-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 01 Apr 2026 08:53:55 +0200 Source: p7zip-rar Architecture: source Version: 16.02+really25.00+ds-0+deb12u1 Distribution: bookworm Urgency: high Maintainer: Robert Luberda Changed-By: Sylvain Beucler Closes: 1109494 Changes: p7zip-rar (16.02+really25.00+ds-0+deb12u1) bookworm; urgency=high . * Non-maintainer upload by the LTS Security Team. * Move codebase to 7-Zip (not p7zip) upstream 25.00, fixes: - CVE-2025-53816: Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service. (Closes: #1109494) * Edit package description about the codebase change. * Drop yasm dependencies, ASM not enabled anymore in p7zip. * Import patches from 25.00+ds-1+deb13u1. * Selectively import packaging from trixie, to avoid disruption in stable release: - Bump p7zip-full dependency. - Sync debian/copyright. - Import debian/rules and 7zip-rar.install. - Import debian/test/. - Drop debian/format/ options. * Stub debian/watch (reuse 7zip-rar tarball instead). * Enable Salsa CI. * Configure git-buildpackage for oldstable. Checksums-Sha1: 76989376d01baf331f5964d0ce5993ee145576af 2013 p7zip-rar_16.02+really25.00+ds-0+deb12u1.dsc 88d68e8c63d705485758a6aef5875bde80131583 1709113 p7zip-rar_16.02+really25.00+ds.orig.tar.bz2 7eeb95ff2b72984cac710e8e84016a368aca412d 8312 p7zip-rar_16.02+really25.00+ds-0+deb12u1.debian.tar.xz fa3d90021892aca6597f4522878f5c2098e461bf 6368 p7zip-rar_16.02+really25.00+ds-0+deb12u1_source.buildinfo Checksums-Sha256: 3a3909768d0c5625abcec7f4fbe44c3f4f9eb200974a17fe6c655e52c96c801c 2013 p7zip-rar_16.02+really25.00+ds-0+deb12u1.dsc 28405dc2d0ab12531b71fac680cc8e5bb5e16763a22993d73efa153f235affb8 1709113 p7zip-rar_16.02+really25.00+ds.orig.tar.bz2 9eba76cc01bd052c24a40728d0fcfeeaad2b41738022d75b77fe58d6294abf0c 8312 p7zip-rar_16.02+really25.00+ds-0+deb12u1.debian.tar.xz cd0259799f602ec8361bf6bac3de528feea5e48f676b687564318473309ed3c3 6368 p7zip-rar_16.02+really25.00+ds-0+deb12u1_source.buildinfo Files: ff578f75f753a8724910a8dec272ec5c 2013 non-free/utils optional p7zip-rar_16.02+really25.00+ds-0+deb12u1.dsc 65fc6eed8e787ad772615787c200ca4f 1709113 non-free/utils optional p7zip-rar_16.02+really25.00+ds.orig.tar.bz2 6e0f79880215f3eb019f63f184a76d0a 8312 non-free/utils optional p7zip-rar_16.02+really25.00+ds-0+deb12u1.debian.tar.xz 7816018f4271f2c122575e088a67c29f 6368 non-free/utils optional p7zip-rar_16.02+really25.00+ds-0+deb12u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmnZ9IIACgkQDTl9HeUl XjCKihAAtviC+NQaVlWPOakZZpwSwwanslCDrHOHHVlf2APgqz9PREl96GoyVuGo rwPf+JT1r32JGmjrwN2wcFRAxDMofTl/glZEOHLS8XaNrf3q0USYc7BhaMNP5q7z etwSuXxolHypuUYK3sZLEHWHFncjJzpRJwCwDvZFHCHjZnE7MRjuYNgj1/qGQEHb gzZQTuJ3/IERknilV5Oo5UJou3Oqi6PcUK40yaD6qlW7zQnYbOUhX+gSUbxhdBDd hY0MD2VZN21EvIzr4q/i+kKp+uMzicTDhQWvCepS5Z1sCSDz7jQdk/QZGu5mpFEt GIZe8D7B2YKYClZHy7W81oltPCEbtZOUXOwZClE5RCZ7yi3GcCHWj8GugJDh9dpN b9+7kBOgoZgORFWQ90HOtPZ1+cvtFnL3mxkhkFeI3xFzbHFtFy86vwD4pogscwrU Vtr2Q9HebY5zfvQxv6DCQRy6uLI7n+QOGJEVSONs5kLf9Rca+bMrjw94zRzKrS6E Ao2fyrK9siGbJYnGC0RKwY9zPuvX3UQfZAihOLuizQ8gT0rdJmO40Af2Lgi6dty8 +kVhzAurs4svTTfkxeSTKqyxGSR+B54mqHvzGEDKfAyl/lnIeDES6/ikQddeG/8y r0BxpKrbJQSWzZF4y6eySeOdKjAqTv0pY2H7RWXgqTwD3yOEL88= =EFeC -----END PGP SIGNATURE-----