Adding autopkgtests for CVEs
I recently had some success adding an autopkgtest for a CVE and
thought I might share:
You generate the uuencode input with "uuencode -m -".
Note that I added a "smoke test" for the non-CVE-related
codepaths; if I just tested whether the reproducer was rejected,
this could mask that I broke the regular operation of the package.
: :' : Chris Lamb
`. `'` email@example.com / chris-lamb.co.uk