[OE-core] [for-krogoth] Backport of new libarchive release
Otavio Salvador
otavio.salvador at ossystems.com.br
Tue Jul 12 11:18:32 UTC 2016
On Mon, Jul 11, 2016 at 10:25 PM, akuster808 <akuster808 at gmail.com> wrote:
> On 07/11/2016 07:41 AM, Otavio Salvador wrote:
>> The libarchive 3.2.1 fixes several bugs and security related issues so
>> it seems like a good candidate for backport. I list below the commits
>> I did in our local fork while testing it:
>
> CVE-2016-1541 is the only missing CVE. Are you aware of others? General bug
> fixes are good. But If I am not mistaken, there are 803 commits between
> 3.1.2 (krogoth) and 3.2.1 (master). The is more than I want to take at this
> time.
No; I am not aware of other. On OE-Core side has fixes which might be
worth check if they apply, even if not bumping the base version.
> thanks for keeping an eye out for changes needing to go into krogoth.
You're welcome. We are using it a lot so we keep finding issues worth
fixing, with low risk.
--
Otavio Salvador O.S. Systems
http://www.ossystems.com.br http://code.ossystems.com.br
Mobile: +55 (53) 9981-7854 Mobile: +1 (347) 903-9750
More information about the Openembedded-core
mailing list