GNU bug report logs

#27519 Podofo security bugs

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #12 received at 27519-done@debbugs.gnu.org (full text, mbox, reply):

Received: (at 27519-done) by debbugs.gnu.org; 4 Feb 2019 23:34:14 +0000
From debbugs-submit-bounces@debbugs.gnu.org Mon Feb 04 18:34:14 2019
Received: from localhost ([127.0.0.1]:59881 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1gqnkk-0005go-B6
	for submit@debbugs.gnu.org; Mon, 04 Feb 2019 18:34:14 -0500
Received: from wout2-smtp.messagingengine.com ([64.147.123.25]:39079)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <leo@famulari.name>) id 1gqnki-0005gY-5n
 for 27519-done@debbugs.gnu.org; Mon, 04 Feb 2019 18:34:13 -0500
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44])
 by mailout.west.internal (Postfix) with ESMTP id 56DE12E01;
 Mon,  4 Feb 2019 18:34:06 -0500 (EST)
Received: from mailfrontend2 ([10.202.2.163])
 by compute4.internal (MEProxy); Mon, 04 Feb 2019 18:34:06 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name;
 h=date:from:to:subject:message-id:mime-version:content-type; s=
 mesmtp; bh=rHkWMhN0dkegBC/J7ZlAQDUfbZs2FQc1cTT8UMMbtnM=; b=oU7JZ
 9nakKauHiH6QZ+iCCJVqtLRY5LBTkiP5Jb/10ilYfUQrhPNMmza6Mh+m43sseFQL
 OAo/fTJz60eWwzqxZjTadgQdr/K3ZNICSX5lgCdzJvmPQ9hY3ck+sSAUX4NwDOiM
 5PH6RppfUfG4aG9OP1B6cF3tx+2CznOTLK+MpU=
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
 messagingengine.com; h=content-type:date:from:message-id
 :mime-version:subject:to:x-me-proxy:x-me-proxy:x-me-sender
 :x-me-sender:x-sasl-enc; s=fm1; bh=rHkWMhN0dkegBC/J7ZlAQDUfbZs2F
 Qc1cTT8UMMbtnM=; b=LgTpAMbab5XuqSSrtTkvdMgrgFFoyavxOMFyFHFdY4F26
 hOg4t86MJcnC6rrPffG7meW9o/W+xwssstYbRFQa6yv6Uz6Q7GE2qvrwQO+CJIG0
 VkiIGk1KN+oNgv3ek6f2SsJ8xP7aEroLQ80+VsbjHIJibwrWycW00h6sKCeSRIOu
 At2+dARsfgDpFIUUCwrt9F8ptVENPwqPlxFjDRNrK8caVSfBy7La2fiii1IgLMst
 CJ2TMoCet2NVPIMoQn7T2UBu6SmlTDkUePyylfi7109zH4NjH8rUEWsmhbgViCJ8
 F+O8HZuCzZr9JWDAeu/LLbwMHeTJUtKlDM0SPAtNw==
X-ME-Sender: <xms:7MtYXLOTfairDP3v7zp4H81SSplxmap2zfbHGXqjUMe5BobqQLJ0NA>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedtledrkeehgdduudcutefuodetggdotefrodftvf
 curfhrohhfihhlvgemucfhrghsthforghilhdpqfhuthenuceurghilhhouhhtmecufedt
 tdenucenucfjughrpeffhffvuffkgggtuggfsehgtderredtredvnecuhfhrohhmpefnvg
 houcfhrghmuhhlrghrihcuoehlvghosehfrghmuhhlrghrihdrnhgrmhgvqeenucfkphep
 udejvddrheeirdduvddrudduvdenucfrrghrrghmpehmrghilhhfrhhomheplhgvohesfh
 grmhhulhgrrhhirdhnrghmvgenucevlhhushhtvghrufhiiigvpedt
X-ME-Proxy: <xmx:7MtYXKOqU5T22kupt456a5OHujPscvSTlyTnS_xTVBZSAtQmf7PYkg>
 <xmx:7MtYXFQG3bzKzCcEonvzQcLsDkRa3XCGayi-eqDI30HLZdKknz2GHA>
 <xmx:7MtYXEAzOrouQ_9mpvu60ANPDMhX8nVZsYI4llE-iW0HHmEo5azHHg>
 <xmx:7ctYXL2XKIvGshMkVwzphChVPLOKxMCWBL7SuP7qytlm5bcPGVOi-Q>
Received: from localhost (unknown [172.56.12.112])
 by mail.messagingengine.com (Postfix) with ESMTPA id 0A9721030F
 for <27519-done@debbugs.gnu.org>; Mon,  4 Feb 2019 18:34:03 -0500 (EST)
Date: Tue, 5 Feb 2019 00:34:01 +0100
From: Leo Famulari <leo@famulari.name>
To: 27519-done@debbugs.gnu.org
Subject: Re: Podofo security bugs
Message-ID: <20190204233401.GA20023@jasmine.lan>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature"; boundary="zYM0uCDKw75PZbzx"
Content-Disposition: inline
User-Agent: Mutt/1.11.2 (2019-01-07)
X-Spam-Score: -0.7 (/)
X-Debbugs-Envelope-To: 27519-done
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -1.7 (-)
[Message part 1 (text/plain, inline)]
We have since packaged a new release of PoDoFo (0.9.6) which apparently
fixed many bugs.

The PoDoFo team does not write changelogs or any sort of release
announcement file. Their SVN repo includes several commits like "Fix
CVE-XXX" followed by "Really fix CVE-XXX".

Since PoDoFo is not widely used in Guix (only by calibre and Scribus),
I'm not going to dig in to whether or not these bugs are really fixed or
not in the current Guix package.

At this point, this bug report is not helping us much, so I am closing
it :)
[signature.asc (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sat Dec 21 17:12:02 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.