Skip to content

Conversation

jlsec-bot
Copy link
Contributor

This action searched recent NVD/EUVD changes/publications, checking 471 (+11) advisories from NVD and 5000 (+239) from EUVD for advisories that pertain here. It identified 14 advisories as being related to the Julia package(s): Exiv2_jll, Perl_jll, ImageMagick_jll, XML2_jll, and GnuTLS_jll.

12 advisories apply to all registered versions of a package

These advisories had no obvious failures but computed a range without bounds.

  • CVE-2021-34334 for packages: Exiv2_jll
    • Exiv2_jll computed ["*"]. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}
      • exiv2:exiv2 at <= 0.27.4 includes all versions
  • CVE-2021-34335 for packages: Exiv2_jll
    • Exiv2_jll computed ["*"]. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}
      • exiv2:exiv2 at <= 0.27.4 includes all versions
  • CVE-2021-37615 for packages: Exiv2_jll
    • Exiv2_jll computed ["*"]. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}
      • exiv2:exiv2 at <= 0.27.4 includes all versions
  • CVE-2021-37616 for packages: Exiv2_jll
    • Exiv2_jll computed ["*"]. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}
      • exiv2:exiv2 at <= 0.27.4 includes all versions
  • CVE-2021-37618 for packages: Exiv2_jll
    • Exiv2_jll computed ["*"]. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}
      • exiv2:exiv2 at <= 0.27.4 includes all versions
  • CVE-2021-37619 for packages: Exiv2_jll
    • Exiv2_jll computed ["*"]. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}
      • exiv2:exiv2 at <= 0.27.4 includes all versions
  • CVE-2021-37620 for packages: Exiv2_jll
    • Exiv2_jll computed ["*"]. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}
      • exiv2:exiv2 at < 0.27.5 includes all versions
  • CVE-2021-37621 for packages: Exiv2_jll
    • Exiv2_jll computed ["*"]. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}
      • exiv2:exiv2 at <= 0.27.4 includes all versions
  • CVE-2021-37622 for packages: Exiv2_jll
    • Exiv2_jll computed ["*"]. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}
      • exiv2:exiv2 at <= 0.27.4 includes all versions
  • CVE-2021-37623 for packages: Exiv2_jll
    • Exiv2_jll computed ["*"]. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}
      • exiv2:exiv2 at <= 0.27.4 includes all versions
  • CVE-2023-47038 for packages: Perl_jll
    • Perl_jll computed ["*"]. Its latest version (5.34.1+0) has components: {"perl:xml-namespacesupport" = "1.12", "perl:file-which" = "1.27", "perl:getopt-tabular" = "0.3", "perl:regexp-common" = "2017060201", "perl:json" = "4.03", "perl:xml-sax" = ["1.02", "Base-1.09"], "perl:term-readline-gnu" = "1.42", "perl:xml-writer" = "0.900", "perl:exporter-lite" = "0.08", perl = "5.34.1", "perl:term-readkey" = "2.38"}
      • perl:perl at >= 5.30.0, <= 5.38.0 includes all versions
  • CVE-2025-32988 for packages: GnuTLS_jll
    • GnuTLS_jll computed ["*"]. Its latest version (3.8.4+0) has components: {gnutls = "3.8.4"}
      • gnu:gnutls at < 3.8.10 includes all versions

1 advisories apply to the latest version of a package and do not have a patch

  • CVE-2021-39212 for packages: ImageMagick_jll
    • ImageMagick_jll computed [">= 6.9.12+0, < 6.9.12+4", ">= 7.1.0+0"]. Its latest version (7.1.2005+0) has components: {imagemagick = "*"}
      • imagemagick:imagemagick at >= 6.9.12-0, < 6.9.12-22 mapped to [>= 6.9.12+0, < 6.9.12+4, >= 7.1.0+0], includes the latest version
      • imagemagick:imagemagick at >= 7.1.0-0, < 7.1.0-7 mapped to [>= 7.1.0+0], includes the latest version

1 advisories found concrete vulnerable ranges

  • CVE-2022-49043 for packages: XML2_jll
    • XML2_jll computed ["< 2.12.0+0"]. Its latest version (2.14.4+0) has components: {libxml2 = "2.14.4"}

@mbauman mbauman added the DONOTUSEJLSEC Testing data prior to publishing real JLSEC identifiers label Oct 8, 2025
@mbauman mbauman closed this Oct 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

DONOTUSEJLSEC Testing data prior to publishing real JLSEC identifiers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants