XPost: linux.debian.devel.release
Package: release.debian.org
Control: affects -1 + src:poppler
X-Debbugs-Cc:
[email protected],
[email protected]
User:
[email protected]
Usertags: unblock
Please unblock package poppler.
[ Reason ]
Security update
[ Impact ]
This update includes the security fix from Ubuntu. The Debian Security
team has marked the issue as "minor" for bookworm.
https://security-tracker.debian.org/tracker/CVE-2025-52886 https://launchpad.net/ubuntu/+source/poppler
[ Tests ]
This package has autopkgtests. I filed this bug before we verified
that the autopkgtests are passing.
I completed the test cases from
https://wiki.ubuntu.com/DesktopTeam/TestPlans/Papers
[ Risks ]
Key package for multiple desktops. If it's not possible to use the
GNOME default app Evince or the KDE default app Okular to load PDFs,
Firefox ESR and other browsers can load PDFs instead.
[ Checklist ]
[✔️] all changes are documented in the d/changelog
[✔️] I reviewed all changes and I approve them
[✔️] attach debdiff against the package in testing
unblock poppler/25.03.0-5
Thank you,
Jeremy Bícha
ZGlmZiAtTnJ1IHBvcHBsZXItMjUuMDMuMC9kZWJpYW4vY2hhbmdlbG9nIHBvcHBsZXItMjUuMDMu MC9kZWJpYW4vY2hhbmdlbG9nCi0tLSBwb3BwbGVyLTI1LjAzLjAvZGViaWFuL2NoYW5nZWxvZwky MDI1LTA0LTE5IDAwOjE2OjMyLjAwMDAwMDAwMCArMDIwMAorKysgcG9wcGxlci0yNS4wMy4wL2Rl Ymlhbi9jaGFuZ2Vsb2cJMjAyNS0wNy0yOCAxMDo1NToxMi4wMDAwMDAwMDAgKzAyMDAKQEAgLTEs MyArMSwxMyBAQAorcG9wcGxlciAoMjUuMDMuMC01KSB1bnN0YWJsZTsgdXJnZW5jeT1oaWdoCisK KyAgWyBNYXJjIERlc2xhdXJpZXJzIF0KKyAgKiBTRUNVUklUWSBVUERBVEU6IERvUyB2aWEgcmVm ZXJlbmNlIGNvdW50IG92ZXJmbG93CisgICAgLSBkZWJpYW4vcGF0Y2hlcy9DVkUtMjAyNS01Mjg4 Ni5wYXRjaDogbGltaXQgYW1vdW50IG9mIGFubm90cyBwZXIKKyAgICAgIGRvY3VtZW50L3BhZ2Ug aW4gcG9wcGxlci9Bbm5vdC5jYywgcG9wcGxlci9QYWdlLmNjLgorICAgIC0gQ1ZFLTIwMjUtNTI4 ODYgKENsb3NlczogIzExMDg3ODQpCisKKyAtLSBKZXJlbXkgQsOtY2hhIDxqYmljaGFAdWJ1bnR1 LmNvbT4gIE1vbiwgMjggSnVsIDIwMjUgMTA6NTU6MTIgKzAyMDAKKwogcG9wcGxlciAoMjUuMDMu MC00KSB1bnN0YWJsZTsgdXJnZW5jeT1oaWdoCiAKICAgKiBUZWFtIHVwbG9hZApkaWZmIC1OcnUg cG9wcGxlci0yNS4wMy4wL2RlYmlhbi9wYXRjaGVzL0NWRS0yMDI1LTUyODg2LnBhdGNoIHBvcHBs ZXItMjUuMDMuMC9kZWJpYW4vcGF0Y2hlcy9DVkUtMjAyNS01Mjg4Ni5wYXRjaAotLS0gcG9wcGxl ci0yNS4wMy4wL2RlYmlhbi9wYXRjaGVzL0NWRS0yMDI1LTUyODg2LnBhdGNoCTE5NzAtMDEtMDEg MDE6MDA6MDAuMDAwMDAwMDAwICswMTAwCisrKyBwb3BwbGVyLTI1LjAzLjAvZGViaWFuL3BhdGNo ZXMvQ1ZFLTIwMjUtNTI4ODYucGF0Y2gJMjAyNS0wNy0yOCAxMDo1NToxMi4wMDAwMDAwMDAgKzAy MDAKQEAgLTAsMCArMSw1MCBAQAorQmFja3BvcnQgb2Y6CisKK0Zyb20gYWMzNmFmZmNjODQ4NmRl MzhlODkwNWE4ZDY1NDdhMzQ2NGZmNDZlNSBNb24gU2VwIDE3IDAwOjAwOjAwIDIwMDEKK0Zyb206 IFN1bmUgVnVvcmVsYSA8c3VuZUB2dW9yZWxhLmRrPgorRGF0ZTogVHVlLCAzIEp1biAyMDI1IDAw OjM1OjE5ICswMjAwCitTdWJqZWN0OiBbUEFUQ0hdIExpbWl0IGFtbW91bnQgb2YgYW5ub3RzIHBl ciBkb2N1bWVudC9wYWdlCisKKy0tLQorIHBvcHBsZXIvQW5ub3QuY2MgfCAgNCArKysrCisgcG9w cGxlci9QYWdlLmNjICB8IDE2ICsrKysrKysrKysrKysrKysKKyAyIGZpbGVzIGNoYW5nZWQsIDIw IGluc2VydGlvbnMoKykKKworLS0tIGEvcG9wcGxlci9Bbm5vdC5jYworKysrIGIvcG9wcGxlci9B bm5vdC5jYworQEAgLTc0NzksNiArNzQ3OSwxMCBAQCBBbm5vdHM6OkFubm90cyhQREZEb2MgKmRv Y0EsIGludCBwYWdlLCBPCisgICAgICAgICAgICAgICAgIGNvbnN0IE9iamVjdCAmb2JqMiA9IGFu bm90c09iai0+YXJyYXlHZXRORihpKTsKKyAgICAgICAgICAgICAgICAgYW5ub3QgPSBjcmVhdGVB bm5vdChzdGQ6Om1vdmUob2JqMSksICZvYmoyKTsKKyAgICAgICAgICAgICAgICAgaWYgKGFubm90 KSB7CisrICAgICAgICAgICAgICAgICAgICBpZiAoYW5ub3QtPnJlZkNudCA+IDEwMDAwMCkgewor KyAgICAgICAgICAgICAgICAgICAgICAgIGVycm9yKGVyclN5bnRheEVycm9yLCAtMSwgIkFubm90 YXRpb25zIGxpa2VseSBtYWxmb3JtZWQuIFRvbyBtYW55IHJlZmVyZW5jZXMuIFN0b3BwaW5nIHBy b2Nlc3NpbmcgYW5ub3RzIG9uIHBhZ2UgezA6ZH0iLCBwYWdlKTsKKysgICAgICAgICAgICAgICAg ICAgICAgICBicmVhazsKKysgICAgICAgICAgICAgICAgICAgIH0KKyAgICAgICAgICAgICAgICAg ICAgIGlmIChhbm5vdC0+aXNPaygpKSB7CisgICAgICAgICAgICAgICAgICAgICAgICAgYW5ub3Qt PnNldFBhZ2UocGFnZSwgZmFsc2UpOyAvLyBEb24ndCBjaGFuZ2UgL1AKKyAgICAgICAgICAgICAg ICAgICAgICAgICBhcHBlbmRBbm5vdChhbm5vdCk7CistLS0gYS9wb3BwbGVyL1BhZ2UuY2MKKysr KyBiL3BvcHBsZXIvUGFnZS5jYworQEAgLTI5Nyw2ICsyOTcsMjIgQEAgUGFnZTo6UGFnZShQREZE b2MgKmRvY0EsIGludCBudW1BLCBPYmplYworICAgICAgICAgZ290byBlcnIyOworICAgICB9Cisg CisrICAgIGlmIChhbm5vdHNPYmouaXNBcnJheSgpICYmIGFubm90c09iai5hcnJheUdldExlbmd0 aCgpID4gMTAwMDApIHsKKysgICAgICAgIGVycm9yKGVyclN5bnRheEVycm9yLCAtMSwgIlBhZ2Ug YW5ub3RhdGlvbnMgb2JqZWN0IChwYWdlIHswOmR9KSBpcyBsaWtlbHkgbWFsZm9ybWVkLiBUb28g YmlnOiAoezE6ZH0pIiwgbnVtLCBhbm5vdHNPYmouYXJyYXlHZXRMZW5ndGgoKSk7CisrICAgICAg ICBnb3RvIGVycjI7CisrICAgIH0KKysgICAgaWYgKGFubm90c09iai5pc1JlZigpKSB7CisrICAg ICAgICBhdXRvIHJlc29sdmVkT2JqID0gZ2V0QW5ub3RzT2JqZWN0KCk7CisrICAgICAgICBpZiAo cmVzb2x2ZWRPYmouaXNBcnJheSgpICYmIHJlc29sdmVkT2JqLmFycmF5R2V0TGVuZ3RoKCkgPiAx MDAwMCkgeworKyAgICAgICAgICAgIGVycm9yKGVyclN5bnRheEVycm9yLCAtMSwgIlBhZ2UgYW5u b3RhdGlvbnMgb2JqZWN0IChwYWdlIHswOmR9KSBpcyBsaWtlbHkgbWFsZm9ybWVkLiBUb28gYmln OiAoezE6ZH0pIiwgbnVtLCByZXNvbHZlZE9iai5hcnJheUdldExlbmd0aCgpKTsKKysgICAgICAg ICAgICBnb3RvIGVycjI7CisrICAgICAgICB9CisrICAgICAgICBpZiAoIXJlc29sdmVkT2JqLmlz QXJyYXkoKSAmJiAhcmVzb2x2ZWRPYmouaXNOdWxsKCkpIHsKKysgICAgICAgICAgICBlcnJvcihl cnJTeW50YXhFcnJvciwgLTEsICJQYWdlIGFubm90YXRpb25zIG9iamVjdCAocGFnZSB7MDpkfSkg aXMgd3JvbmcgdHlwZSAoezE6c30pIiwgbnVtLCByZXNvbHZlZE9iai5nZXRUeXBlTmFtZSgpKTsK KysgICAgICAgICAgICBnb3RvIGVycjI7CisrICAgICAgICB9CisrICAgIH0KKysKKyAgICAgLy8g Y29udGVudHMKKyAgICAgY29udGVudHMgPSBwYWdlT2JqLmRpY3RMb29rdXBORigiQ29udGVudHMi KS5jb3B5KCk7CisgICAgIGlmICghKGNvbnRlbnRzLmlzUmVmKCkgfHwgY29udGVudHMuaXNBcnJh eSgpIHx8IGNvbnRlbnRzLmlzTnVsbCgpKSkgewpkaWZmIC1OcnUgcG9wcGxlci0yNS4wMy4wL2Rl Ymlhbi9wYXRjaGVzL3NlcmllcyBwb3BwbGVyLTI1LjAzLjAvZGViaWFuL3BhdGNoZXMvc2VyaWVz Ci0tLSBwb3BwbGVyLTI1LjAzLjAvZGViaWFuL3BhdGNoZXMvc2VyaWVzCTIwMjUtMDQtMTkgMDA6 MTY6MzIuMDAwMDAwMDAwICswMjAwCisrKyBwb3BwbGVyLTI1LjAzLjAvZGViaWFuL3BhdGNoZXMv c2VyaWVzCTIwMjUtMDctMjggMTA6NTU6MTIuMDAwMDAwMDAwICswMjAwCkBAIC0xLDMgKzEsNCBA QAogQ1ZFLTIwMjUtMzIzNjQucGF0Y2gKIENWRS0yMDI1LTMyMzY1LnBhdGNoCiBDVkUtMjAyNS00 MzkwMy5wYXRjaAorQ1ZFLTIwMjUtNTI4ODYucGF0Y2gK
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)