This bug was fixed in the package mlt - 7.36.1-1ubuntu3.1
---------------
mlt (7.36.1-1ubuntu3.1) resolute-security; urgency=medium
* SECURITY UPDATE: Fix code path exposing Kdenlive. (LP: #2168441)
- debian/patches/CVE-2026-45184.patch: Fix time formatting overflow
and disable ante/post by default.
- CVE-2026-45184
-- Rik Mills <[email protected]> Thu, 24 Sep 2026 15:33:18 +0100
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168441
Title:
Kdenlive: Remote code execution via malicious project file
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/kdenlive/+bug/2168441/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs