Hi Paul, On Fri, Jun 07, 2019 at 08:08:07PM +0200, Paul Gevers wrote: > Hi Salvatore, > > On 07-06-2019 08:37, Salvatore Bonaccorso wrote: > > On Sun, Jun 02, 2019 at 07:39:04AM +0000, Debian Bug Tracking System wrote: > >> On 02-06-2019 00:07, Reinhard Tartler wrote: > >>> Please unblock package libheif to address CVE-2019-11471, aka #928210 in > >>> Debian/buster. > >>> > >>> unblock libheif/1.3.2-2 > >> > >> Unblocked, thanks. > > > > Looks libheif (similarly to qemu) cannot move to testing/buster: > > > > libheif (1.3.2-1 to 1.3.2-2) > > Maintainer: Debian Multimedia Maintainers > > 5 days old (needed 5 days) > > Depends: libheif gcc-8 (not considered) > > Updating libheif fixes old bugs: #928210 > > Piuparts tested OK - > > https://piuparts.debian.org/sid/source/libh/libheif.html > > Ignoring block request by freeze, due to unblock request by elbrus > > Invalidated by dependency > > > > should an upload be done via tpu here or is an unblock for the gcc-8 > > bug still under possible consideration? > > I believe that Ivo told you in real life that rebuilds > * that target tpu > * that are unblocked by the release team in unstable > * that are blocked by gcc-8 and > * have security issues > are acceptable and will be unblocked when you ping us. > > The gcc-8 bug is waiting for moreinfo.
I just have uploaded for buster a source-only upload for buster with the attached debdiff. So this will be just a rebuild of the unstable version for buster with a lower version. Thanks to all the release team for your work! Regards, Salvatore
diff -Nru libheif-1.3.2/debian/changelog libheif-1.3.2/debian/changelog --- libheif-1.3.2/debian/changelog 2019-06-01 23:56:05.000000000 +0200 +++ libheif-1.3.2/debian/changelog 2019-06-07 20:19:26.000000000 +0200 @@ -1,3 +1,10 @@ +libheif (1.3.2-2~deb10u1) buster; urgency=medium + + * Non-maintainer upload. + * Rebuild for buster. + + -- Salvatore Bonaccorso <car...@debian.org> Fri, 07 Jun 2019 20:19:26 +0200 + libheif (1.3.2-2) unstable; urgency=medium * Team Upload