tracker.debian.org

2 security issues in sid high

There are 2 open security issues in sid.

2 important issues:

  • CVE-2017-7475: Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.
  • CVE-2025-50422: Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.

Created: 2022-07-04 Last update: 2026-08-02 20:32

2 security issues in forky high

There are 2 open security issues in forky.

2 important issues:

  • CVE-2017-7475: Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.
  • CVE-2025-50422: Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.

Created: 2025-08-09 Last update: 2026-08-02 20:32

3 bugs tagged patch in the BTS normal

Created: 2026-08-15 Last update: 2026-08-31 21:00

lintian reports 1 warning normal

Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.

Created: 2026-02-28 Last update: 2026-02-28 11:00

2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

1 issue left for the package maintainer to handle:

  • CVE-2025-50422: (postponed; to be fixed through a stable update) Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.

You can find information about how to handle this issue in the security team's documentation.

1 ignored issue:

  • CVE-2017-7475: Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.

Created: 2023-06-11 Last update: 2026-08-02 20:32

Standards version of the package is outdated. wishlist

The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.3).

Created: 2026-03-31 Last update: 2026-03-31 15:01

Read the original on tracker.debian.org ↗