<andi->
ris: go for the "full" point release for 19.09 then. That is probably the easiest part for us and rebuilds will happend anyway
<ris>
ok
<ris>
currently assessing the feasibility of a 2.4 fix - not looking likely
<ris>
will probably have to add "known vulnerabilities"
<andi->
do we have many consumerS?
<ris>
good question
<ris>
yes, several
<andi->
This is yet another case where security issues aren't black/white. One of them is yet another "simple" parsing error in binary formats. Now the user should decide if they care about that or if they only use *sane* images..
<ris>
i think it's about loading of serialized e.g. feature bundles
<ris>
so fairly obscure
<ris>
andi-: actually could probably look at trying to move some of those users to opencv3 - i bet some of those packages have support for both
<andi->
yeah, I was thinking the same. If you have the mental bandwidth to deal with that go for it :-)