Closed LeSpocky closed 5 years ago
Patch for https://bugzilla.gnome.org/show_bug.cgi?id=775200 was sent to ptxdist mailinglist: https://www.mail-archive.com/ptxdist@pengutronix.de/msg12930.html
Release Announcement for v2.9.9 here: https://mail.gnome.org/archives/xml/2019-January/msg00000.html
Security:
- CVE-2018-9251 CVE-2018-14567 Fix infinite loop in LZMA decompression (Nick Wellnhofer)
- CVE-2018-14404 Fix nullptr deref with XPath logic ops (Nick Wellnhofer)
Patches for 2.9.9 need review. Not clear if the patch for CVE-2017-8872 can be dropped?
see: https://mail.gnome.org/archives/xml/2019-January/msg00010.html
Applied with 2f88d0401bc3398a0a164c7391d0088dff86c9d3.
https://mail.gnome.org/archives/xml/2018-March/msg00001.html