On Mon, Mar 13, 2017 at 01:39:00PM +0100, Mattia Rizzolo wrote:
> On Thu, Mar 02, 2017 at 05:31:34PM +0100, Agostino Sarubbo wrote:
> > Please consider the following:
> > 
> > …
> 
> All of these now have CVEs associated.

And apparently the Debian release team is considering these severe
enough to warrant removing libpodofo from the next debian stable release
rather then leaving them unfixed (http://bugs.debian.org/856592).
I severely lack time (and real proper knowledge) to start to help with
these, but I'd appreciate if you could prioritize them.

> I find the Debian view for security issues particularly nice to look at:
> https://security-tracker.debian.org/tracker/source-package/libpodofo

-- 
regards,
                        Mattia Rizzolo

GPG Key: 66AE 2B4A FCCF 3F52 DA18  4D18 4B04 3FCD B944 4540      .''`.
more about me:  https://mapreri.org                             : :'  :
Launchpad user: https://launchpad.net/~mapreri                  `. `'`
Debian QA page: https://qa.debian.org/developer.php?login=mattia  `-

Attachment: signature.asc
Description: PGP signature

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Podofo-users mailing list
Podofo-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/podofo-users

Reply via email to