delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2007/05/30/21:14:05

X-Spam-Check-By: sourceware.org
Message-ID: <465E215F.7080805@byu.net>
Date: Wed, 30 May 2007 19:14:07 -0600
From: Eric Blake <ebb9 AT byu DOT net>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.10) Gecko/20070221 Thunderbird/1.5.0.10 Mnenhy/0.7.5.666
MIME-Version: 1.0
To: cygwin AT cygwin DOT com
Subject: Re: Updated [experimental]: findutils-4.3.4-1
References: <announce DOT 462AD782 DOT 5020607 AT byu DOT net> <871wgyfjhz DOT fsf AT peder DOT flower> <465E178C DOT 70104 AT byu DOT net>
In-Reply-To: <465E178C.70104@byu.net>
X-IsSubscribed: yes
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

According to Eric Blake on 5/30/2007 6:32 PM:
> According to Jan Nieuwenhuizen on 5/30/2007 8:56 AM:
>> Findutils duplicates usr/lib/charset.alias from gettext.  See
> 
>>    http://cygwin.com/cgi-bin2/package-grep.cgi?grep=usr%2Flib%2Fcharset.alias
> 
> Bah; I thought I had taken care of this at one point.  I would really like
> for this to be fixed in cygport, since any GNU package that uses gettext
> for i18n will attempt to create the same file as part of their package.
> Anyways, now that findutils has gone to 4.3.6 upstream, I was already
> planning on respinning the package soon.

What timing.  Right after I started building 4.3.6, I got an email stating
that 4.3.7 will be released shortly to resolve security issue
CVE-2007-2452.  So look for 4.3.7 instead, once it is ready to go.
Fortunately, cygwin is pretty much immune to CVE-2007-2452, since it is
pretty hard for cygwin's PATH_MAX of 260 to overflow the fixed buffer
length of 1026 in affected versions of locate :)

- --
Don't work too hard, make some time for fun as well!

Eric Blake             ebb9 AT byu DOT net
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Cygwin)
Comment: Public key at home.comcast.net/~ericblake/eblake.gpg
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGXiFe84KuGfSFAYARAn8HAJ4rBRa1hsrabukejo8oz77SQEL+VQCdG1nd
A41K4eUjl1JklcDj2z0EFak=
=oI1j
-----END PGP SIGNATURE-----

--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019