[meego-commits] 5499: Changes to Trunk:Testing/libpng

Bin Gao bin.gao at intel.com
Mon Jul 12 03:23:49 UTC 2010


Oh, 0205 patch is for CVE-2010-0205 but 1.2.44 has fixed it so I removed
corresponding patch.
CVE-2010-2249 and CVE-2010-1205 are 2 other CVE bugs that we didn't have
patches for them in Trunk.

On Sun, 2010-07-11 at 21:02 -0600, Zhu, Peter J wrote:
> Actually I’m surprised your imagination. See below. I thought you
> would like tell why you removed 0205 patch. 
> 
>  
> 
> old:
> 
> ----
> 
>   CVE-2010-0205.patch
> 
>   libpng-1.2.37-apng.patch
> 
>   libpng-1.2.37.tar.bz2
> 
>  
> 
>  
> 
>  
> 
> 
> From: Gao, Bin 
> Sent: Monday, July 12, 2010 10:29 AM
> To: Zhu, Peter J
> Cc: meego-commits at meego.com
> Subject: RE: [meego-commits] 5499: Changes to Trunk:Testing/libpng
> 
> 
> 
>  
> 
> Surprised at your imagination:-) 1205 is a CVE ID not a date. See
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1205
> Please accept it ASAP.
> 
> Thanks,
> Bin
> 
> On Fri, 2010-07-09 at 06:49 -0600, Zhu, Peter J wrote: 
> 
> 
>  
> > -----Original Message-----
> > From: meego-commits-bounces at meego.com
> > [mailto:meego-commits-bounces at meego.com] On Behalf Of Bin Gao
> > Sent: Friday, July 09, 2010 3:31 PM
> > To: meego-commits at meego.com
> > Subject: [meego-commits] 5499: Changes to Trunk:Testing/libpng
> > 
> > Hi,
> > I have made the following changes to libpng in project Trunk:Testing. Please
> > review and accept ASAP.
> > 
> > Thank You,
> > Bin Gao
> > 
> > [This message was auto-generated]
> > 
> > ---
> > 
> > Request #5499:
> > 
> >   submit:   home:bgao1:branches:Trunk:Testing/libpng(r2)(cleanup) ->
> > Trunk:Testing/libpng
> > 
> > 
> > Message:
> >     update to 1.2.44 and fix the missing apng patch
> > 
> > State:   new          2010-07-08T19:26:49 bgao1
> > Comment: None
> > 
> > 
> > 
> > changes files:
> > --------------
> > --- libpng.changes
> > +++ libpng.changes
> > @@ -0,0 +1,3 @@
> > +* Mon Jul 05 2010 Bin Gao <bin.gao at intel.com> - 1.2.44
> > +- Update to 1.2.44 which includes CVE fix for CVE-2010-1205 and
> > CVE-2010-2249
> Seem the change log is wrong. It include fix for CVE-2010-0205, not CVE-2010-1205
>  
> Peter
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.meego.com/pipermail/meego-commits/attachments/20100712/4adfc44a/attachment.html>


More information about the MeeGo-commits mailing list