Skip to content

Conversation

@jlsec-bot
Copy link
Contributor

This action searched recent NVD/EUVD changes/publications, checking 2146 (+2) advisories from NVD and 355 (+1831) from EUVD for advisories that pertain here. It identified 9 advisories as being related to the Julia package(s): Git_jll, LibVPX_jll, ImageMagick_jll, Poppler_jll, libwebp_jll, LibArchive_jll, nghttp2_jll, and libnode_jll.

1 advisories apply to all registered versions of a package

These advisories had no obvious failures but computed a range without bounds.

  • CVE-2023-5217 for packages: LibVPX_jll
    • LibVPX_jll computed ["*"]. Its latest version (1.15.2+0) has components: {libvpx = "*"}
      • webmproject:libvpx at < 1.13.1 includes all versions

1 advisories apply to the latest version of a package and do not have a patch

  • CVE-2023-44487 for packages: nghttp2_jll, and libnode_jll
    • nghttp2_jll computed ["< 1.58.0+0"]. Its latest version (1.67.1+0) has components: {nghttp2 = "1.67.1", nghttp2-libs = "*"}
    • libnode_jll computed [">= 18.12.1+0"]. Its latest version (18.12.1+0) has components: {node-v = "18.12.1", nodejs = "18.12.1"}
      • nodejs:node.js at >= 18.0.0, < 18.18.2 mapped to [>= 18.12.1+0], includes the latest version`

7 advisories found concrete vulnerable ranges

  • CVE-2016-3714 for packages: ImageMagick_jll
    • ImageMagick_jll computed ["< 6.9.11+0"]. Its latest version (7.1.2005+0) has components: {imagemagick = "7.1.2-3"}
  • CVE-2016-3715 for packages: ImageMagick_jll
    • ImageMagick_jll computed ["< 6.9.11+0"]. Its latest version (7.1.2005+0) has components: {imagemagick = "7.1.2-3"}
  • CVE-2016-3718 for packages: ImageMagick_jll
    • ImageMagick_jll computed ["< 6.9.11+0"]. Its latest version (7.1.2005+0) has components: {imagemagick = "7.1.2-3"}
  • CVE-2021-30860 for packages: Poppler_jll
    • Poppler_jll computed ["< 23.12.0+0"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
  • CVE-2023-4863 for packages: libwebp_jll
    • libwebp_jll computed ["< 1.3.2+0"]. Its latest version (1.6.0+0) has components: {libwebp = "1.6.0"}
  • CVE-2025-48384 for packages: Git_jll
    • Git_jll computed ["< 2.50.1+0"]. Its latest version (2.51.1+0) has components: {git-for-windows = "2.51.0.windows.1", git = "2.51.0"}
  • CVE-2025-5914 for packages: LibArchive_jll
    • LibArchive_jll computed ["< 3.8.0+0"]. Its latest version (3.8.2+0) has components: {libarchive = "3.8.2"}

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants