Bug#1085137: libxen: Libxen Includes Code Similar to LZO Decompressor with a Known CVE

2024-10-15 Thread Mariam Arutunian
Package: libxen Version: 4.17.3 Severity: normal X-Debbugs-Cc: mariamarutun...@gmail.com Dear Maintainer, A vulnerability identified as CVE-2014-4608 was discovered and fixed in LZO decompressor in the Linux kernel with the following commit: https://github.com/torvalds/linux/commit/206a81c18401c

Bug#1084873: libxine2: Outdated libfaad sources in the project

2024-10-10 Thread Mariam Arutunian
Package: libxine2 Version: 1.2.13 Severity: normal X-Debbugs-Cc: mariamarutun...@gmail.com Dear Maintainer, A vulnerability identified as CVE-2019-15296 was discovered and fixed in the FAAD2 project with the following commit: https://github.com/knik0/faad2/commit/942c3e0aee748ea6fe97cb2c1aa58932

Bug#1084825: zchunk: CVE in zchunk

2024-10-09 Thread Mariam Arutunian
Package: zchunk Version: 1.2.3 Severity: important X-Debbugs-Cc: mariamarutun...@gmail.com Dear Maintainer, zchunk contains a CVE (CVE-2023-46228) which is fixed in the 1.3.2 version with the following commit: https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe. Coul

Bug#1084787: libzip-dev: CVE in libzip

2024-10-08 Thread Mariam Arutunian
Sorry, I mixed up the versions. Thanks, Mariam On Tue, Oct 8, 2024 at 1:17 PM Thomas Klausner wrote: > While I support the notion that the libzip package should be updated, that > bug got fixed in 1.3.0, so 1.7.3 is safe. > Thomas >

Bug#1084787: libzip-dev: CVE in libzip

2024-10-08 Thread Mariam Arutunian
Package: libzip-dev Version: 1.7.3 Severity: important X-Debbugs-Cc: mariamarutun...@gmail.com Dear Maintainer, there is a CVE (CVE-2019-17582) in this version of libzip that is fixed in newer version with the following commit: https://github.com/nih-at/libzip/commit/2217022b7d1142738656d891e00b3

Bug#1084524: lifelines: Lifeline contains a code associated with CVE.

2024-10-07 Thread Mariam Arutunian
Package: lifelines Version: 3.0.61 (latest) Severity: important X-Debbugs-Cc: mariamarutun...@gmail.com Dear Maintainer, A vulnerability identified as CVE-2018-21027 was discovered and fixed in Boa project with the following commit: https://github.com/gpg/boa/pull/1/commits/e139b87835994d007fbd

Bug#1036970: 0ad: third party library (mbedtls) needs to be updated

2023-05-31 Thread Mariam Arutunian
Package: 0ad Version: 0.0.26-3 Severity: normal X-Debbugs-Cc: mariamarutun...@gmail.com Dear Maintainer, The project mbedtsl which is used in 0ad project (path 0ad/build/premake/premake5/contrib/mbedtls) contains vulnerability (CVE-2019-16910, CVE-2017-14032). The vulnerability is fixed in newe