SECURITY: [ GLSA 200706-09 ] libexif: Buffer overflow

Yaakov (Cygwin Ports) yselkowitz@users.sourceforge.net
Wed Jul 25 06:41:00 GMT 2007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Corinna Vinschen wrote:
> Never mind, I just found them.  The directory layout is a bit weird
> now:
> 
>    - exif
>      - libexif
>        - libexif12
>        - libexif-devel
>      - libexif10

Yeah, I know, that's how Gerrit set them up; should I move libexif
immediately under release?

> Why are libexif12 and libexif-devel not in the same directory level
> as libexif10?  Oh, and, do you also take over maintainance of libexif10
> or is that still an orphaned package?

libexif10 should be moved to _obsolete, and being that it's also
affected by the buffer overflow, should be dropped like a hot potato.


Yaakov
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Cygwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGpvC/piWmPGlmQSMRCF0OAJ9AK0ElZi8EYh+y8z5u+tkFN6wW1gCfUWGL
EXeAtYuZQbojxCNwY/7Z7sg=
=u+i+
-----END PGP SIGNATURE-----



More information about the Cygwin-apps mailing list