There are some CVEs in libxml2 which has not been addressed in our branches (master, jethro, fido, dizzy). I suggest to upgrade libxml2 version in master and all maintained brances to address all these vulnerabilities. Looking at the log, it seems that 2.9.3 is mainely CVE fixes and some minor changes. Any comment on this? https://git.gnome.org/browse/libxml2/log/ v2.9.3 CVE-2015-8242 CVE-2015-7500 CVE-2015-7499-1 CVE-2015-7499-2 CVE-2015-5312 CVE-2015-7498 CVE-2015-7497 CVE-2015-7942-2 CVE-2015-1819 CVE-2015-7941_2 CVE-2015-7941_1 CVE-2015-7942 CVE-2015-8035 v2.9.2 CVE-2014-3660 v2.9.2-rc2 v2.9.2-rc1 CVE-2013-2877 CVE-2014-0191 v2.9.1
A 2.9.3 upgrade for master is good but for jethro you'll have to convince the jethro maintainer (Robert Yang) that an upgrade is safer than a number of patches.
some of these have been or are in the middle of being addressed by bug 8641
there are more than just CVE fixes in this update. Also, IMHO, not all security issues need to be fixed if the are low enough.
Ok, we just upgrade master and backport individual CVEs in all maintained branches which we believe are important.
(In reply to comment #4) > Ok, we just upgrade master and backport individual CVEs in all maintained > branches which we believe are important. From an OSV point of view, we have different matrix to determine which CVE's get fixed. For OE/Yocto project, there may be a different set of standards.
(In reply to comment #4) > Ok, we just upgrade master and backport individual CVEs in all maintained > branches which we believe are important. By 'we', do you mean the community?
Looks like master is taken care of. http://cgit.openembedded.org/openembedded-core/commit/?id=88e68f25e1756988692108d4c15dfa8efc94e5e5
Yes Armin, I mean The Yocto Project Community. > From an OSV point of view, we have different matrix to determine which CVE's get fixed. What do you mean by “OSV”? > For OE/Yocto project, there may be a different set of standards. Do you think it would be better that The Yocto Project have clear process of which CVEs should get fixed? Maybe we should add this info to Yocto security wiki (as a guideline)? We can use NVD scoring (ex: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3660) and have goal to backport all CVS’s scored higher than 5.0 at least in those packages which are widely used. For CVEs which are not yet in NVD’s data base, we can use other data base such as: http://www.cvedetails.com/
patch set sent for jethro and fido http://patches.openembedded.org/patch/109267/
Patches are merged for jethro and pending a merge request for fido.
Merged to Fido