accel-config (4.1.6-1) unstable; urgency=medium . * Sync with upstream 4.1.6 release azure-uamqp-python (1.6.9-2) unstable; urgency=high . * Team upload. * CVE-2024-29195: An attacker can cause an integer wraparound or under- allocation or heap buffer overflow due to vulnerabilities in parameter checking mechanism, by exploiting the buffer length parameter in Azure C SDK, which may lead to remote code execution. Applied upstream patch: CVE-2024-29195_Add-malloc-size-checks.patch (Closes: #1068457). azure-uamqp-python (1.6.9-1) unstable; urgency=medium . * Team upload. * New upstream version * d/patches/CVE-2024-25110: removed, applied upstream. azure-uamqp-python (1.6.8-2) unstable; urgency=medium . * Team upload. * d/patches/no-distutils: remove useage of distutils for Python 3.12. * d/patches: cherry-pick two patches from upstream's upstream to fix CVE-2024-25110 and CVE-2024-27099. Closes: #1064996, #1064996 c-ares (1.27.0-1.2) unstable; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. Closes: #1062032 c-ares (1.27.0-1.1) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. c-ares (1.27.0-1.1~exp1) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. cl-plus-ssl (20220328.git8b91648-5) unstable; urgency=medium . * Team upload. . [ Sébastien Villemot ] * Remove myself from Uploaders . [ Christoph Berg ] * Rebuild to pick up new libssl3t64 package name. (Closes: #1066067) globus-authz-callout-error (4.2-3) unstable; urgency=medium . * Enable bind-now hardening globus-authz-callout-error (4.2-2.1) unstable; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. Closes: #1062138 globus-authz-callout-error (4.2-2.1~exp1) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. lcalc (2.0.5-1.1) unstable; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. Closes: #1062519 lcalc (2.0.5-1.1~exp1) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. libpsl (0.21.2-1.1) unstable; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. Closes: #1062576 libpsl (0.21.2-1.1~exp1) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. libssh2 (1.11.0-4.1) unstable; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. Closes: #1062637 libssh2 (1.11.0-4.1~exp1) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. lua-lxc (1:3.0.2-3) unstable; urgency=medium . * Team upload * d/control: - Update Standards-Version to 4.7.0 (no changes needed) - Update Build-Depends pkg-config => pkgconf - Removed hard-coded Depends on liblxc1 (Closes: #1068402) lxc (1:5.0.3-3) unstable; urgency=medium . [ Aleksandr Mikhalitsyn ] * debian/tests: Addition of the "no-devel" test * debian/tests/unprivileged-containers: Fix and make work on Ubuntu . [ Mathias Gibbens ] * d/control: - Update Build-Depends from systemd -> systemd-dev (Closes: #1060614) - Update Build-Depends from pkg-config -> pkgconf * Cherry-pick upstream fixes for d/tests/test-usernic * Update years in d/copyright . [ Michael Biebl ] * Install PAM modules into /usr. (Closes: #1061490) * Drop Build-Depends on dh-exec, no longer necessary. . [ Stéphane Graber ] * Cherry-pick upstream bugfixes: - 0013-cherry-pick-remove-broken-cgroup-tests.patch - 0014-cherry-pick-lxc-copy-apparmor.patch * Add Ubuntu-specific patch (for now): - Handle AppArmor ABI 4 with userns extension * debian/rules - Add lxc-copy apparmor profile - Apply Ubuntu-specific patch lxc (1:5.0.3-2.1) unstable; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. Closes: #1062679 lxc (1:5.0.3-2.1~exp1) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. mbedtls (2.28.8-1) unstable; urgency=medium . * New upstream version 2.28.8 * d/libmbedtls-dev.install: install new pkg-config files (Closes: #900015) * d/.symbols: add new PSA symbols mbedtls (2.28.7-1.1) unstable; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. Closes: #1062859 mbedtls (2.28.7-1.1~exp1) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. neon27 (0.33.0-1.1) unstable; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. Closes: #1064246 neon27 (0.33.0-1.1~exp2) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. neon27 (0.33.0-1.1~exp1) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. openni (1.5.4.0+dfsg-7.1) unstable; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. Closes: #1063098 openni (1.5.4.0+dfsg-7.1~exp1) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. openssl (3.2.1-3) unstable; urgency=medium . * Upload to unstable. * Correct prvious security level in NEWS file (Closes: #1066116). openssl (3.2.1-2) experimental; urgency=medium . * Disable brotli and enable zlib for certificate compression. * Update to latest openssl-3.2 branch. openssl (3.2.1-1.1~exp1) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. openssl (3.2.1-1) experimental; urgency=medium . * Import 3.2.1 - CVE-2024-0727 (PKCS12 Decoding crashes). (Closes: #1061582). - CVE-2023-6237 (Excessive time spent checking invalid RSA public keys) (Closes: #1060858). - CVE-2023-6129 (POLY1305 MAC implementation corrupts vector registers on PowerPC) (Closes: #1060347). openssl (3.2.0-2) experimental; urgency=medium . * Use generic target for riscv64. * Update to latest openssl-3.2 branch. openssl (3.2.0-1) experimental; urgency=medium . * Import 3.2.0 * Enable zstd, brotli and for certificate compression. openssl (3.1.5-1.1) unstable; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. Closes: #1064264 pari (2.15.5-1) unstable; urgency=medium . * New upstream release. - patch upstream-forqfvec: removed, applied upstream pari (2.15.5~pre1-1.1~exp2) experimental; urgency=medium . * Update debian/rules for the new library package name. pari (2.15.5~pre1-1.1~exp1) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. pari (2.15.5~pre1-1) experimental; urgency=medium . * New upstream prerelease. * patch usptream-forqfvec: removed pari (2.15.4-2.1) unstable; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. Closes: #1063210 pari (2.15.4-2.1~exp1) experimental; urgency=medium . * Non-maintainer upload. * Rename libraries for 64-bit time_t transition. pgbackrest (2.51-1) unstable; urgency=medium . [ Bradford D. Boyle ] * New Upstream Release - Bug Fixes: * Skip zero-length files for block incremental delta restore. - Improvements: * Improved support for dual stack connections. * Make meson the primary build system. * Detect files that have not changed during non-delta incremental backup. * Prevent invalid recovery when backup_label removed. * Improve archive-push WAL segment queue handling. * Limit resume functionality to full backups. * Update resume functionality for block incremental. * Allow --version and --help for version and help. * Add detailed backtrace to autoconf/make build. - Documentation Improvements: * Update references to recovery.conf. . [ Christoph Berg ] * Recognize Bradford as pgbackrest Uploader. pgloader (3.6.10-2) unstable; urgency=medium . * Limit architectures to those that have sbcl available and working thread support (notably, this excludes armel and armhf). picolisp (24.3-1) unstable; urgency=medium . * New upstream version 24.3 * debian/control: build-dep pkg-config -> pkgconf * debian/control: bump standards-version to 4.7.0, no changes needed python3-lxc (1:5.0.0-2) unstable; urgency=medium . * d/control: - Update Standards-Version to 4.7.0 (no changes needed) - Update Build-Depends pkg-config => pkgconf - Removed hard-coded Depends on liblxc1 (Closes: #1068937) * Update years in d/copyright sope (5.10.0-1) unstable; urgency=medium . * New upstream release. * Fix watch to allow for double digit components of a version. * Update copyright years and download URL. * Drop GNUStep 1.29 compatibility patch, fixed upstream. stone (2.4-1.1) unstable; urgency=medium . * Non-maintainer upload. * d/copyright: Convert to machine-readable format. * Convert to source format 3.0. (Closes: #1007330) . [ Helmut Grohne ] * Fix FTCBFS: Let dh_auto_build pass cross tools to make. (Closes: #999881) . [ Tatsuya Kinoshita ] * Fix FTBFS on GNU/Hurd. (Closes: #403401) . [ Tomoaki Hayasaka ] * Do not pass empty POP_FLAGS and POP_LIBS to build. (Closes: #626252) stunnel4 (3:5.72-3) unstable; urgency=medium . * autopkgtest: use Ruff 0.3.5 with no changes. * Use X-DH-Compat instead of debian/compat. * Add the 08-smtp-ehlo patch for some SMTP servers. * Declare compliance with Policy 4.7.0 with no changes. * Add a NEWS entry about the deprecation of the stunnel4.service autogenerated by systemd from the SysV init script in favor of the per-tunnel stunnel@ template. stunnel4 (3:5.72-2) unstable; urgency=medium . [ Simon McVittie ] * Don't run build-time tests on the 32-bit non-i386 architectures. This allows libcurl to be rebuilt on the architectures affected by the 64-bit time_t transition, which unblocks rebuilding of a lot of the C/C++ ecosystem without having to wait for rustc/cargo to be re-bootstrapped (#1065787). Thanks to Mattia Rizzolo. Closes: #1066049 . [ Peter Pentchev ] * Minor improvements to the autopkgtest Python harness: - the test suite for the testing program itself: - use Ruff 0.3.2, no changes - make the Ruff config simpler - let Ruff also validate the docstrings - use Ruff for source code formatting, too - let Ruff insist on trailing commas - enable Ruff preview mode, disable some checks - fix the forgotten f- prefix on two f-strings - use a hierarchy of exceptions * Add the 07-reproducible-build patch to use the Debian changelog's date instead of the current one. Closes: #1059014 x11vnc (0.9.16-10) unstable; urgency=medium . * Team upload. . [ Michael Hudson-Doyle ] * debian/patches: + Add 0007-use-clock_gettime-to-replace-gettimeofday.patch. Fix FTBFS related to time_64t transition. (Closes: #1067076). . [ Mike Gabriel ] * debian/control: + Bump Standards-Version: to 4.6.2. No changes needed. xrdp (0.9.24-4) unstable; urgency=medium . [ Alex Myczko ] * Update my name. * d/control: build-depends pkg-config to pkgconf. * Bump standards version to 4.7.0. . [ Arnaud Rebillout ] * d/control: add pipewire-module-xrdp to recommends.