Skip to content

insecure dependency: Freeimage is littered with CVEs #221

@Sigmanificient

Description

@Sigmanificient

Hi, I am currently porting freej2me to nixpkgs (a linux package repository). Unfortunately, the package is stuck in draft due to the Freeimage dependency, which is littered with CVEs:

CVE-2021-33367
CVE-2021-40262
CVE-2021-40263
CVE-2021-40264
CVE-2021-40265
CVE-2021-40266
CVE-2023-47992
CVE-2023-47993
CVE-2023-47994
CVE-2023-47995
CVE-2023-47996

Due to the insecure nature of the dependency, it cannot be merged at the current state. I know that freej2me may not have high security concerns as it isn't a critical application, but I think using a freeimage should be avoided in it's current state.

I hope this can mark the start to migrating towards a vulnerability-free graphics library.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions