Re: graphicsmagick / CVE-2016-7447

2016-09-19 Thread Luciano Bello
On Monday 19 September 2016 18.25.31 Brian May wrote:
> While the code is a significant improvement on the old code, does this
> justify a security update?
> 
> Possibly the answer is Yes, when combined with fixes for the other
> security issues against graphicsmagick. Thought I should check here
> however.

We have many pending issues with graphicsmagick, so we can definitely add this 
one in the list.

Laszlo, are you still working on this?

Cheers, luciano



Re: graphicsmagick / CVE-2016-7447

2016-09-19 Thread GCS
On Mon, Sep 19, 2016 at 7:14 PM, Luciano Bello  wrote:
> On Monday 19 September 2016 18.25.31 Brian May wrote:
>> While the code is a significant improvement on the old code, does this
>> justify a security update?
>>
>> Possibly the answer is Yes, when combined with fixes for the other
>> security issues against graphicsmagick. Thought I should check here
>> however.
>
> We have many pending issues with graphicsmagick, so we can definitely add this
> one in the list.
>
> Laszlo, are you still working on this?
 Do you mean updating Wheezy? As discussed with Raphaƫl, it's better
if I don't support it. Also, I've seen a discussion on LTS mailing
list that you don't have enough work, so it's fine with me to do it
yourself.
With the Jessie update, I've a big lag. :( Worked on other RC bugs and
Jessie PUs. :(

Regards,
Laszlo/GCS