[Git][security-tracker-team/security-tracker][master] Reserve DLA-4330-1 for ghostscript

Abhijith PA (@abhijith) abhijith at debian.org
Tue Oct 14 08:23:30 BST 2025



Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9386f369 by Abhijith PA at 2025-10-14T12:53:10+05:30
Reserve DLA-4330-1 for ghostscript

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -30964,7 +30964,6 @@ CVE-2025-7463 (A vulnerability was found in Tenda FH1201 1.2.0.14. It has been d
 CVE-2025-7462 (A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1 ...)
 	{DSA-6024-1}
 	- ghostscript 10.05.1~dfsg-2 (bug #1109270)
-	[bullseye] - ghostscript <postponed> (Minor issue; crash)
 	NOTE: https://bugs.ghostscript.com/show_bug.cgi?id=708606
 	NOTE: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=619a106ba4c4abed95110f84d5efcd7aee38c7cb
 CVE-2025-7461 (A vulnerability was found in code-projects Modern Bag 1.0 and classifi ...)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[14 Oct 2025] DLA-4330-1 ghostscript - security update
+	{CVE-2025-7462 CVE-2025-59798 CVE-2025-59799}
+	[bullseye] - ghostscript 9.53.3~dfsg-7+deb11u11
 [13 Oct 2025] DLA-4329-1 libfcgi - security update
 	{CVE-2025-23016}
 	[bullseye] - libfcgi 2.4.2-2+deb11u1


=====================================
data/dla-needed.txt
=====================================
@@ -112,10 +112,6 @@ gegl (Sylvain Beucler)
   NOTE: 20250928: Consider fixing all the old CVEs as well. (utkarsh)
   NOTE: 20250928: Check w/ Emilio as the maintainer of the package. (utkarsh)
 --
-ghostscript
-  NOTE: 20250924: Added by Front-Desk (utkarsh)
-  NOTE: 20251014: backported, upload ready (abhijith)
---
 gimp (Sylvain Beucler)
   NOTE: 20250410: Added by Front-Desk (Beuc)
   NOTE: 20250410: CVE-2025-2760 may need a custom patch as upstream now focuses on gimp3,



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9386f3695c717364d975c16b8c3d17b8b991591d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9386f3695c717364d975c16b8c3d17b8b991591d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251014/214b1f91/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list