<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=6076&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / luakit and CVE-2023-40476 - or - security in Devuan]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=6076</link>
		<description><![CDATA[The most recent posts in luakit and CVE-2023-40476 - or - security in Devuan.]]></description>
		<lastBuildDate>Fri, 13 Oct 2023 11:06:49 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[luakit and CVE-2023-40476 - or - security in Devuan]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44864#p44864</link>
			<description><![CDATA[<p>Hi people,</p><p>I stumbled upun a security problem today. Is there a solution for this kind of problem?</p><p>I use luakit. CVE-2023-40476 [1] applies to luakit via libwebkit2gtk-4.0-37 . So - I have questions:<br />- Why does libwebkit2gtk-4.0-37 depend on libgstreamer-plugins-bad1.0-0 - which is explicitly the less-maintained part of gstreamer?<br />- Do we really want to rely on Debian doing the right thing here?</p><p>[1] <a href="https://security-tracker.debian.org/tracker/CVE-2023-40476" rel="nofollow">https://security-tracker.debian.org/tra … 2023-40476</a></p>]]></description>
			<author><![CDATA[dummy@example.com (Plentyn)]]></author>
			<pubDate>Fri, 13 Oct 2023 11:06:49 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44864#p44864</guid>
		</item>
	</channel>
</rss>
