X-Spam-Check-By: sourceware.org
Message-ID: <465E215F.7080805@byu.net>
Date: Wed, 30 May 2007 19:14:07 -0600
From: Eric Blake <ebb9@byu.net>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.10) Gecko/20070221 Thunderbird/1.5.0.10 Mnenhy/0.7.5.666
MIME-Version: 1.0
To: cygwin@cygwin.com
Subject: Re: Updated [experimental]: findutils-4.3.4-1
References: <announce.462AD782.5020607@byu.net> <871wgyfjhz.fsf@peder.flower> <465E178C.70104@byu.net>
In-Reply-To: <465E178C.70104@byu.net>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
X-IsSubscribed: yes
Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe@cygwin.com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin@cygwin.com>
List-Help: <mailto:cygwin-help@cygwin.com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner@cygwin.com
Mail-Followup-To: cygwin@cygwin.com
Delivered-To: mailing list cygwin@cygwin.com

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

According to Eric Blake on 5/30/2007 6:32 PM:
> According to Jan Nieuwenhuizen on 5/30/2007 8:56 AM:
>> Findutils duplicates usr/lib/charset.alias from gettext.  See
> 
>>    http://cygwin.com/cgi-bin2/package-grep.cgi?grep=usr%2Flib%2Fcharset.alias
> 
> Bah; I thought I had taken care of this at one point.  I would really like
> for this to be fixed in cygport, since any GNU package that uses gettext
> for i18n will attempt to create the same file as part of their package.
> Anyways, now that findutils has gone to 4.3.6 upstream, I was already
> planning on respinning the package soon.

What timing.  Right after I started building 4.3.6, I got an email stating
that 4.3.7 will be released shortly to resolve security issue
CVE-2007-2452.  So look for 4.3.7 instead, once it is ready to go.
Fortunately, cygwin is pretty much immune to CVE-2007-2452, since it is
pretty hard for cygwin's PATH_MAX of 260 to overflow the fixed buffer
length of 1026 in affected versions of locate :)

- --
Don't work too hard, make some time for fun as well!

Eric Blake             ebb9@byu.net
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Cygwin)
Comment: Public key at home.comcast.net/~ericblake/eblake.gpg
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGXiFe84KuGfSFAYARAn8HAJ4rBRa1hsrabukejo8oz77SQEL+VQCdG1nd
A41K4eUjl1JklcDj2z0EFak=
=oI1j
-----END PGP SIGNATURE-----

--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

