angular.js (1.8.3-3) unstable; urgency=medium . * Team upload * Multi-Arch foreign angular.js (1.8.3-2) unstable; urgency=medium . * Team upload * Move to js team umbrella * Fix CVE-2022-25844 (Closes: #1014779) A Regular Expression Denial of Service vulnerability (ReDoS) was found by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value * Fix CVE-2023-26116 (Closes: #1036694) A Regular Expression Denial of Service (ReDoS) was found via the angular.copy() utility function due to the usage of an insecure regular expression. * Fix CVE-2023-26117: A Regular Expression Denial of Service (ReDoS) was found via the $resource service due to the usage of an insecure regular expression. * Fix CVE-2023-26118: A Regular Expression Denial of Service (ReDoS) was found via the element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking. * Fix CVE-2024-8372: (Closes: #1088804) Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing * Fix CVE-2024-8373: (Closes: #1088805) Improper sanitization of the value of the [srcset] attribute in HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing * Fix CVE-2024-21490: A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. * Fix CVE-2025-0716: (Closes: #1104485) Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing . * Fix CVE-2025-2336: An improper sanitization vulnerability has been identified in ngSanitize module, which allows attackers to bypass common image source restrictions normally applied to image elements. This bypass can further lead to a form of Content Spoofing. Similarly, the application's performance and behavior could be negatively affected by using too large or slow-to-load images. openssh (1:10.0p1-6) unstable; urgency=medium . * Temporarily divert /usr/sbin/sshd during upgrades from before 1:9.8p1-1~, to avoid new connections failing between unpack and configure (closes: #1109742). qtcreator (16.0.1-2) unstable; urgency=medium . * Team upload. * Update changelog with a better wording