[pkg-php-pear] Bug#1065062: bookworm-pu: package php-zend-code/4.8.0-1+deb12u1
David Prévot
taffit at debian.org
Thu Feb 29 10:58:03 GMT 2024
Package: release.debian.org
Severity: normal
Tags: bookworm
X-Debbugs-Cc: php-zend-code at packages.debian.org, team at security.debian.org
Control: affects -1 + src:php-zend-code
User: release.debian.org at packages.debian.org
Usertags: pu
[6/9 for bookworm]
This is a follow up from composer/DSA-5632-1.
In order to fix a Debian-specific issue related to CVE-2024-24821, we
agreed with the security team to push related dependencies via the next
point release.
The only change (besides changelog entry) in the binary package is the
following (thanks to diffoscope).
│ │ ├── ./usr/share/php/Laminas/Code/autoload.php
│ │ │ @@ -1,14 +1,14 @@
│ │ │ <?php
│ │ │
│ │ │ // Require
│ │ │
│ │ │ // Suggest
│ │ │ -if (stream_resolve_include_path('Doctrine/Common/Annotations/autoload.php')) { include_once 'Doctrine/Common/Annotations/autoload.php'; }
│ │ │ -if (stream_resolve_include_path('Laminas/Stdlib/autoload.php')) { include_once 'Laminas/Stdlib/autoload.php'; }
│ │ │ +if (stream_resolve_include_path(__DIR__ . '/../../Doctrine/Common/Annotations/autoload.php')) { include_once __DIR__ . '/../../Doctrine/Common/Annotations/autoload.php'; }
│ │ │ +if (stream_resolve_include_path(__DIR__ . '/../Stdlib/autoload.php')) { include_once __DIR__ . '/../Stdlib/autoload.php'; }
│ │ │
│ │ │ // @codingStandardsIgnoreFile
│ │ │ // @codeCoverageIgnoreStart
The goal is to ensure related dependencies are loaded from the system
path.
The attached debdiff is a bit bigger, since it aims at keeping the
testsuite at buildtime effective.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
TIA for considering.
Cheers,
taffit
-------------- next part --------------
A non-text attachment was scrubbed...
Name: php-zend-code.4.8.0-1+deb12u1.patch
Type: text/x-diff
Size: 3772 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-php-pear/attachments/20240229/7265e255/attachment.patch>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-php-pear/attachments/20240229/7265e255/attachment.sig>
More information about the pkg-php-pear
mailing list