From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:40554) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fH4ic-0005I9-1S for guix-patches@gnu.org; Fri, 11 May 2018 05:52:07 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fH4iY-00014l-Uv for guix-patches@gnu.org; Fri, 11 May 2018 05:52:06 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:49259) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1fH4iY-00014X-Qq for guix-patches@gnu.org; Fri, 11 May 2018 05:52:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1fH4iY-0006aT-Gm for guix-patches@gnu.org; Fri, 11 May 2018 05:52:02 -0400 Subject: [bug#30801] Add opencv Resent-Message-ID: Date: Fri, 11 May 2018 11:51:24 +0200 From: =?UTF-8?Q?Bj=C3=B6rn_?= =?UTF-8?Q?H=C3=B6fling?= Message-ID: <20180511115124.0f8ed3d9@alma-ubu> In-Reply-To: <878t8sxzdi.fsf@gnu.org> References: <20180313175809.7d782c1a@alma-ubu> <87po45rqx5.fsf@gnu.org> <20180401002649.37231b47@alma-ubu> <87a7unglrh.fsf@gnu.org> <20180507203547.3ae3cb35@alma-ubu> <878t8sxzdi.fsf@gnu.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; boundary="Sig_/ofNFNlOOJPOXeq_f2OIDXNp"; protocol="application/pgp-signature" List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: Ludovic =?UTF-8?Q?Court=C3=A8s?= Cc: 30801-done@debbugs.gnu.org --Sig_/ofNFNlOOJPOXeq_f2OIDXNp Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On Thu, 10 May 2018 00:01:13 +0200 ludo@gnu.org (Ludovic Court=C3=A8s) wrote: > > * gnu/packages/image-processing.scm (opencv): New variable. =20 >=20 > Applied! Thanks. =20 > =E2=80=98guix lint=E2=80=99 reports this: >=20 > gnu/packages/image-processing.scm:201:2: opencv@3.4.1: probably > vulnerable to CVE-2018-7712, CVE-2018-7713, CVE-2018-7714 >=20 > Could you take a look? It could be that 3.4.2 is around the corner > and we=E2=80=99ll just update at that point; if not, we may have to apply > upstream patches for these issues. While finally linting, I noticed these too. OpenCV claims this is not an issue: https://github.com/opencv/opencv/issues/10998 Should we mention it somewhere in the code? Is there a formal process to hide or comment specific CVEs? Bj=C3=B6rn --Sig_/ofNFNlOOJPOXeq_f2OIDXNp Content-Type: application/pgp-signature Content-Description: OpenPGP digital signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iEYEARECAAYFAlr1Z50ACgkQvyhstlk+X/3fHwCgs57XBO5BT8puIebg/+8ykIB8 8Z8AoIVtp6ZsQeRuC8ewVjGsG3yrMyTL =T1wP -----END PGP SIGNATURE----- --Sig_/ofNFNlOOJPOXeq_f2OIDXNp--