There are 3 open security issues in bookworm.
3 issues left for the package maintainer to handle:
- CVE-2024-2002:
(needs triaging)
A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results.
- CVE-2022-32200:
(needs triaging)
libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c.
- CVE-2022-34299:
(needs triaging)
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
You can find information about how to handle these issues in the security team's documentation.