Debian Package Tracker
Register | Log in
Subscribe

olm

Choose email to subscribe with

general
  • source: olm (main)
  • version: 3.2.13~dfsg-1
  • maintainer: Matrix Packaging Team (archive) (DMD)
  • uploaders: Hubert Chathi [DMD]
  • arch: all any
  • std-ver: 4.6.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 2.2.2+git20170526.0fd768e+dfsg-1
  • old-bpo: 3.1.4~dfsg-1~bpo10+1
  • stable: 3.2.1~dfsg-7
  • stable-bpo: 3.2.11~dfsg-1~bpo11+1
  • testing: 3.2.13~dfsg-1
  • unstable: 3.2.13~dfsg-1
versioned links
  • 2.2.2+git20170526.0fd768e+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.1.4~dfsg-1~bpo10+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.2.1~dfsg-7: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.2.11~dfsg-1~bpo11+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.2.13~dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libjs-olm
  • libolm-dev
  • libolm3
  • python3-olm
action needed
A new upstream version is available: 3.2.14 high
A new upstream version 3.2.14 is available, you should consider packaging it.
Created: 2022-12-10 Last update: 2023-03-31 04:34
Depends on packages which need a new maintainer normal
The packages that olm depends on which need a new maintainer are:
  • emscripten (#1013374)
    • Build-Depends-Indep: emscripten
Created: 2022-06-23 Last update: 2023-03-31 06:04
2 low-priority security issues in bullseye low

There are 2 open security issues in bullseye.

2 issues left for the package maintainer to handle:
  • CVE-2021-34813: (needs triaging) Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations.
  • CVE-2021-44538: (needs triaging) The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to manipulate the state of the receiver's session in such a way that, for some buffer sizes, a buffer overflow happens on a call to olm_session_describe. Furthermore, safe buffer sizes were undocumented. The overflow content is partially controllable by the attacker and limited to ASCII spaces and digits. The known affected products are Element Web And SchildiChat Web.

You can find information about how to handle these issues in the security team's documentation.

Created: 2022-07-04 Last update: 2023-03-27 11:06
debian/patches: 2 patches to forward upstream low

Among the 2 debian patches available in version 3.2.13~dfsg-1 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-02-26 15:54
Build log checks report 3 warnings low
Build log checks report 3 warnings
Created: 2017-10-26 Last update: 2022-02-17 22:35
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.2 instead of 4.6.0).
Created: 2022-05-11 Last update: 2022-12-17 19:18
news
[rss feed]
  • [2022-10-20] olm 3.2.13~dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-10-15] Accepted olm 3.2.13~dfsg-1 (source) into unstable (Jochen Sprickerhof)
  • [2022-08-05] Accepted olm 3.2.11~dfsg-1~bpo11+1 (source all amd64) into bullseye-backports, bullseye-backports (Debian FTP Masters) (signed by: Hubert Chathi)
  • [2022-08-01] olm 3.2.12~dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-26] Accepted olm 3.2.12~dfsg-1 (source) into unstable (Jochen Sprickerhof)
  • [2022-04-18] olm 3.2.11~dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-04-16] Accepted olm 3.2.11~dfsg-1 (source) into unstable (Jonas Smedegaard)
  • [2022-02-23] olm 3.2.10~dfsg-6 MIGRATED to testing (Debian testing watch)
  • [2022-02-21] Accepted olm 3.2.10~dfsg-6 (source) into unstable (Jonas Smedegaard)
  • [2022-02-17] Accepted olm 3.2.10~dfsg-5 (source) into unstable (Jonas Smedegaard)
  • [2022-01-24] olm 3.2.10~dfsg-4 MIGRATED to testing (Debian testing watch)
  • [2022-01-19] Accepted olm 3.2.10~dfsg-4 (source) into unstable (Jonas Smedegaard)
  • [2022-01-19] olm 3.2.10~dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2022-01-13] Accepted olm 3.2.10~dfsg-3 (source) into unstable (Jonas Smedegaard)
  • [2022-01-13] Accepted olm 3.2.10~dfsg-2 (source) into unstable (Jonas Smedegaard)
  • [2022-01-13] Accepted olm 3.2.10~dfsg-1 (source) into unstable (Jonas Smedegaard)
  • [2021-12-16] olm 3.2.8~dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2021-12-13] Accepted olm 3.2.8~dfsg-1 (source) into unstable (Jonas Smedegaard)
  • [2021-12-13] olm 3.2.7~dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2021-12-07] Accepted olm 3.2.7~dfsg-2 (source) into unstable (Jonas Smedegaard)
  • [2021-12-07] Accepted olm 3.2.7~dfsg-1 (source) into experimental (Jonas Smedegaard)
  • [2021-09-26] olm 3.2.6~dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2021-09-21] Accepted olm 3.2.6~dfsg-2 (source) into unstable (Jonas Smedegaard)
  • [2021-09-19] Accepted olm 3.2.6~dfsg-1 (source) into experimental (Jonas Smedegaard)
  • [2021-08-29] olm 3.2.4~dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2021-08-23] Accepted olm 3.2.4~dfsg-1 (source) into unstable (Jonas Smedegaard)
  • [2021-08-23] olm 3.2.3~dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2021-08-16] Accepted olm 3.2.3~dfsg-3 (source) into unstable (Jonas Smedegaard)
  • [2021-06-17] Accepted olm 3.2.3~dfsg-2 (source) into experimental (Jonas Smedegaard)
  • [2021-05-24] Accepted olm 3.2.3~dfsg-1 (source) into experimental (Jonas Smedegaard)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 0
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, checks, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.2.13~dfsg-1ubuntu1
  • patches for 3.2.13~dfsg-1ubuntu1

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing