joe problem on the main list

Yaakov (Cygwin Ports) yselkowitz@users.sourceforge.net
Mon Aug 4 22:57:00 GMT 2008


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Corinna Vinschen wrote:
| are you still with us?  There was a joe problem reported on the main
| list two weeks ago.

Jari,

There are also outstanding security issues with three of your packages:

mercurial: Directory traversal (CVE-2008-2942)
http://www.gentoo.org/security/en/glsa/glsa-200807-09.xml
http://sources.gentoo.org/viewcvs.py/gentoo-x86/dev-util/mercurial/files/mercurial-1.0.1-87c704ac92d4-git-patch.patch

pngcrush: User-assisted execution of arbitrary code (CVE-2008-1382)
http://www.gentoo.org/security/en/glsa/glsa-200805-10.xml
http://sources.gentoo.org/viewcvs.py/gentoo-x86/media-gfx/pngcrush/

python-paramiko: Information disclosure (CVE-2008-0299)
http://www.gentoo.org/security/en/glsa/glsa-200803-07.xml


Yaakov
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Cygwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEAREIAAYFAkiXiTEACgkQpiWmPGlmQSOE4gCguJ+2ak9kpzteK/2cOHqgSMYN
O6sAoNmvQG0punY9xp65IFlvA+KF1D12
=Ohus
-----END PGP SIGNATURE-----



More information about the Cygwin-apps mailing list