Re: [OE-core] [PATCH 1/1] webkitgtk: fix CVEs

2018-08-30 Thread Kang Kai
On 2018年08月30日 17:29, Alexander Kanavin wrote: Isn't it better - and simpler - to just update webkitgtk itself? 2.20.3 to 2.20.5. Upgrade to 2.20.5 is better but I am afraid whether the upgrade could be accepted after M3. And commit to fix CVE-2018-12911 is also not included in 2.20.5. Regar

Re: [OE-core] [PATCH 1/1] webkitgtk: fix CVEs

2018-08-30 Thread Alexander Kanavin
Isn't it better - and simpler - to just update webkitgtk itself? 2.20.3 to 2.20.5. Alex 2018-08-30 4:46 GMT+02:00 : > From: Kai Kang > > Backport patches to fix CVE-2017-17821 and CVE-2018-12911 for webkitgtk. > > Signed-off-by: Kai Kang > --- > .../webkitgtk/0001-Fix-CVE-2017-17821.patch |

[OE-core] [PATCH 1/1] webkitgtk: fix CVEs

2018-08-29 Thread kai.kang
From: Kai Kang Backport patches to fix CVE-2017-17821 and CVE-2018-12911 for webkitgtk. Signed-off-by: Kai Kang --- .../webkitgtk/0001-Fix-CVE-2017-17821.patch | 44 ++ .../webkitgtk/0002-Fix-CVE-2018-12911.patch | 82 +++ meta/recipes-sato/webkit/webkitgtk_2.20.3.b