Skip to content

CVE-2014-7204: endless loop + disk usage bomb on minified js file #14

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
NicoHood opened this issue Dec 23, 2016 · 0 comments
Open

CVE-2014-7204: endless loop + disk usage bomb on minified js file #14

NicoHood opened this issue Dec 23, 2016 · 0 comments

Comments

@NicoHood
Copy link

I am quite sure this also applies to this software:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742605
https://git.archlinux.org/svntogit/packages.git/tree/trunk/CVE-2014-7204.patch?h=packages/ctags

Context:
I try to package arduino builder independent from arduino. Using pure ctags does not work because the arduino patches are required and using the new fork #2 was not implemented yet.

The whole dependency hell of arduino gives me headache. Could you please confirm to upstream packages and patch sources upstream instead of creating unique forks? This would give us way better maintenance, less data dedup, upstream bugsfixes/features and less security issues. This is a real issue and not something low priority to fix some day. You will likely miss issue like the one linked above.

--> One more reason to implement #2. The maintainer was also willing to help.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant