- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3862-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                          Adrian Bunk
September 02, 2024                            https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : calibre
Version        : 5.12.0+dfsg-1+deb11u3
CVE ID         : CVE-2021-44686 CVE-2023-46303
Debian Bug     : 

Two vulnerabilities have been fixed in the e-book manager Calibre.

CVE-2021-44686

    Regular Expression Denial of Service

CVE-2023-46303

    HTML Input: Don't add resources that exist outside the document root 
    by default

For Debian 11 bullseye, these problems have been fixed in version
5.12.0+dfsg-1+deb11u3.

We recommend that you upgrade your calibre packages.

For the detailed security status of calibre please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/calibre

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-3862-1: calibre Security Advisory Updates

September 2, 2024
Two vulnerabilities have been fixed in the e-book manager Calibre

Summary

CVE-2021-44686

Regular Expression Denial of Service

CVE-2023-46303

HTML Input: Don't add resources that exist outside the document root
by default

For Debian 11 bullseye, these problems have been fixed in version
5.12.0+dfsg-1+deb11u3.

We recommend that you upgrade your calibre packages.

For the detailed security status of calibre please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/calibre

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : calibre
Version : 5.12.0+dfsg-1+deb11u3
CVE ID : CVE-2021-44686 CVE-2023-46303
Debian Bug :

Related News