There are 2 open security issues in bookworm.
2 issues left for the package maintainer to handle:
- CVE-2023-33551:
(needs triaging)
Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image.
- CVE-2023-33552:
(needs triaging)
Heap Buffer Overflow in the erofs_read_one_data function at data.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image.
You can find information about how to handle these issues in the security team's documentation.