Re: ccextractor embeds unpatched and vulnerable source code from gpac in buster - 994746

2021-09-29 Thread Neil Williams
On Tue, 28 Sep 2021 22:17:58 +0200 Ola Lundqvist wrote: > Hi Neil > > Good summary. > > Considering the high amount of marked CVEs for ccextractor I > think the best way forward is to keep the same track. We mark the > CVEs as no-dsa if they are marked as no-dsa for later releases. It > also f

Re: ccextractor embeds unpatched and vulnerable source code from gpac in buster - 994746

2021-09-29 Thread Ola Lundqvist
Hi Neil Thank you for the clarification. I misunderstood you. I think what you describe is a good way forward. Best regards // Ola On Wed, 29 Sept 2021 at 10:10, Neil Williams wrote: > On Tue, 28 Sep 2021 22:17:58 +0200 > Ola Lundqvist wrote: > > > Hi Neil > > > > Good summary. > > > > Consi

Re: Propose to ignore libxstream-java CVEs

2021-09-29 Thread Markus Koschany
Hi, Am Donnerstag, dem 23.09.2021 um 19:40 +0200 schrieb Anton Gladky: > Hi Markus, > > I have applied your patch and the pipelines are passed [1]. So, at least > nothing breaks from the "build side of view". thanks to all who have contributed to this thread. I have just uploaded a new securit