[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Building AbiWord without libwmf and removing libwmf from Guix
From: |
Mark H Weaver |
Subject: |
Re: Building AbiWord without libwmf and removing libwmf from Guix |
Date: |
Sat, 27 May 2017 15:41:41 -0400 |
User-agent: |
Gnus/5.13 (Gnus v5.13) Emacs/25.2 (gnu/linux) |
Leo Famulari <address@hidden> writes:
> The last update to libwmf was twelve years ago, in 2005. In the
> meantime, a large number of security issues have been discovered in this
> library. These bugs are fixed somewhat haphazardly by the distributions.
>
> While working on patching CVE-2016-9011 in libwmf, and backporting fixes
> for CVE-2016-{9317,10167,10168} in the ancient bundled libgd, I find
> myself wondering if we need this library at all. The patches from this
> 12 year span of 3rd party fixes begin to conflict with each other...
>
> Libwmf is only used as a "plugin" by AbiWord, and AbiWord can be
> configured to build without it.
What functionality would be lost? I guess that AbiWord would lose the
ability to open some kinds of files, but it would be good to know
whether or not such files are still in common use.
Mark