Comment 65 for bug 26650

Revision history for this message
In , Martin Schulze (joey-infodrom) wrote : Re: Bug#342292: tetex-bin: Multiple exploitable heap overflows in embedded xpdf copy

Hi Frank!

Frank Küster wrote:
> I looked at both, and it seems that Martin's does more. I'm speaking of
> the patch attached to http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=342292;msg=136
>
> It introduces limits.h and does the same we did for the xpdf patches at
> the beginning of the year, namely change code that can be optimized away
> by compilers.

*sigh* You are correct. I'll add the missing bits as well.

> It seems to me that Martin Pitt's patch also has everything that yours
> (Joey's) has, but I'm not completely sure; anyway it seems that also the
> stable packages should use the code with limits.h.

Aye.

> Am I correct that the other issues that Florian found are not addressed
> by any patch yet, and have not yet been widely published? Should I
> delay an upload to sid until this can be fixed, too?

Which issues? *phear*

Regards,

 Joey

--
If nothing changes, everything will remain the same. -- Barne's Law

Please always Cc to me when replying to me on the lists.