Remove add-ons mechanism
Andreas K. Huettel
dilfridge@gentoo.org
Thu Oct 5 21:11:00 GMT 2017
Am Donnerstag, 5. Oktober 2017, 14:54:47 CEST schrieb Joseph Myers:
> On Thu, 5 Oct 2017, Florian Weimer wrote:
> > Their packaging is completely different from the libidn upstream releases.
>
> And updating from the libidn upstream releases would be problematic given
> that it's a non-FSF-assigned project that has changed license.
So what strategy is best to short-term fix bugs that have already been
addressed by libidn upstream?
A quick search finds (but I haven't checked all these in detail yet, nor do I
claim the list is complete):
CVE-2015-2059, CVE-2015-8948, CVE-2016-6261, CVE-2016-6262, CVE-2016-6263
--
Andreas K. Hüttel
dilfridge@gentoo.org
Gentoo Linux developer (council, perl, libreoffice)
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: This is a digitally signed message part.
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20171005/45f5302a/attachment.sig>
More information about the Libc-alpha
mailing list