You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@mxnet.apache.org by GitBox <gi...@apache.org> on 2020/03/18 00:50:09 UTC

[GitHub] [incubator-mxnet] leezu opened a new pull request #17860: libjpeg-turbo: Fix user-assisted execution of arbitrary code

leezu opened a new pull request #17860: libjpeg-turbo: Fix user-assisted execution of arbitrary code
URL: https://github.com/apache/incubator-mxnet/pull/17860
 
 
   Reference https://security.gentoo.org/glsa/202003-23 and https://nvd.nist.gov/vuln/detail/CVE-2019-2201 though the CVE text is wrong.

----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
 
For queries about this service, please contact Infrastructure at:
users@infra.apache.org


With regards,
Apache Git Services

[GitHub] [incubator-mxnet] leezu commented on issue #17860: libjpeg-turbo: Fix user-assisted execution of arbitrary code

Posted by GitBox <gi...@apache.org>.
leezu commented on issue #17860: libjpeg-turbo: Fix user-assisted execution of arbitrary code
URL: https://github.com/apache/incubator-mxnet/pull/17860#issuecomment-600937616
 
 
   @access2rohit no, but it's tested by CI.

----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
 
For queries about this service, please contact Infrastructure at:
users@infra.apache.org


With regards,
Apache Git Services

[GitHub] [incubator-mxnet] leezu merged pull request #17860: libjpeg-turbo: Fix user-assisted execution of arbitrary code

Posted by GitBox <gi...@apache.org>.
leezu merged pull request #17860: libjpeg-turbo: Fix user-assisted execution of arbitrary code
URL: https://github.com/apache/incubator-mxnet/pull/17860
 
 
   

----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
 
For queries about this service, please contact Infrastructure at:
users@infra.apache.org


With regards,
Apache Git Services

[GitHub] [incubator-mxnet] access2rohit commented on issue #17860: libjpeg-turbo: Fix user-assisted execution of arbitrary code

Posted by GitBox <gi...@apache.org>.
access2rohit commented on issue #17860: libjpeg-turbo: Fix user-assisted execution of arbitrary code
URL: https://github.com/apache/incubator-mxnet/pull/17860#issuecomment-600372763
 
 
   Woah! That's a serious security risk you caught. BTW did you attempt to make a wheel after updating the dependency ? 

----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
 
For queries about this service, please contact Infrastructure at:
users@infra.apache.org


With regards,
Apache Git Services