> > As recently discovered the patch, which fixed CAN-2004-0888,
> > seems to be broken on all 64bit platforms (tested only on ia64
> > though).[1]
>=20
> Note that CAN-2005-0206 has been assigned for this issue.
>=20
> BTW, since you were able to track this one down, do you have any
> info about the other packages (cupsys, xpdf, etc) that also has
> CAN-2004-0888? Do they also need fixes, and do you have a patch for
> them?
>=20
Martin Pitt <martin <at> piware.de> told me, that tetex-bin is not
vulnerable as the file debian/patches/patch-CAN-2004-0888 continas
not the original patch form the xpdf developer, but already a fixed
version of the patch. So we should not be affected.
Sorry for the confusion!
Hilmar
--=20
sigmentation fault
Message-ID: <20050322103959 .GD2336@ preusse>
Date: Tue, 22 Mar 2005 11:39:59 +0100
From: Hilmar Preusse <email address hidden>
To: Joey Hess <email address hidden>, <email address hidden>
Cc: Martin Pitt <email address hidden>
Subject: Re: Bug#300182: tetex-bin still vulnerable to CAN-2004-0888 (CAN-2005-0206)
--XsQoSWH+UP9D9v3l Disposition: inline Transfer- Encoding: quoted-printable
Content-Type: text/plain; charset=us-ascii
Content-
Content-
On 18.03.05 Joey Hess (<email address hidden>) wrote:
> Hilmar Preusse wrote:
Hi,
> > As recently discovered the patch, which fixed CAN-2004-0888, patches/ patch-CAN- 2004-0888 continas
> > seems to be broken on all 64bit platforms (tested only on ia64
> > though).[1]
>=20
> Note that CAN-2005-0206 has been assigned for this issue.
>=20
> BTW, since you were able to track this one down, do you have any
> info about the other packages (cupsys, xpdf, etc) that also has
> CAN-2004-0888? Do they also need fixes, and do you have a patch for
> them?
>=20
Martin Pitt <martin <at> piware.de> told me, that tetex-bin is not
vulnerable as the file debian/
not the original patch form the xpdf developer, but already a fixed
version of the patch. So we should not be affected.
Sorry for the confusion!
Hilmar
--=20
sigmentation fault
--XsQoSWH+UP9D9v3l pgp-signature Disposition: inline
Content-Type: application/
Content-
-----BEGIN PGP SIGNATURE-----
10zwKFtukZhFxAQ J2dgMAjj/ XLSOBGmZQ1h8NFb y9JpjBmgEWLi0T JsZ0I2KxXUt1das rIhP6F8LjXdRg5L OCgxL6l2pt2AH41 zZFv JJJ/MY4jYjge3iN 3vbc6j5M0
Version: GnuPG v1.4.0 (Cygwin)
iQB1AwUBQj/
1vHVLirSQXAZMrr
6FdLu2R/
=OTL+
-----END PGP SIGNATURE-----
--XsQoSWH+ UP9D9v3l- -