There are 2 open security issues in bookworm.
2 issues left for the package maintainer to handle:
- CVE-2021-33464:
(postponed; to be fixed through a stable update)
An issue was discovered in yasm version 1.3.0. There is a heap-buffer-overflow in inc_fopen() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2023-29579:
(postponed; to be fixed through a stable update)
yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.
You can find information about how to handle these issues in the security team's documentation.