guix-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: v2: OpenJPEG security fixes (CVE-2016-{5157,7163})


From: Leo Famulari
Subject: Re: v2: OpenJPEG security fixes (CVE-2016-{5157,7163})
Date: Fri, 9 Sep 2016 16:26:39 -0400
User-agent: Mutt/1.7.0 (2016-08-17)

On Fri, Sep 09, 2016 at 02:04:58PM -0400, Leo Famulari wrote:
> Also, the fix for CVE-2016-5157 does not apply to openjpeg-2.0. I'd like
> to investigate this issue separately. The only user of openjpeg-2.0 is
> mupdf.

I think the best thing to do is update mupdf to the latest upstream
release, 1.9a, make it use address@hidden, and remove openjpeg-2.0.

Please see attached. These patches should be applied on top of the
patches in the email that I am replying to.

Attachment: 0001-gnu-mupdf-Update-to-1.9a.patch
Description: Text document

Attachment: 0002-gnu-Remove-openjpeg-2.0.patch
Description: Text document

Attachment: signature.asc
Description: PGP signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]