I've had another look; it still looks sane to me; but given that it's
network code we're importing in the bootloader, it feels like a
potential source of vulnerabilities and would be better to have it
checked by the Security team.

I've assigned it to ~ubuntu-security...

Please have a look at grub-code/net/http.c; which seems to be the only
real source file involved (from grub2 source) into providing the module.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1787630

Title:
  [FFe] Include HTTP support in pre-build GRUB module

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/grub2/+bug/1787630/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to