Debian Package Tracker
Register | Log in
Subscribe

librest

Choose email to subscribe with

general
  • source: librest (main)
  • version: 0.10.2-1
  • maintainer: Debian GNOME Maintainers (archive) (DMD)
  • uploaders: Ying-Chun Liu (PaulLiu) [DMD] – Jeremy Bícha [DMD]
  • arch: all any
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 0.8.1-1.1
  • oldstable: 0.9.1-6
  • stable: 0.9.1-6
  • testing: 0.10.2-1
  • unstable: 0.10.2-1
versioned links
  • 0.8.1-1.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.9.1-6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.10.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • gir1.2-rest-1.0
  • gir1.2-restextras-1.0
  • librest-1.0-0
  • librest-dev
  • librest-doc
  • librest-extras-1.0-0
  • librest-extras-dev
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-16615: A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.
Created: 2026-07-23 Last update: 2026-07-24 18:01
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-16615: A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.
Created: 2026-07-23 Last update: 2026-07-24 18:01
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-16615: A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.
Created: 2026-07-23 Last update: 2026-07-24 18:01
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-16615: A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.
Created: 2026-07-23 Last update: 2026-07-24 18:01
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-16615: A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.
Created: 2026-07-23 Last update: 2026-07-24 18:01
debian/patches: 1 patch to forward upstream low

Among the 1 debian patch available in version 0.10.2-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2025-09-06 11:32
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.2).
Created: 2025-12-23 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2025-09-11] librest 0.10.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-05] Accepted librest 0.10.2-1 (source) into unstable (Jeremy Bícha)
  • [2023-04-20] librest 0.9.1-6 MIGRATED to testing (Debian testing watch)
  • [2023-03-30] Accepted librest 0.9.1-6 (source) into unstable (Jeremy Bicha)
  • [2023-03-16] Accepted librest 0.9.1-5 (source) into unstable (Laurent Bigonville)
  • [2022-11-27] librest 0.9.1-4 MIGRATED to testing (Debian testing watch)
  • [2022-11-22] Accepted librest 0.9.1-4 (source) into unstable (Sebastien Bacher)
  • [2022-10-24] librest 0.9.1-3 MIGRATED to testing (Debian testing watch)
  • [2022-10-13] Accepted librest 0.9.1-3 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2022-09-11] librest 0.9.1-2 MIGRATED to testing (Debian testing watch)
  • [2022-09-05] Accepted librest 0.9.1-2 (source) into unstable (Jeremy Bicha)
  • [2022-08-16] Removed 1.0.0-1 from experimental (Debian FTP Masters)
  • [2022-01-17] Accepted librest 1.0.0-1 (source amd64 all) into experimental, experimental (Debian FTP Masters) (signed by: Ying-Chun Liu)
  • [2020-12-24] librest 0.8.1-1.1 MIGRATED to testing (Debian testing watch)
  • [2020-12-18] Accepted librest 0.8.1-1.1 (source) into unstable (Holger Levsen)
  • [2018-10-24] librest 0.8.1-1 MIGRATED to testing (Debian testing watch)
  • [2018-10-14] Accepted librest 0.8.1-1 (source amd64 all) into unstable, unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2016-11-04] librest 0.8.0-2 MIGRATED to testing (Debian testing watch)
  • [2016-10-24] Accepted librest 0.8.0-2 (source amd64 all) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2016-05-24] librest 0.8.0-1 MIGRATED to testing (Debian testing watch)
  • [2016-05-13] Accepted librest 0.8.0-1 (source amd64 all) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2015-05-13] librest 0.7.93-1 MIGRATED to testing (Britney)
  • [2015-05-02] Accepted librest 0.7.93-1 (source amd64 all) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2015-03-12] librest 0.7.92-3 MIGRATED to testing (Britney)
  • [2015-03-09] Accepted librest 0.7.92-3 (source i386 all) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2014-10-29] librest 0.7.92-2 MIGRATED to testing (Britney)
  • [2014-10-23] Accepted librest 0.7.92-2 (source i386 all) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2014-09-18] librest 0.7.92-1 MIGRATED to testing (Britney)
  • [2014-09-08] Accepted librest 0.7.92-1 (source i386 all) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2014-03-18] Accepted librest 0.7.91-1 (source i386 all) (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.10.2-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing