[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Alpha version of libtheora in unstable seem like a bad idea



[Sebastian Ramacher]
> I am happy to revert to the old release. I was mostly looking for the
> optimizations for arm64 that the 1.2 alpha release has.

Aha.  Note, I do not know of any concrete problems with the 1.2 release,
and my scepsis is only based on my belief that it contain half baked
changes that was never properly verified.

> In any case, there is another question to be raised: with upstream
> inactive and an open CVE-2024-56431, is it time to start thinking of
> dropping libtheora?

I know ogg theora is still used quite a lot, so it should not be dropped
lightly.  I will poke the Xiph team about the need for a new release.  I
reminded them of the CVE on #xiph today, and there is at least some
people there talking about wrapping up a new release.

Perhaps I wrap up a new release myself, like I did with liboggz,
libkate, libfishsound and liboggplay, but I hope someone who know the
theora code base will step up instead.

Adding the multimedia team back, to make the rest of the team know about
the development.

-- 
Happy hacking
Petter Reinholdtsen


Reply to: