This is the mail archive of the
cygwin
mailing list for the Cygwin project.
Re: Updated [experimental]: findutils-4.3.4-1
- From: Eric Blake <ebb9 at byu dot net>
- To: cygwin at cygwin dot com
- Date: Wed, 30 May 2007 19:14:07 -0600
- Subject: Re: Updated [experimental]: findutils-4.3.4-1
- References: <announce.462AD782.5020607@byu.net> <871wgyfjhz.fsf@peder.flower> <465E178C.70104@byu.net>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
According to Eric Blake on 5/30/2007 6:32 PM:
> According to Jan Nieuwenhuizen on 5/30/2007 8:56 AM:
>> Findutils duplicates usr/lib/charset.alias from gettext. See
>
>> http://cygwin.com/cgi-bin2/package-grep.cgi?grep=usr%2Flib%2Fcharset.alias
>
> Bah; I thought I had taken care of this at one point. I would really like
> for this to be fixed in cygport, since any GNU package that uses gettext
> for i18n will attempt to create the same file as part of their package.
> Anyways, now that findutils has gone to 4.3.6 upstream, I was already
> planning on respinning the package soon.
What timing. Right after I started building 4.3.6, I got an email stating
that 4.3.7 will be released shortly to resolve security issue
CVE-2007-2452. So look for 4.3.7 instead, once it is ready to go.
Fortunately, cygwin is pretty much immune to CVE-2007-2452, since it is
pretty hard for cygwin's PATH_MAX of 260 to overflow the fixed buffer
length of 1026 in affected versions of locate :)
- --
Don't work too hard, make some time for fun as well!
Eric Blake ebb9@byu.net
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Cygwin)
Comment: Public key at home.comcast.net/~ericblake/eblake.gpg
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFGXiFe84KuGfSFAYARAn8HAJ4rBRa1hsrabukejo8oz77SQEL+VQCdG1nd
A41K4eUjl1JklcDj2z0EFak=
=oI1j
-----END PGP SIGNATURE-----
--
Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple
Problem reports: http://cygwin.com/problems.html
Documentation: http://cygwin.com/docs.html
FAQ: http://cygwin.com/faq/