[Bug 97628] New: CxImage component needs update

bugzilla-daemon at freedesktop.org bugzilla-daemon at freedesktop.org
Wed Sep 7 12:26:20 UTC 2016


https://bugs.freedesktop.org/show_bug.cgi?id=97628

            Bug ID: 97628
           Summary: CxImage component needs update
           Product: Spice
           Version: unspecified
          Hardware: Other
                OS: Windows (All)
            Status: NEW
          Severity: normal
          Priority: medium
         Component: win32 agent
          Assignee: spice-bugs at lists.freedesktop.org
          Reporter: fziglio at redhat.com

We are still relaying on CxImage to copy from/to the clipboard. Beside we use
very few features/formats of this library (basically Windows handle from/to raw
bmp/png) we are still using version 6.00. There are some problems with this
version, mostly that the zlib and libpng versions used are obsolete containing
security vulnerability in it.
It's not a big issue unless you connect to a malicious server which send some
specific crafted images.
One problem is that even the last version (7.02) use old versions of these
libraries.

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.freedesktop.org/archives/spice-bugs/attachments/20160907/98639821/attachment.html>


More information about the spice-bugs mailing list