DFSG NEW Queue

DFSG, Licensing & New Packages Team

Review: opencolorio 2.5.1+dfsg-1

New Package Report

.changes
Changed-ByMatteo F. Vescovi
Architecturesource amd64
Distributionexperimental
DateSat, 14 Feb 2026 17:26:26 +0100
Sourceopencolorio
Version2.5.1+dfsg-1
Changelog
opencolorio (2.5.1+dfsg-1) experimental; urgency=medium
 .
   [ Matteo F. Vescovi ]
   * New upstream release (Closes: #1125416)
     This release addresses CVE-2025-15506:
     | A vulnerability was found in AcademySoftwareFoundation OpenColorIO
     | up to 2.5.0. This issue affects the function
     | ConvertToRegularExpression of the file
     | src/OpenColorIO/FileRules.cpp. Performing a manipulation results in
     | out-of-bounds read. The attack needs to be approached locally. The
     | exploit has been made public and could be used.
   * debian/: SONAME bump 2.1 -> 2.5
   * debian/control:
     - b-dep switch pkg-config -> pkgconf
     - libminizip-ng-dev b-dep added
     - strict versioning for pystring added
     - S-V bump 4.6.1 -> 4.7.3 (no changes needed)
     - Priority field dropped (obsolete)
     - RRR field dropped (obsolete)
   * debian/watch: v4 -> v5 switch
   * debian/python3-pyopencolorio.install: path fixed
   * debian/libopencolorio2.5.lintian-overrides: file dropped (useless)
 .
   [ Jordan Justen ]
   * d/patches: Update patches for v2.5.1
   * d/rules: Stop deleting Findyaml-cpp.cmake.
     Ref: c075bff0 ("Import Debian changes 2.1.2+dfsg1-4.1")
.dsc
Sectionlibdevel
Priorityoptional
Componentmain
Package-Listlibopencolorio-dev deb libdevel optional arch=any
libopencolorio2.5 deb libs optional arch=any
opencolorio-tools deb utils optional arch=any
python3-pyopencolorio deb python optional arch=any
debian/copyright
Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Upstream-Name: opencolorio
Source: https://github.com/AcademySoftwareFoundation/OpenColorIO
Files-Excluded:
 .appveyor.yml
 .github
 .gitattributes
 .gitignore
 .nojekyll

Files: *
Copyright: 2003-2010 Sony Pictures Imageworks Inc., et al.
           2019, Contributors to the OpenColorIO Project
License: BSD-3-Clause

Files: debian/*
Copyright: 2013-2022 Matteo F. Vescovi <mfv@debian.org>
License: BSD-3-Clause

Files: docs/site/static/*
Copyright: 2008-2009, Haiku.
License: MIT
 Permission is hereby granted, free of charge, to any person obtaining
 a copy of this software and associated documentation files (the
 "Software"), to deal in the Software without restriction, including
 without limitation the rights to use, copy, modify, merge, publish,
 distribute, sublicense, and/or sell copies of the Software, and to
 permit persons to whom the Software is furnished to do so, subject to
 the following conditions:
 .
 The above copyright notice and this permission notice shall be
 included in all copies or substantial portions of the Software.
 .
 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
 EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
 MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
 NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
 LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
 OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
 WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

License: BSD-3-Clause
 Redistribution and use in source and binary forms, with or without
 modification, are permitted provided that the following conditions
 are met:
 1. Redistributions of source code must retain the above copyright
    notice, this list of conditions and the following disclaimer.
 2. Redistributions in binary form must reproduce the above copyright
    notice, this list of conditions and the following disclaimer in the
    documentation and/or other materials provided with the distribution.
 3. Neither the name of the University nor the names of its contributors
    may be used to endorse or promote products derived from this software
    without specific prior written permission.
 .
 THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
 ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
 ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
 FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
 DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
 OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
 HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
 LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
 OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
 SUCH DAMAGE.

Review Information

accepted — allocated to awm 8 days ago, started 8 days ago, completed 8 days ago.

Final Comment

The package is accepted, but the debian/copyright should be adjust to reflect the
different licensing (mainly CC-BY-4.0) of several files. See the review for the full
list found by licenserecon.

Thanks!

Public Notes

8 days ago ● public

Licenserecon

Command: lrc -s
Exit code: 3

en: Versions: licenserecon '11.0'  licensecheck '3.3.9-1'

Parsing Source Tree  ....
Reading d/copyright  ....
Running licensecheck ....

d/copyright      | licensecheck

BSD-3-Clause     | CC-BY-4.0         ASWF/Charter.md
BSD-3-Clause     | BSD-3-clause and/or CC-BY-4.0 ASWF/CLA-corporate.md
BSD-3-Clause     | CC-BY-4.0         ASWF/DCO.md
BSD-3-Clause     | BSD-3-clause and/or CC-BY-4.0 docs/aswf/license.rst
BSD-3-Clause     | CC-BY-4.0         docs/concepts/_index.rst
BSD-3-Clause     | BSD-3-clause and/or CC-BY-4.0 docs/guides/contributing/coding_style_guide.rst
BSD-3-Clause     | CC-BY-4.0         docs/guides/contributing/contributing.rst
BSD-3-Clause     | BSD-2-clause      ext/xxHash/src/include/xxhash.h
BSD-3-Clause     | CC-BY-4.0         GOVERNANCE.md

Short option in use. Not all differences shown

Back to Dashboard | View all reviews for this package