glaubitz commented on PR #3220:
URL: https://github.com/apache/thrift/pull/3220#issuecomment-4377286118

   > The commits are not marked primarily for the [technical reason that it 
would break git 
history](https://www.apache.org/security/committers.html#complete). Also, 
binding a CVE to single commit ids is not always possible. Finally, there are 
opinions on both end of the spectrum why this is a great or a bad idea (pick 
your side) at all. The CVE you mentioned is fixed in 0.23.0 and master.
   
   The problem is that enterprise distributions can't just easily update to the 
latest and greatest upstream versions. We have to cherry-pick patches and that 
usually works for 99% of the upstream projects. I'm quite surprised that the 
Apache Foundation handles it differently and expects downstream just to keep 
updating the whole software package to fix a CVE.
   
   I'll try to find the commit myself then. It fixes a buffer overflow, so it 
should be a single identifiable patch.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to