mpd (0.24.12-1)
[PTS] [DDPO]
OK: VCS matches the version in the archive
- Git: https://salsa.debian.org/mpd-team/mpd.git
-
- Branch: master
- Path: debian/changelog
- Repo size: 995328
- Browser: https://salsa.debian.org/mpd-team/mpd
- Last scan: 2026-07-15 03:45:10+00
- Next scan: 2026-07-20 08:54:00+00
- Merge requests: 1
- CI pipeline status: success
- Debian changelog in Git:
mpd (0.24.12-1) unstable; urgency=medium
* New upstream version 0.24.12 (closes: #1138215)
+ fixes a stack buffer overflow vulnerability in the pcm_unpack_24be
function in src/pcm/Pack.cxx (CVE-2026-49127)
+ fixes a path traversal vulnerability in LocalStorage::MapFSOrThrow and
LocalStorage::MapUTF8 within the local storage plugin (CVE-2026-49128)
+ fixes a server-side request forgery vulnerability in CurlInputPlugin
(CVE-2026-49129)
+ fixes a CRLF injection vulnerability in the xspf_char_data function
within the XSPF playlist plugin (CVE-2026-49130)
* Add new files to d/copyright
* d/copyright: fix lintian warning about old FSF postal address
* Bump libcurl dependency to 7.85
* Declare compliance with Debian Policy 4.7.4
-- Florian Schlichting <fsfs@debian.org> Mon, 01 Jun 2026 22:42:36 +0200
- This branch is even with tag debian/0.24.12-1