD,
 HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,USER_IN_DKIM_WELCOMELIST
 autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 107; hammy, 150; neutral, 126; spammy,
 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz,
 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from muffat.debian.org ([2607:f8f0:614:1::1274:33]:59782)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wM1Df-002bab-2O for 1135778-close@bugs.debian.org;
 Sun, 10 May 2026 10:17:07 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by muffat.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wM1Dg-000zrF-0F for 1135778-close@bugs.debian.org;
 Sun, 10 May 2026 10:17:07 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=rwobhhKgOqWw+JlRg7ykihhJFVDSbBXm0nx5YkdouwE=; b=qKcVWAwnp3Iv8aPj9dKYhuoLqQ
 F8vNybNOe+7yi/qIW3dryb60T+k7tqhHQfPjq4YzfrkIDlMRD6xpczjTS6w+yR/urMYw5n0RmB3kp
 wqZ+POpIvm+xGPh6JVkdy+tgfQfb5c0yAgj0asrA0CqhyIQB2tQZt58aC3aw65lfrqZXhwc4xMMk2
 GiQuNgS7iaoLmZMbTUokVoZxbsvJkQ/A0Hsyw5SMTkLc+O5Yt1Eri4BCxjMBkQzEeF2zSoW+dmjaF
 t67kXElbcq/qOVg/0FePfNxuU387g1rcJEZCXH4/xjMspqFLO62fQYKdiqlAwNqFWrxw9TI9WJCOA
 8NPWPhaQ==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wM1Dd-00000007RvN-47eE; Sun, 10 May 2026 10:17:05 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: Adrian Bunk &lt;bunk@debian.org&gt;
To: 1135778-close@bugs.debian.org
X-DAK: dak process-policy
X-Debian: DAK
X-Debian-Package: cimg
Debian: DAK
Debian-Changes: cimg_3.5.2+dfsg-1+deb13u1_source.changes
Debian-Source: cimg
Debian-Version: 3.5.2+dfsg-1+deb13u1
Debian-Architecture: source
Debian-Suite: proposed-updates
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1135778: fixed in cimg 3.5.2+dfsg-1+deb13u1
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============5347879239666879307==&quot;
Message-Id: &lt;E1wM1Dd-00000007RvN-47eE@fasolo.debian.org&gt;
Date: Sun, 10 May 2026 10:17:05 +0000

--===============5347879239666879307==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: cimg
Source-Version: 3.5.2+dfsg-1+deb13u1
Done: Adrian Bunk &lt;bunk@debian.org&gt;

We believe that the bug you reported is fixed in the latest version of
cimg, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1135778@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Adrian Bunk &lt;bunk@debian.org&gt; (supplier of updated cimg package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 08 May 2026 14:47:35 +0300
Source: cimg
Architecture: source
Version: 3.5.2+dfsg-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Debian Science Maintainers &lt;debian-science-maintainers@lists.alio=
th.debian.org&gt;
Changed-By: Adrian Bunk &lt;bunk@debian.org&gt;
Closes: 1135778
Changes:
 cimg (3.5.2+dfsg-1+deb13u1) trixie; urgency=3Dmedium
 .
   * Non-maintainer upload.
   * CVE-2026-42144: Integer overflow in PNM size check
   * CVE-2026-42146: OOM on crafted BMP
   * (Closes: #1135778)
Checksums-Sha1:
 b6c2644766564ae6245a2b5ed103c5d0fbe2b234 2624 cimg_3.5.2+dfsg-1+deb13u1.dsc
 67cae724ab5d0833bb1676d5bd901b11db6bf511 10677044 cimg_3.5.2+dfsg.orig.tar.xz
 a67dd17810bf8317665cc5302de8daed39e08619 21372 cimg_3.5.2+dfsg-1+deb13u1.deb=
ian.tar.xz
Checksums-Sha256:
 96a4a4cc6d0260c70d1cd4f1aade8ad854bde69a28075892967328f91b713da2 2624 cimg_3=
.5.2+dfsg-1+deb13u1.dsc
 34611e441ce8add59a45a38f81fb2dc1da59ba4edb3f33d6423206c19df97cbb 10677044 ci=
mg_3.5.2+dfsg.orig.tar.xz
 033c3ef73774c27990d54b706a680a8ce09efe51f521fff7e6930f8068508b75 21372 cimg_=
3.5.2+dfsg-1+deb13u1.debian.tar.xz
Files:
 6fd7ae9c11474f019d3635a1dd35b53a 2624 math optional cimg_3.5.2+dfsg-1+deb13u=
1.dsc
 ac01c8e09907de481ba2ba53b6e17416 10677044 math optional cimg_3.5.2+dfsg.orig=
.tar.xz
 3f451fedfef596a5b5db5054699eb359 21372 math optional cimg_3.5.2+dfsg-1+deb13=
u1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmn94V0ACgkQiNJCh6LY
mLHo8hAAtTxFQsK4aL9CI49cW7n+2aO80qTat8oeEuqIzXhJnCE7K1aBRA6bVbZw
bllmEVwk7+7Zkj7ROND6zytPdFPAkgsnk+dhAJhke51AZI/D6G0TTLmipI+1t5oL
Ap/lTY4qdEZMDeUXxx8e7pW6knpXQXD8GXHIRN5gRU/T8V3VxZYW9qgMrFYR8i+n
RRg3b+fSma3zJ2s6lEjALE0yFN88Qwsf87pJsC0B2KAvOKquNndH/VYVRotI2lBl
S7A8ptaqZdRPtWHdvve/Ru6JDhZ5AblTO/zvPl7mW5u/fNPsSvM6EfmkFIrRB2ub
j9msFtyc/fEK1R7fhumC/h0YfKZcyRPmF7EKtJiX7WVj/N+lFJYIrc6QIJS7SwNF
lXlk+FRH49cnp1uGmi+8tqxKPyEEI+C6Ezd+nnUy5UJ5BMUlFV4JJ37UIGhi0b+0
PK2lNCj+kQt3NCYSNnnTRMT3KVwWNC1F00bumLmxcP6dVhEBGp2nK/JWC0SueWSe
UiAhtYJ73LwgT1Ebzd5R7q/VYJd8ZINCJsjQzuWihdOlnxeeSbER5U9HMgKq9q35
l5XcOd6MchyC1vJEjua5OYZkJiadsZ+tsoLxEvQoB7trqc1HmDETmB0dCJEb/uOd
6LLzI+REHAQojA/yB0ZF+jB1q9GeUhJGAD4RywOQGzQNGHHIAW4=3D
=3D7w48
-----END PGP SIGNATURE-----


--===============5347879239666879307==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCagBbIQAKCRCb9qggYcy5
IS1HAP41F6lAXusok/DoKNYnWOESZk+tQGS/XPNx93Ywula8jgEA6rptDfD6Ygh0
Z9db1tHRw4I9mviGK+0kY/Uszs/CxAM=
=FEtt
-----END PGP SIGNATURE-----

--===============5347879239666879307==--
]