CVE-2025-13151 and Cygwin package libtasn1_6

Marco Atzeri marco.atzeri@gmail.com
Thu Jan 22 17:13:45 GMT 2026


On 22/01/2026 17:50, FOPPE, JEFFREY B CIV USAF AFMC AFLCMC/WFRQ via 
Cygwin wrote:
> CVE-2025-13151 points out a vulnerability in libtasn1 versions 4.20 and earlier.  The version provided through Cygwin is much earlier.  It doesn't look like this package has been updated since 2019 and is listed as Orphaned.  A lot of other packages seem to depend on it.  Does anyone know if a developer will look at updating this?
> 
> 
> Jeff Foppe
> 
> 
Looking on it

Regards
Marco



More information about the Cygwin mailing list