Re: HDF5 - how about removing gif2h5 subject to several CVE?

2023-05-24 Thread Andreas Tille
Hi Gilles, since nobody responded to your question (I did not respond as well since none of my packages uses this tool) here some opinion from me: No contradiction means agreement - thus just go for it. Thanks a lot for caring for hdf5 libraries Andreas. Am Sat, Feb 25, 2023 at 10:37:58PM

HDF5 - how about removing gif2h5 subject to several CVE?

2023-02-25 Thread Gilles Filippini
Hi debian-science, Three CVE were recently reported [1] against gif2h5. When I asked the HDF group about these CVE I had this answer: > Those appear to be flaws in a small, poorly-written, command-line tool (gif2h5) and not the HDF5 library itself. This is only a concern if you have built a