Re: [Podofo-users] Fwd: Re: CVE confusion, also in Debian (was: Re: Next PoDoFo Release 0.9.6)

2018-07-13 Thread Matthew Brincke
Hello Mattia, hello Dominik, hello all, > On 13 July 2018 at 14:30 Mattia Rizzolo wrote: > > > On Fri, Jul 13, 2018 at 08:17:31AM +0200, Dominik Seichter via Podofo-users > wrote: > > I tagged the podofo-0.9.6 release already and also provided the tarball on > > sourceforge. There was no

Re: [Podofo-users] Fwd: Re: CVE confusion, also in Debian (was: Re: Next PoDoFo Release 0.9.6)

2018-07-13 Thread Dominik Seichter via Podofo-users
Hi Matthew et al. I tagged the podofo-0.9.6 release already and also provided the tarball on sourceforge. There was no official announcement though, yet. I still think we should release 0.9.6, as the status of 0.9.6 is not worse than 0.9.5 (PLEASE CORRECT ME IF I AM WRONG HERE!). Nontheless, we

[Podofo-users] Fwd: Re: CVE confusion, also in Debian (was: Re: Next PoDoFo Release 0.9.6)

2018-07-12 Thread Matthew Brincke
Hello Mattia, hello all, firstly I apologize (especially in case the delay in reaction on my part is the reason PoDoFo 0.9.6 was released with CVEs unfixed, for some of them see below in the original message) for having been busy with another project and not squeezing this in-between, I also was

Re: [Podofo-users] Fwd: Re: CVE confusion, also in Debian (was: Re: Next PoDoFo Release 0.9.6)

2018-07-09 Thread Mattia Rizzolo
On Fri, Jun 15, 2018 at 10:47:14AM +0200, Mattia Rizzolo wrote: > Thanks for all your help, and sorry for the delay in dealing with this. Now that 0.9.6 is out I took my time and had a look at also the new CVEs that appeared this year. I've reported them in the podofo issue tracker (there are