From 1be510f9529cb082f802408b472a77d074b394c0 Mon Sep 17 00:00:00 2001 From: Nicolas Vigier Date: Sun, 14 Apr 2013 13:46:12 +0000 Subject: Add zarb MLs html archives --- zarb-ml/mageia-dev/2011-October/008652.html | 102 ++++++++++++++++++++++++++++ 1 file changed, 102 insertions(+) create mode 100644 zarb-ml/mageia-dev/2011-October/008652.html (limited to 'zarb-ml/mageia-dev/2011-October/008652.html') diff --git a/zarb-ml/mageia-dev/2011-October/008652.html b/zarb-ml/mageia-dev/2011-October/008652.html new file mode 100644 index 000000000..ce7071997 --- /dev/null +++ b/zarb-ml/mageia-dev/2011-October/008652.html @@ -0,0 +1,102 @@ + + + + [Mageia-dev] About syslinux & libpng + + + + + + + + + +

[Mageia-dev] About syslinux & libpng

+ Erwan Velu + erwanaliasr1 at gmail.com +
+ Thu Oct 6 10:54:00 CEST 2011 +

+
+ +
I think part of the point I noticed didn't got understood/seen by people
+answering on this topic.
+I'll rephrase my wondering differently.
+
+Syslinux is a modern bootloader and use some libs (a zlib, a png one, a jpeg
+one, maybe other ...).
+
+The patch I was talking about is about to change the png lib with the main
+argument about the security. A possible scenario with a png attack.
+
+My point is that if we care about the security of the bootloaders regarding
+this kind of scenario, our work is very partial.
+If we want to stay consitent, we have to remove the jpeg lib too, the
+compression libs also.
+
+And this is true about all the other bootloaders. Did someone already
+thought about managing the security of the builtin libs inside gfxboot ?
+Do we care about the gunzip code of grub ?
+
+Being that intrusive regarding the static inclusion of this libs inside the
+bootloaders is just a work to report upstream and not the distro side.
+Only focusing on changing the libpng or not of syslinux isn't enough....
+
+Honestly, for me this really sounds like cutting hairs in 4 with a hammer.
+-------------- next part --------------
+An HTML attachment was scrubbed...
+URL: </pipermail/mageia-dev/attachments/20111006/354e3360/attachment.html>
+
+ + + + + + + + + + + + + + + + + + + + + + +
+

+ +
+More information about the Mageia-dev +mailing list
+ -- cgit v1.2.1