[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: ASAN builds and exiv2



On 2017-11-23 15:10:17, Roberto C. Sánchez wrote:
> On Thu, Nov 23, 2017 at 02:51:56PM -0500, Antoine Beaupré wrote:
>> 
>> Fun times. So I'm stuck now - I reported the CVE issues upstream so
>> they're at least aware of the issue:
>> 
>> https://github.com/Exiv2/exiv2/issues/174
>> 
>> ... but I am not sure what to do with the package in Wheezy. I'm tempted
>> to mark this as no-dsa because there's no upstream fix and we can't
>> reproduce, but I wonder if we should just mark it as not-affected
>> instead.
>> 
>> Opinions?
>> 
> Antoine,
>
> The problems you reported sound quite puzzling.  Would you like for me
> to try to at least to see if I can get the ASAN build to complete
> without failing?

I would definitely love to see more eyes on this, so yes, please go
ahead.

> Did you have to adjust any dependencies to get exiv2 to build in
> jessie?

Nope, not at all - it just builds fine if you (like me) just dget the
package from wheezy, forget to change anything and build it as-is. :)

A.

-- 
Celui qui sait jouir du peu qu'il a est toujours assez riche.
                         - Démocrite


Reply to: