-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 21 Mar 2026 19:34:10 +0100 Source: p7zip Architecture: source Version: 16.02+really25.01+dfsg-0+deb12u1 Distribution: bookworm Urgency: high Maintainer: Robert Luberda Changed-By: Sylvain Beucler Closes: 1111068 Changes: p7zip (16.02+really25.01+dfsg-0+deb12u1) bookworm; urgency=high . * Non-maintainer upload by the LTS Security Team. * Move codebase to 7-Zip (not p7zip) upstream 25.01, fixes: - CVE-2022-47069: heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd - CVE-2023-31102: Ppmd7.c allows an integer underflow and invalid read operation via a crafted 7Z archive. - CVE-2023-40481: SquashFS File Parsing Out-Of-Bounds Write RCE - CVE-2023-52168: heap-based buffer overflow in NTFS handler - CVE-2023-52169: out-of-bounds read in NTFS handler - CVE-2024-11612: CopyCoder Infinite Loop Denial-of-Service - CVE-2025-11001: ZIP File Parsing Directory Traversal RCE - CVE-2025-11002: ZIP File Parsing Directory Traversal RCE - CVE-2025-53817: null pointer dereference in the Compound handler may lead to denial of service - CVE-2025-55188: does not always properly handle symbolic links during extraction. (Closes: #1111068) * Add NEWS entry and edit package description about the codebase change. * Drop assembly support, which would require asmc-linux, not present before trixie, or re-porting the ASM code to yasm as p7zip did. * Make 7-Zip behave like p7zip to avoid compatibility issues: - d/p/p7zip-compat-version-output.patch: mimic p7zip output - d/p/p7zip-compat-symlinks.patch: mimic symlinks handling - d/p/p7zip-compat-utf16.patch: mimic -[no-]utf16 options * Sync patches from 25.01+dfsg-1~deb13u1: - drop all old patches - drop new patches: - 000*-Use-c-flags-for-asmc.patch (no ASM) - 000*-Add-fpic-for-Asmc-options.patch (no ASM) - 000*-Use-system-locale-to-select-codepage-for-legacy-zip-.patch (behavior change) * Selectively import packaging from trixie, to avoid disruption in stable release: - Sync debian/copyright. - Import debian/rules, drop ASM rules, adapt p7zip.install and p7zip-full.install, add dependency to dh-exec for *.install rename support (as in the 7zip package). - Adjust d/p7zip-full.docs, drop d/p7zip-full.doc-base and d/p7zip-full.links (no more HTML documentation). - Import debian/man/ from trixie (except for 7zz.1), merge d/p7zip.1 to debian/man/ (same file), make 7zr.1 the primary file (as it's the only one in the p7zip base package / !full). - Import debian/test/ (except for 7zz tests). - Drop debian/format/ options. * Stub debian/watch (reuse 7zip tarball instead). * Enable Salsa CI. * Configure git-buildpackage for oldstable. Checksums-Sha1: d82c4185dd1e7914029dcc725ec4a06347d67091 2026 p7zip_16.02+really25.01+dfsg-0+deb12u1.dsc 60dae021cb41e62d50e1e43a20adf9c18d45250f 1529512 p7zip_16.02+really25.01+dfsg.orig.tar.xz d8a2352816f82f42784b9907e6a6c05cc8be04f0 21152 p7zip_16.02+really25.01+dfsg-0+deb12u1.debian.tar.xz 962616f9a296c0da79e0dee425121d4e10fe2016 6379 p7zip_16.02+really25.01+dfsg-0+deb12u1_source.buildinfo Checksums-Sha256: ccba7114e9818faaa6ec2d6caa796d28c6bfb6cf596623d2ba05bbecf8863ff1 2026 p7zip_16.02+really25.01+dfsg-0+deb12u1.dsc 077c424cd50001e2be8847892522bc83e807e0b9448af1b69512c03d769c88ef 1529512 p7zip_16.02+really25.01+dfsg.orig.tar.xz e708ea7deb0ad9658fc4e628c2e2a57abf60ce41cb41de4f0b1e869eb8cb9336 21152 p7zip_16.02+really25.01+dfsg-0+deb12u1.debian.tar.xz aa3b143419580036d9a5e028d956dadb11e65003242c2f9da82e4f42fa7e95cf 6379 p7zip_16.02+really25.01+dfsg-0+deb12u1_source.buildinfo Files: fb005342de3fa85156b99f5b0cbbc36b 2026 utils optional p7zip_16.02+really25.01+dfsg-0+deb12u1.dsc 0ef56a0d775ad6eda416d5861a56a2a7 1529512 utils optional p7zip_16.02+really25.01+dfsg.orig.tar.xz 8ba9915f5956d9146f81c5fff6889e14 21152 utils optional p7zip_16.02+really25.01+dfsg-0+deb12u1.debian.tar.xz d2d73361a248c0dcc0415d13df1658e9 6379 utils optional p7zip_16.02+really25.01+dfsg-0+deb12u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmnZ7TUACgkQDTl9HeUl XjAFLBAAtS/vrLF4+Vb2Km0ESCpcFp5sfN/nY/HTDREnD/FWIM3E6sR1jJSvxEwc UktOFmKsD54vG7A2gUvK9Gr+tWdVe1zo0vGih/zN2HIhOcUJcaqpH1ny9eS6ePi9 c8GQpU7tqYwUBRJQS4dEnPhpZmrS9LF2CIXy8R4lakz43hXrsLqtPb5SndRpcvcW gozxHvE9l0mRIeYwOtO6eH2JNIf8GWqKSZ2/lEFETL0G/pSkMd3zXqybCEFC0Y2E SymtfO5TzTfxA8TElGpaNQGJt/gCLvrPolggckLE6sxDLfB7OhNA8Fz7jP3J/Vbd t4O0WFCKNWGu3F6zX6H9VD5j4c9n/voxEmJaj085y6uYYi+psyxJf5nRK7gFHHlS t5bNSxG7+8pRPoGF8UrZLydZFVlCKjw3yg58tmT6Sl6OEPajEuwD9zz0pCAWjkZc AJPpsmryAQNEA8vKCWPD62P2TdHX6Mk67BfxAPaVXsF+zICrg4OmdDDxRZftd0LD aANGGwXhNHvRKB4dKtdk1wvnuQxbUsx6sPiw4Hqi/XiTsMS3EJvuort8ZUEBgUjZ 5XNqi5D6uztYbKJZVUWXdo2Ys2chXEZgURpM0uOkxIqXksu+rDZop5NaCPIsfrsA R0tjfGIG7FQb7YMqBaJiHR3b8gKnKuVdbzM6HZ93lEWDY5XXAhg= =kr2i -----END PGP SIGNATURE-----