Rebase patches and bump version to 12.3.0. This also addresses
CVE-2023-20867 and CVE-2023-20900.
Furthermore it makes the patch for CVE-2022-31676 obsolete.
Make sure that pkg-stats doesn't show any CVEs. There were two false
positives which are now in the ignore list.
Signed-off-by: Stefan Agner <stefan@agner.ch>
(cherry picked from commit a3dced0daf)
Signed-off-by: Jan Čermák <sairon@sairon.cz>