Source: ippsample Version: 0.0.0~git20220215.f365352-2 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for ippsample. CVE-2026-77220[0]: | PDFio before 1.6.5 contains a dangling pointer vulnerability in the | dictionary string-formatting function that stores a pointer to a | stack-local buffer in the document dictionary without copying the | string value. In multi-threaded or pooled-request environments, | attackers or concurrent users can trigger stack memory reuse across | requests, causing cross-tenant document content corruption by | silently overwriting one caller's dictionary string values with | another caller's data. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-77220 https://www.cve.org/CVERecord?id=CVE-2026-77220 [1] https://github.com/michaelrsweet/pdfio/commit/22b9afc800c5833f9e851e35938972bd4c76a357 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

