libdbi-perl_1.652-2~deb13u1_sourceonly.changes ACCEPTED into proposed-updates
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Mon Aug 31 14:48:48 BST 2026
Thank you for your contribution to Debian.
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 22 Aug 2026 22:43:46 +0200
Source: libdbi-perl
Architecture: source
Version: 1.652-2~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Perl Group <pkg-perl-maintainers at lists.alioth.debian.org>
Changed-By: Salvatore Bonaccorso <carnil at debian.org>
Closes: 1141667 1142072 1144470 1144471 1144851
Changes:
libdbi-perl (1.652-2~deb13u1) trixie-security; urgency=high
.
* Team upload.
* Rebuild for trixie-security
* Revert "Remove «Priority: optional», which is the current default."
* Revert "Remove «Rules-Requires-Root: no», which is the current default."
* Revert "Declare compliance with Debian Policy 4.7.4."
* Revert "Reformat debian/control."
.
libdbi-perl (1.652-2) unstable; urgency=medium
.
* Add patch from upstream Git to fix 32bit test failure.
Thanks to Adrian Bunk for the bug report. (Closes: #1144851)
.
libdbi-perl (1.652-1) unstable; urgency=medium
.
* Import upstream version 1.652.
+ Limit statements to 292 Mb in preparse (CVE-2026-73193)
(Closes: #1144470)
+ Force placeholder limit on :# and :p# too (CVE-2026-73194)
(Closes: #1144471)
* Install new SECURITY.md file.
* Refresh t__40profile.t__NTP.patch (offset).
.
libdbi-perl (1.651-1) unstable; urgency=medium
.
* Import upstream version 1.651.
- Fix inverted comparisons for strings in DBI::SQL::Nano
(CVE-2026-15043)
- Fix DBD::File to ensure that the table is not a symlink outside of f_dir
(CVE-2026-15392)
- Fix an out-of-bounds error when a statement handle has no fields but the
source row is not empty (CVE-2026-60082)
- Add an overridable upper bound $MAX_PATH_DEPTH for DBI::ProfileData
(CVE-2026-60081)
Closes: #1142072
.
libdbi-perl (1.650-1) unstable; urgency=medium
.
* Import upstream version 1.650.
- Set a hard limit of 99999 on '?' placeholders
(CVE-2026-14739)
- Fix out-of-bounds read in preparse of SQL that starts with a comment
(CVE-2026-14740)
- Fix code injection via Profile DSN attribute or DBI_PROFILE variable
(CVE-2026-14380)
Closes: #1141667
* Install new upstream document.
.
libdbi-perl (1.649-1) unstable; urgency=medium
.
* Import upstream version 1.649.
.
libdbi-perl (1.648-1) unstable; urgency=medium
.
* Import upstream version 1.648.
Fixes CVE-2026-9698 and CVE-2026-10879.
* Update years of upstream and packaging copyright.
* Declare compliance with Debian Policy 4.7.4.
* Remove «Rules-Requires-Root: no», which is the current default.
* Remove «Priority: optional», which is the current default.
Checksums-Sha1:
e84a20877081f9a4158d67ef2b30ee72751105e0 2373 libdbi-perl_1.652-2~deb13u1.dsc
5fc073e859390f07b06ddd0a26020ef52d02e78e 734177 libdbi-perl_1.652.orig.tar.gz
45c0c4a18716c4de2562d7f643e7a3c69e2f3333 15296 libdbi-perl_1.652-2~deb13u1.debian.tar.xz
Checksums-Sha256:
9820de2e2b5767d80492b7dba575ed8df10edfa71bce3a04b35fdf41a20822ce 2373 libdbi-perl_1.652-2~deb13u1.dsc
e7981833696d15414bb76c43817d48f9fc3879e1421433116374fbc63e8e78ad 734177 libdbi-perl_1.652.orig.tar.gz
3f344c1491c4435e60ec6bc678655c52f34ccc41f3d6813d076b9d128a92f4f6 15296 libdbi-perl_1.652-2~deb13u1.debian.tar.xz
Files:
1b5efbf7f19090e721285a56c15446df 2373 perl optional libdbi-perl_1.652-2~deb13u1.dsc
0d511887cb8b8d2a86c5ef78395b0438 734177 perl optional libdbi-perl_1.652.orig.tar.gz
2076444e9f06e4253a2ac5319207092a 15296 perl optional libdbi-perl_1.652-2~deb13u1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmqK4yhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89ExQsP/3v9e8Ao38M6fr2xECDCeZ31cQVkBPk+
v/aYS3fAdS04QBVDiEWkYSh96+pfEUm2Dq6Ha28DnoAxnyNBo182pYZXA6ToilD/
iFMCY7oZSR+1AekbCstbzHMtkvI42BEAzOeO7NEUsNSjoYdIBfiO/crCObxlemAK
xEKp2yIxBgPrlLwxzajBv+EE4rgD8z+ZWQAWnI+fG86B9jbocAP6Wp/oaH65+cj+
hYgZOadv9HhZdOu8rbAujI2kEJn/w35AUcGd5JH4b2dUv61hJab6AZ8QMDme4qlv
DlShVfgRw89SqTeLiEDOkUKPQHxWVVxUI98m9eH1YCRB1NxTSxB1DP1re+fl6Nlm
4/NKP02V9tpzgUeTTRWtTaPm4Kv8SSMfs61oE4Azj3TjIGdr6cfvYWBwyqJKk2+U
rhtEM2fi2EUKhobMyfI24G3VFp3nzWCAojWxQZbi6JuFSY5a2fOpEzO5UhEcfevK
aDPUwIsbRvfYr83EGyceppvQCTIle7HT298jh1eCDjnszC7Pbw1oa0k6dVgaE+4U
kifJDuj8bYu3dM/+qVMlnfDaVokQjeOQ+FSeUE32B6GCs58dstoqHGjawWPVTUn8
DtRZgCuXS9oyXLSHyOl117aWn3OTlwa0uWuhw9ZTt2fmL0EAOvmZOJ7hgPYKfRvz
SbGu2jKWe9fx
=wnr0
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-perl-maintainers/attachments/20260831/ff9b874c/attachment.sig>
More information about the pkg-perl-maintainers
mailing list