Bug#932755: libsdl2-image security issues in testing

Hugo Lefeuvre hle at debian.org
Thu Jul 25 00:21:28 BST 2019


Hi Felix,

> Thanks for your work!
> 
> I'm preparing a 2.0.5 upload right now.
> As far as I can tell all CVEs in the tracker are fixed with 2.0.5.
> Do you agree?

Thanks for the libsdl2-image upload!

Concerning sdl-image1.2:

I have a jessie LTS fix pending, patches are very similar to libsdl2-image.

However in the sdl-image1.2 case upstream did not provide a new release
addressing these issues, so I guess we'll have to go for targeted fixes. I
will provide a debdiff shortly. Would you be available to review it? I can
handle the upload if necessary, or NMU.

cheers,
Hugo

-- 
                Hugo Lefeuvre (hle)    |    www.owl.eu.com
RSA4096_ 360B 03B3 BF27 4F4D 7A3F D5E8 14AA 1EB8 A247 3DFD
ed25519_ 37B2 6D38 0B25 B8A2 6B9F 3A65 A36F 5357 5F2D DC4C
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 659 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-sdl-maintainers/attachments/20190724/73fa651d/attachment-0001.sig>


More information about the Pkg-sdl-maintainers mailing list