[OE-core] [for-krogoth] Backport of new libarchive release

Otavio Salvador otavio.salvador at ossystems.com.br
Tue Jul 12 11:18:32 UTC 2016


On Mon, Jul 11, 2016 at 10:25 PM, akuster808 <akuster808 at gmail.com> wrote:
> On 07/11/2016 07:41 AM, Otavio Salvador wrote:
>> The libarchive 3.2.1 fixes several bugs and security related issues so
>> it seems like a good candidate for backport. I list below the commits
>> I did in our local fork while testing it:
>
> CVE-2016-1541 is the only missing CVE. Are you aware of others? General bug
> fixes are good.  But If I am not mistaken, there are 803 commits between
> 3.1.2 (krogoth) and 3.2.1 (master). The is more than I want to take at this
> time.

No; I am not  aware of other. On OE-Core side has fixes which might be
worth check if they apply, even if not bumping the base version.

> thanks for keeping an eye out for changes needing to go into krogoth.

You're welcome. We are using it a lot so we keep finding issues worth
fixing, with low risk.

-- 
Otavio Salvador                             O.S. Systems
http://www.ossystems.com.br        http://code.ossystems.com.br
Mobile: +55 (53) 9981-7854            Mobile: +1 (347) 903-9750



More information about the Openembedded-core mailing list