[From nobody Mon Aug 31 14:49:14 2026
Received: (at 1144851-close) by bugs.debian.org; 31 Aug 2026 13:48:51 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-112.6 required=4.0 tests=BAYES_00,DKIM_SIGNED,
 DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FVGT_m_MULTI_ODD,HAS_BUG_NUMBER,
 MD5_SHA1_SUM,PDS_BTC_ID,PGPSIGNATURE,RCVD_IN_DNSWL_MED,SPF_HELO_PASS,
 SPF_PASS,USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 4; hammy, 150; neutral, 396; spammy,
 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz,
 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from mitropoulos.debian.org
 ([2001:648:2ffc:deb:216:61ff:fe9d:958d]:51998)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1x12NX-007OgJ-12 for 1144851-close@bugs.debian.org;
 Mon, 31 Aug 2026 13:48:51 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by mitropoulos.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1x12NV-007Xnv-2G for 1144851-close@bugs.debian.org;
 Mon, 31 Aug 2026 13:48:49 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=T9tmzKTgnWG5oSA4cOwwLoI5RaD+3TyQqiDXUXqZlPg=; b=fax4R/evshIuggiM73YqSCRjfc
 JXMgG0X6lT70XvPx+vCtbEDMbIfre3HyO62FBbo+eGQtkGeccngAZNlE1U6JcR9MKv0vmufHkJcMi
 sD4aLJ6uX6zjrnGdBJi0903Ux91o/z22W2YT2/PLCtaguimcmvkGgPp/kpN5L98wI7hR4rmWxEje6
 B741UXMuGMcyGSPK/FdYEYXO2tLmGxakHc42nJb+iRMss7T6fDPHt2cLj5YsMgUGs+MaXZdHlaPua
 tgj0kElU2YikAoeKgHPV1u+am5a7tBbolfhF9f5Ks9qeqUlCTLjgahZgwYnTSbmIBiQtPGQhhKKT/
 JprB2vuw==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1x12NU-000000050Qk-2E3I; Mon, 31 Aug 2026 13:48:48 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: Salvatore Bonaccorso &lt;carnil@debian.org&gt;
To: 1144851-close@bugs.debian.org
X-DAK: dak process-policy
X-Debian: DAK
X-Debian-Package: libdbi-perl
Debian: DAK
Debian-Changes: libdbi-perl_1.652-2~deb13u1_sourceonly.changes
Debian-Source: libdbi-perl
Debian-Version: 1.652-2~deb13u1
Debian-Architecture: source
Debian-Suite: proposed-updates
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1144851: fixed in libdbi-perl 1.652-2~deb13u1
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============6882577992653829564==&quot;
Message-Id: &lt;E1x12NU-000000050Qk-2E3I@fasolo.debian.org&gt;
Date: Mon, 31 Aug 2026 13:48:48 +0000
X-CrossAssassin-Score: 3

--===============6882577992653829564==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: libdbi-perl
Source-Version: 1.652-2~deb13u1
Done: Salvatore Bonaccorso &lt;carnil@debian.org&gt;

We believe that the bug you reported is fixed in the latest version of
libdbi-perl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144851@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso &lt;carnil@debian.org&gt; (supplier of updated libdbi-perl pac=
kage)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 22 Aug 2026 22:43:46 +0200
Source: libdbi-perl
Architecture: source
Version: 1.652-2~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Perl Group &lt;pkg-perl-maintainers@lists.alioth.debian.org&gt;
Changed-By: Salvatore Bonaccorso &lt;carnil@debian.org&gt;
Closes: 1141667 1142072 1144470 1144471 1144851
Changes:
 libdbi-perl (1.652-2~deb13u1) trixie-security; urgency=3Dhigh
 .
   * Team upload.
   * Rebuild for trixie-security
   * Revert &quot;Remove =C2=ABPriority: optional=C2=BB, which is the current defa=
ult.&quot;
   * Revert &quot;Remove =C2=ABRules-Requires-Root: no=C2=BB, which is the current=
 default.&quot;
   * Revert &quot;Declare compliance with Debian Policy 4.7.4.&quot;
   * Revert &quot;Reformat debian/control.&quot;
 .
 libdbi-perl (1.652-2) unstable; urgency=3Dmedium
 .
   * Add patch from upstream Git to fix 32bit test failure.
     Thanks to Adrian Bunk for the bug report. (Closes: #1144851)
 .
 libdbi-perl (1.652-1) unstable; urgency=3Dmedium
 .
   * Import upstream version 1.652.
     + Limit statements to 292 Mb in preparse (CVE-2026-73193)
       (Closes: #1144470)
     + Force placeholder limit on :# and :p# too (CVE-2026-73194)
       (Closes: #1144471)
   * Install new SECURITY.md file.
   * Refresh t__40profile.t__NTP.patch (offset).
 .
 libdbi-perl (1.651-1) unstable; urgency=3Dmedium
 .
   * Import upstream version 1.651.
     - Fix inverted comparisons for strings in DBI::SQL::Nano
       (CVE-2026-15043)
     - Fix DBD::File to ensure that the table is not a symlink outside of f_d=
ir
       (CVE-2026-15392)
     - Fix an out-of-bounds error when a statement handle has no fields but t=
he
       source row is not empty (CVE-2026-60082)
     - Add an overridable upper bound $MAX_PATH_DEPTH for DBI::ProfileData
       (CVE-2026-60081)
     Closes: #1142072
 .
 libdbi-perl (1.650-1) unstable; urgency=3Dmedium
 .
   * Import upstream version 1.650.
     - Set a hard limit of 99999 on '?' placeholders
       (CVE-2026-14739)
     - Fix out-of-bounds read in preparse of SQL that starts with a comment
       (CVE-2026-14740)
     - Fix code injection via Profile DSN attribute or DBI_PROFILE variable
       (CVE-2026-14380)
     Closes: #1141667
   * Install new upstream document.
 .
 libdbi-perl (1.649-1) unstable; urgency=3Dmedium
 .
   * Import upstream version 1.649.
 .
 libdbi-perl (1.648-1) unstable; urgency=3Dmedium
 .
   * Import upstream version 1.648.
     Fixes CVE-2026-9698 and CVE-2026-10879.
   * Update years of upstream and packaging copyright.
   * Declare compliance with Debian Policy 4.7.4.
   * Remove =C2=ABRules-Requires-Root: no=C2=BB, which is the current default.
   * Remove =C2=ABPriority: optional=C2=BB, which is the current default.
Checksums-Sha1:=20
 e84a20877081f9a4158d67ef2b30ee72751105e0 2373 libdbi-perl_1.652-2~deb13u1.dsc
 5fc073e859390f07b06ddd0a26020ef52d02e78e 734177 libdbi-perl_1.652.orig.tar.gz
 45c0c4a18716c4de2562d7f643e7a3c69e2f3333 15296 libdbi-perl_1.652-2~deb13u1.d=
ebian.tar.xz
Checksums-Sha256:=20
 9820de2e2b5767d80492b7dba575ed8df10edfa71bce3a04b35fdf41a20822ce 2373 libdbi=
-perl_1.652-2~deb13u1.dsc
 e7981833696d15414bb76c43817d48f9fc3879e1421433116374fbc63e8e78ad 734177 libd=
bi-perl_1.652.orig.tar.gz
 3f344c1491c4435e60ec6bc678655c52f34ccc41f3d6813d076b9d128a92f4f6 15296 libdb=
i-perl_1.652-2~deb13u1.debian.tar.xz
Files:=20
 1b5efbf7f19090e721285a56c15446df 2373 perl optional libdbi-perl_1.652-2~deb1=
3u1.dsc
 0d511887cb8b8d2a86c5ef78395b0438 734177 perl optional libdbi-perl_1.652.orig=
.tar.gz
 2076444e9f06e4253a2ac5319207092a 15296 perl optional libdbi-perl_1.652-2~deb=
13u1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmqK4yhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89ExQsP/3v9e8Ao38M6fr2xECDCeZ31cQVkBPk+
v/aYS3fAdS04QBVDiEWkYSh96+pfEUm2Dq6Ha28DnoAxnyNBo182pYZXA6ToilD/
iFMCY7oZSR+1AekbCstbzHMtkvI42BEAzOeO7NEUsNSjoYdIBfiO/crCObxlemAK
xEKp2yIxBgPrlLwxzajBv+EE4rgD8z+ZWQAWnI+fG86B9jbocAP6Wp/oaH65+cj+
hYgZOadv9HhZdOu8rbAujI2kEJn/w35AUcGd5JH4b2dUv61hJab6AZ8QMDme4qlv
DlShVfgRw89SqTeLiEDOkUKPQHxWVVxUI98m9eH1YCRB1NxTSxB1DP1re+fl6Nlm
4/NKP02V9tpzgUeTTRWtTaPm4Kv8SSMfs61oE4Azj3TjIGdr6cfvYWBwyqJKk2+U
rhtEM2fi2EUKhobMyfI24G3VFp3nzWCAojWxQZbi6JuFSY5a2fOpEzO5UhEcfevK
aDPUwIsbRvfYr83EGyceppvQCTIle7HT298jh1eCDjnszC7Pbw1oa0k6dVgaE+4U
kifJDuj8bYu3dM/+qVMlnfDaVokQjeOQ+FSeUE32B6GCs58dstoqHGjawWPVTUn8
DtRZgCuXS9oyXLSHyOl117aWn3OTlwa0uWuhw9ZTt2fmL0EAOvmZOJ7hgPYKfRvz
SbGu2jKWe9fx
=3Dwnr0
-----END PGP SIGNATURE-----


--===============6882577992653829564==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCapWGQAAKCRCb9qggYcy5
IRBBAQDNffO1N6WEooVSB817GLbmKpVmat9w59+jtV2iSGNmrAEA4Kmqahjd90Co
wHuhDJo4P6f+n+4VeYottxwcXfMvEQU=
=Ysx2
-----END PGP SIGNATURE-----

--===============6882577992653829564==--
]