Bug#1084787: libzip-dev: CVE in libzip

2024-10-08 Thread Mariam Arutunian
Sorry, I mixed up the versions. Thanks, Mariam On Tue, Oct 8, 2024 at 1:17 PM Thomas Klausner wrote: > While I support the notion that the libzip package should be updated, that > bug got fixed in 1.3.0, so 1.7.3 is safe. > Thomas >

Bug#1084787: libzip-dev: CVE in libzip

2024-10-08 Thread Thomas Klausner
While I support the notion that the libzip package should be updated, that bug got fixed in 1.3.0, so 1.7.3 is safe. Thomas

Bug#1084787: libzip-dev: CVE in libzip

2024-10-08 Thread Mariam Arutunian
Package: libzip-dev Version: 1.7.3 Severity: important X-Debbugs-Cc: mariamarutun...@gmail.com Dear Maintainer, there is a CVE (CVE-2019-17582) in this version of libzip that is fixed in newer version with the following commit: https://github.com/nih-at/libzip/commit/2217022b7d1142738656d891e00b3