This is the mail archive of the cygwin-apps mailing list for the Cygwin project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

Re: SECURITY: [ GLSA 200706-09 ] libexif: Buffer overflow


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Corinna Vinschen wrote:
> Never mind, I just found them.  The directory layout is a bit weird
> now:
> 
>    - exif
>      - libexif
>        - libexif12
>        - libexif-devel
>      - libexif10

Yeah, I know, that's how Gerrit set them up; should I move libexif
immediately under release?

> Why are libexif12 and libexif-devel not in the same directory level
> as libexif10?  Oh, and, do you also take over maintainance of libexif10
> or is that still an orphaned package?

libexif10 should be moved to _obsolete, and being that it's also
affected by the buffer overflow, should be dropped like a hot potato.


Yaakov
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Cygwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGpvC/piWmPGlmQSMRCF0OAJ9AK0ElZi8EYh+y8z5u+tkFN6wW1gCfUWGL
EXeAtYuZQbojxCNwY/7Z7sg=
=u+i+
-----END PGP SIGNATURE-----


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]