Version in base suite: 0.34-3 Base version: libfile-find-rule-perl_0.34-3 Target version: libfile-find-rule-perl_0.34-4~deb12u1 Base file: /srv/ftp-master.debian.org/ftp/pool/main/libf/libfile-find-rule-perl/libfile-find-rule-perl_0.34-3.dsc Target file: /srv/ftp-master.debian.org/policy/pool/main/libf/libfile-find-rule-perl/libfile-find-rule-perl_0.34-4~deb12u1.dsc changelog | 13 +++++ patches/Fix-for-CVE-2011-10007-Use-3-arg-open-in-grep.patch | 29 ++++++++++++ patches/series | 1 3 files changed, 43 insertions(+) diff -Nru libfile-find-rule-perl-0.34/debian/changelog libfile-find-rule-perl-0.34/debian/changelog --- libfile-find-rule-perl-0.34/debian/changelog 2022-11-19 16:06:52.000000000 +0000 +++ libfile-find-rule-perl-0.34/debian/changelog 2025-06-05 12:32:51.000000000 +0000 @@ -1,3 +1,16 @@ +libfile-find-rule-perl (0.34-4~deb12u1) bookworm-security; urgency=high + + * Rebuild for bookworm-security. + + -- Salvatore Bonaccorso Thu, 05 Jun 2025 14:32:51 +0200 + +libfile-find-rule-perl (0.34-4) unstable; urgency=high + + * Team upload. + * Fix for CVE-2011-10007: Use 3 arg open in grep() (Closes: #1107311) + + -- Salvatore Bonaccorso Thu, 05 Jun 2025 14:26:45 +0200 + libfile-find-rule-perl (0.34-3) unstable; urgency=medium [ Debian Janitor ] diff -Nru libfile-find-rule-perl-0.34/debian/patches/Fix-for-CVE-2011-10007-Use-3-arg-open-in-grep.patch libfile-find-rule-perl-0.34/debian/patches/Fix-for-CVE-2011-10007-Use-3-arg-open-in-grep.patch --- libfile-find-rule-perl-0.34/debian/patches/Fix-for-CVE-2011-10007-Use-3-arg-open-in-grep.patch 1970-01-01 00:00:00.000000000 +0000 +++ libfile-find-rule-perl-0.34/debian/patches/Fix-for-CVE-2011-10007-Use-3-arg-open-in-grep.patch 2025-06-05 12:32:51.000000000 +0000 @@ -0,0 +1,29 @@ +From: Stig Palmquist +Date: Thu, 5 Jun 2025 12:58:45 +0200 +Subject: Fix for CVE-2011-10007: Use 3 arg open in grep()` +Origin: https://github.com/richardc/perl-file-find-rule/commit/df58128bcee4c1da78c34d7f3fe1357e575ad56f +Bug: https://rt.cpan.org/Public/Bug/Display.html?id=64504 +Bug-Debian: https://bugs.debian.org/1107311 +Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2011-10007 +Bug: https://github.com/richardc/perl-file-find-rule/pull/4 + +--- + lib/File/Find/Rule.pm | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/lib/File/Find/Rule.pm b/lib/File/Find/Rule.pm +index feccc76f9fcb..d4dc4754d309 100644 +--- a/lib/File/Find/Rule.pm ++++ b/lib/File/Find/Rule.pm +@@ -420,7 +420,7 @@ sub grep { + + $self->exec( sub { + local *FILE; +- open FILE, $_ or return; ++ open FILE, '<', $_ or return; + local ($_, $.); + while () { + for my $p (@pattern) { +-- +2.49.0 + diff -Nru libfile-find-rule-perl-0.34/debian/patches/series libfile-find-rule-perl-0.34/debian/patches/series --- libfile-find-rule-perl-0.34/debian/patches/series 2022-11-19 16:06:52.000000000 +0000 +++ libfile-find-rule-perl-0.34/debian/patches/series 2025-06-05 12:32:51.000000000 +0000 @@ -1 +1,2 @@ sequential_slashes.patch +Fix-for-CVE-2011-10007-Use-3-arg-open-in-grep.patch