From: Alexander Kanavin <alexander.kanavin@linux.intel.com>
To: Richard Purdie <richard.purdie@linuxfoundation.org>,
openembedded-core@lists.openembedded.org
Subject: Re: CVE-2016-3116: dropbear: X11 forwarding input not validated properly
Date: Wed, 14 Sep 2016 12:58:43 +0300 [thread overview]
Message-ID: <fd30a088-4a2f-9e4b-1289-d5bababdc3e2@linux.intel.com> (raw)
In-Reply-To: <1473846188.7207.57.camel@linuxfoundation.org>
On 09/14/2016 12:43 PM, Richard Purdie wrote:
>> That said, I vote for updating to the version that comes with the
>> fix.
>> Backporting fixes should not be the default in the stable yocto
>> releases; we should trust the upstream more.
>
> Taking that argument to the extreme, we should update all versions in
> the "stable" release to the latest to ensure we get all the fixes. At
> that point, it becomes no different to master and its not the
> definition of "stable" which most people want to use.
But I'm not making this argument at all. What I'm saying, is that master
branch and stable branches are two different extremes with their own
problems (one is moving too fast, the other is conservative to a fault),
and we should try to find a sensible middle ground between them.
> In this case, its a question of what else changed in dropbear between
> these versions. Were there a ton of new features or was it just
> bugfixes? How much risk of other problems is there?
In this case, the only difference between 2015.71 and 2016.72 is indeed
the CVE fix commit:
https://secure.ucc.asn.au/hg/dropbear/graph
(you need to scroll down some to see it in the graph).
Alex
next prev parent reply other threads:[~2016-09-14 10:00 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-09-14 8:49 CVE-2016-3116: dropbear: X11 forwarding input not validated properly Sona Sarmadi
2016-09-14 9:06 ` Alexander Kanavin
2016-09-14 9:43 ` Richard Purdie
2016-09-14 9:58 ` Alexander Kanavin [this message]
2016-09-14 10:24 ` Sona Sarmadi
2016-09-14 10:31 ` Alexander Kanavin
2016-09-14 20:19 ` akuster808
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=fd30a088-4a2f-9e4b-1289-d5bababdc3e2@linux.intel.com \
--to=alexander.kanavin@linux.intel.com \
--cc=openembedded-core@lists.openembedded.org \
--cc=richard.purdie@linuxfoundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox