<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="http://dev1galaxy.org/extern.php?action=feed&amp;tid=8158&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
		<link>http://dev1galaxy.org/viewtopic.php?id=8158</link>
		<description><![CDATA[The most recent posts in yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High).]]></description>
		<lastBuildDate>Thu, 10 Sep 2026 17:04:45 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65456#p65456</link>
			<description><![CDATA[<p>Yes it&#039;s very true that there is actually little point in packaging these types of scripts, which can simply be downloaded from the project&#039;s own page.</p><p>It&#039;s the nature of Debian however that anything and everything may be packaged while someone is willing to package it and then maintain it.</p><p>It is also the nature of Debian that, with very few exceptions, no new versions of &quot;upstream&quot; software are introduced after the &quot;freeze&quot;. Note: I&#039;m not defending this model, just explaining the basics of how it works.</p><p>Around 15 - 20 years ago, this manifested itself most publicly, in the multitudes of &quot;I want the latest firefox&quot; rant threads. This was where users who were running Debian stable, e.g. 1.5 years into a release, were still at easily a 2 year old firefox release (rebranded to &quot;iceweasel&quot; due to licence and trademark issues).</p><p>The obvious answer was to just go to mozilla and download it, but many still complained and felt entitled to the latest version. Unlike the example in this thread, Iceweasel did receive backported security patches, but functionality wise could be 2+ years behind.</p><p>This situation is similar - few will be happy with the packaged version, so it is indeed pointless.</p>]]></description>
			<author><![CDATA[dummy@example.com (blackhole)]]></author>
			<pubDate>Thu, 10 Sep 2026 17:04:45 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65456#p65456</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65455#p65455</link>
			<description><![CDATA[<div class="quotebox"><cite>luvr wrote:</cite><blockquote><div><p>To be honest, I believe installing yt-dlp from a distro repository is pointless, on any distro. I don’t get why distros even want to include it in their repositories, because it is such a movable target.</p></div></blockquote></div><p>Indeed, this isn&#039;t just a Debian/Devuan issue. Virtually every distro has this problem with a subset of its packages.</p><p>For something updated as frequently as yt-dlp (or ffmpeg, in my case), I&#039;ve resorted to using the nightlies when I&#039;m pressed. Even Sid isn&#039;t going to be cutting-edge 100% of the time.</p>]]></description>
			<author><![CDATA[dummy@example.com (jw4791)]]></author>
			<pubDate>Thu, 10 Sep 2026 13:41:54 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65455#p65455</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65454#p65454</link>
			<description><![CDATA[<p>To be honest, I believe installing <em>yt-dlp</em> from a distro repository is pointless, on any distro. I don’t get why distros even <em>want</em> to include it in their repositories, because it is such a movable target.</p><p>If a distro really, <em>really,</em> <strong>really</strong> wants to provide a way to install <em>yt-dlp</em> through its repositories, then won’t it make more sense to distribute a <em>“yt-dlp <strong>installer”</strong></em> or some such, that will download and install the latest <em>yt-dlp</em> whenever it is run? Somewhat akin to the <em>“Adobe Flash installer”</em> that Debian used to have in its repositories? Maybe provide some way to rerun the installer periodically, or to allow the user to easily rerun it manually on request, to keep <em>yt-dlp</em> up-to-date?</p><p>In any case, I manually run a bash script to update <em>yt-dlp</em> whenever I want to make sure that my installed copy of <em>yt-dlp</em> is up-to-date; in fact, I do the same to keep <em>deno</em> (<em>“a modern runtime for JavaScript and TypeScript”</em> that is used by <em>yt-dlp</em>) updated as well.</p>]]></description>
			<author><![CDATA[dummy@example.com (luvr)]]></author>
			<pubDate>Thu, 10 Sep 2026 13:02:46 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65454#p65454</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65363#p65363</link>
			<description><![CDATA[<p>JMHO I use this one on all my Linuxes... <a href="https://flathub.org/en/apps/com.github.unrud.VideoDownloader" rel="nofollow">https://flathub.org/en/apps/com.github. … Downloader</a></p>]]></description>
			<author><![CDATA[dummy@example.com (yurimodin)]]></author>
			<pubDate>Mon, 31 Aug 2026 14:35:07 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65363#p65363</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65282#p65282</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>tux_99 wrote:</cite><blockquote><div><p>... how many other long known CVEs are there in other Debian packages that have not been fixed yet?</p></div></blockquote></div><p>Cannot but agree that you <span class="bbu">do</span> have a point.</p><p>That said, I have not noticed that CVEs get slept on.<br />From memory (make what you will of that), the CVEs I have read about have usually been solved/worked out in three or four days.</p><p>This from using Devuan since ~2017.</p><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Thu, 20 Aug 2026 20:28:58 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65282#p65282</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65281#p65281</link>
			<description><![CDATA[<p>yt-dlp definitely has a learning curve no matter how you install and set it up.</p><p>there is a reason why the main webpage is a very very long slog:</p><p><a href="https://github.com/yt-dlp/yt-dlp" rel="nofollow"> https://github.com/yt-dlp/yt-dlp</a></p>]]></description>
			<author><![CDATA[dummy@example.com (stargate-sg1-cheyenne-mtn)]]></author>
			<pubDate>Thu, 20 Aug 2026 20:14:28 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65281#p65281</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65279#p65279</link>
			<description><![CDATA[<div class="quotebox"><cite>blackhole wrote:</cite><blockquote><div><p>Not sure where all the hostility is coming from?</p></div></blockquote></div><p>I wouldn&#039;t call it hostility, but if you write a reply that clearly shows that you didn&#039;t read the previous posts in the thread and therefore write incorrect or redundant stuff then don&#039;t expect to be also thanked for that.</p><div class="quotebox"><blockquote><div><p>This isn&#039;t the Debian official forum or mailing lists though, so maybe take it up with them using one of those channels? Mailing list is preferred - perhaps search the list first.</p></div></blockquote></div><p>I&#039;m a Devuan user and this affects Devuan too so I&#039;m writing it here, I have no interest in joining the Debian forum or ML. Also as I suspected there must be Debian Devs keeping an eye on this forum too, as it&#039;s too much of a coincidence that they started working on the yt-dlp package for trixie last night a few hours after I started this thread here.</p><div class="quotebox"><cite>Dutch_Master wrote:</cite><blockquote><div><p>FYI: latest version, as of date of writing this, was released yesterday.</p></div></blockquote></div><p>Yep, the latest upstream version, I&#039;m using that right now since I&#039;m no longer using the outdated and insecure packaged Debian version.</p><div class="quotebox"><cite>rbit wrote:</cite><blockquote><div><p>If you don&#039;t use those options (--write-link, --write-url-link, or --write-desktop-link), this particular issue won&#039;t affect you.</p></div></blockquote></div><div class="quotebox"><cite>RedGreen925 wrote:</cite><blockquote><div><p> But those that would rather bitch and complain about how hard done by they are by the very busy Debian maintainer not doing it, that is too much of a burden on them.</p></div></blockquote></div><p>This is not about me, as I already wrote I have now moved on to the upstream binaries anyway, it&#039;s about all other Debian 13 / Devuan 6 users who use the Debian yt-dlp package and might not even be aware of this CVE.</p><p>But if we have to manually install binaries from upstream to avoid security issues then what&#039;s the point of a distro?</p><p>My main concern now is how many other long known CVEs are there in other Debian packages that have not been fixed yet?</p><p>Do I really have to start checking all the packages that I use for known CVEs that Debian hasn&#039;t fixed yet?</p><p>Does this not make you concerned?</p>]]></description>
			<author><![CDATA[dummy@example.com (tux_99)]]></author>
			<pubDate>Thu, 20 Aug 2026 19:10:25 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65279#p65279</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65276#p65276</link>
			<description><![CDATA[<div class="quotebox"><blockquote><div><p>FYI: latest version, as of date of writing this, was released yesterday.</p></div></blockquote></div><p>Yes and for anyone supposedly concerned with their security in using it, it is a less than five minute process to upgrade to the latest version like I did last night after seeing this thread. But those that would rather bitch and complain about how hard done by they are by the very busy Debian maintainer not doing it, that is too much of a burden on them. And to top it off the complaint is made in a place that that maintainer is likely never to see.</p><div class="codebox"><pre><code>zeus@9600k:~$ which yt-dlp
/usr/bin/yt-dlp
zeus@9600k:~$ chmod +x /home/zeus/Downloads/yt-dlp_linux
zeus@9600k:~$ mv /home/zeus/Downloads/yt-dlp_linux /home/zeus/bin/yt-dlp
zeus@9600k:~$ which yt-dlp
/home/zeus/bin/yt-dlp
zeus@9600k:~$ yt-dlp -v
[debug] Command-line config: [&#039;-v&#039;]
[debug] System config &quot;/etc/yt-dlp.conf&quot;: []
[debug] Encodings: locale UTF-8, fs utf-8, pref UTF-8, out utf-8, error utf-8, screen utf-8
[debug] yt-dlp version stable@2026.08.19 from yt-dlp/yt-dlp (linux_exe)
[debug] Python 3.14.7 (CPython x86_64 64bit) - Linux-6.12.101+deb13-amd64-x86_64-with-glibc2.41 (OpenSSL 3.5.7 9 Jun 2026, glibc 2.41)
[debug] exe versions: ffmpeg 7.1.5-0 (setts), ffprobe 7.1.5-0
[debug] Optional libraries: Cryptodome-3.23.0, brotli-1.2.0, certifi-2026.07.22, curl_cffi-0.16.0, mutagen-1.48.1, requests-2.34.2, secretstorage-3.5.0, sqlite3-3.53.4, urllib3-2.7.0, websockets-17.0.1, yt_dlp_ejs-0.8.0
[debug] JS runtimes: none
[debug] Proxy map: {}
[debug] Request Handlers: urllib, requests, websockets, curl_cffi
[debug] Plugin directories: none
[debug] Loaded 1744 extractors</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (RedGreen925)]]></author>
			<pubDate>Thu, 20 Aug 2026 16:49:37 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65276#p65276</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65275#p65275</link>
			<description><![CDATA[<p>I would also point out, according to what you wrote, </p><div class="quotebox"><cite>tux_99 wrote:</cite><blockquote><div><p>the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files ...</p></div></blockquote></div><p>If you don&#039;t use those options (--write-link, --write-url-link, or --write-desktop-link), this particular issue won&#039;t affect you.&#160; If you do use them, and don&#039;t want to check the output files, then by all means, update to a newer version (which is probably necessary anyway for it to work with youtube)</p>]]></description>
			<author><![CDATA[dummy@example.com (rbit)]]></author>
			<pubDate>Thu, 20 Aug 2026 16:45:34 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65275#p65275</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65274#p65274</link>
			<description><![CDATA[<p>FYI: latest version, as of date of writing this, was released yesterday.</p>]]></description>
			<author><![CDATA[dummy@example.com (Dutch_Master)]]></author>
			<pubDate>Thu, 20 Aug 2026 15:44:10 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65274#p65274</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65273#p65273</link>
			<description><![CDATA[<p>Not sure where all the hostility is coming from?</p><p>My source of the version info is here: <a href="https://tracker.debian.org/pkg/yt-dlp" rel="nofollow">https://tracker.debian.org/pkg/yt-dlp</a></p><p>But there are inconsistencies between the source and binary package versions for stable backports: </p><p><a href="https://packages.debian.org/source/trixie-backports/yt-dlp" rel="nofollow">https://packages.debian.org/source/trix … rts/yt-dlp</a><br /><a href="https://packages.debian.org/trixie-backports/yt-dlp" rel="nofollow">https://packages.debian.org/trixie-backports/yt-dlp</a></p><p>The source is ahead of the binary, which may mean the update is in the works... so yes you&#039;re correct that it&#039;s still behind for now.</p><p>All we know about this particular CVE is that there is no DSA against it and thus no patch. For some reason Debian security aren&#039;t in a hurry to fix it.</p><p>This isn&#039;t the Debian official forum or mailing lists though, so maybe take it up with them using one of those channels? Mailing list is preferred - perhaps search the list first.</p>]]></description>
			<author><![CDATA[dummy@example.com (blackhole)]]></author>
			<pubDate>Thu, 20 Aug 2026 13:54:20 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65273#p65273</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65272#p65272</link>
			<description><![CDATA[<div class="quotebox"><cite>blackhole wrote:</cite><blockquote><div><p>Currently, the backports version is the same as the version in unstable, so the solution seems to be to install the bacports version and follow that.</p></div></blockquote></div><p>As I said I was already using the version from excalibur backports but that&#039;s 2026.03.17, which is <strong>not</strong> the latest version and it&#039;s <strong>not</strong> the same as unstable which has the latest version (2026.07.04-1), so your statement is simply incorrect.</p><div class="quotebox"><blockquote><div><p>it may be better to direct your concerns to the upstream project</p></div></blockquote></div><p>What nonsense comment, my concern is that debian has a known vulnerable version since more than a month in stable with no security update available, upstream has nothing to do with that.</p><div class="quotebox"><blockquote><div><p>Debian &quot;freezes&quot; packages at a specific version and any security patches are backported as necessary. So any newer version will never&#160; be available in stable.</p></div></blockquote></div><p>I don&#039;t care whether Debian backports the security patch or the latest version as long as the CVE is fixed, but so far they haven&#039;t done either of the two options.</p>]]></description>
			<author><![CDATA[dummy@example.com (tux_99)]]></author>
			<pubDate>Thu, 20 Aug 2026 13:10:03 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65272#p65272</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65271#p65271</link>
			<description><![CDATA[<p>With the number of vulnerabilities found in this over the last three years, it may be better to direct your concerns to the upstream project itself rather than Debian.</p><p><a href="https://www.cvedetails.com/vulnerability-list/vendor_id-31193/Yt-dlp-Project.html" rel="nofollow">https://www.cvedetails.com/vulnerabilit … oject.html</a></p><p>Currently, the backports version is the same as the version in unstable, so the solution seems to be to install the bacports version and follow that. I thought it was commonly known that, with few exceptions, Debian &quot;freezes&quot; packages at a specific version and any security patches are backported as necessary. So any newer version will never&#160; be available in stable. As it stands, there is no DSA for this as yet. You would have to search the mailing lists / ask the maintainer.</p>]]></description>
			<author><![CDATA[dummy@example.com (blackhole)]]></author>
			<pubDate>Thu, 20 Aug 2026 07:18:17 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65271#p65271</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65268#p65268</link>
			<description><![CDATA[<p>You should also look into <a href="https://freetubeapp.io" rel="nofollow">FreeTube</a>, which can also work with it if you want to download or stream videos you come across externally.</p>]]></description>
			<author><![CDATA[dummy@example.com (brocashelm)]]></author>
			<pubDate>Thu, 20 Aug 2026 02:34:45 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65268#p65268</guid>
		</item>
		<item>
			<title><![CDATA[Re: yt-dlp in Debian 13 / Devuan 6 affected by serious CVE (Score: High)]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=65263#p65263</link>
			<description><![CDATA[<p>Well the packaged version from backports (2026.03.17) was working fine for me until a couple of days ago (BTW, yt-dlp isn&#039;t only for youtube, it works on many sites), only today it started acting up which is why I was looking for updates and found out about the CVE.</p><div class="quotebox"><cite>fsmithred wrote:</cite><blockquote><div><p> That&#039;s probably why the maintainer doesn&#039;t bother to update it.</p></div></blockquote></div><p>A serious CVE should be a good enough reason to update it.</p>]]></description>
			<author><![CDATA[dummy@example.com (tux_99)]]></author>
			<pubDate>Wed, 19 Aug 2026 22:28:44 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=65263#p65263</guid>
		</item>
	</channel>
</rss>
