Updated [experimental]: findutils-4.3.4-1

Eric Blake ebb9@byu.net
Thu May 31 07:46:00 GMT 2007

Hash: SHA1

According to Eric Blake on 5/30/2007 6:32 PM:
> According to Jan Nieuwenhuizen on 5/30/2007 8:56 AM:
>> Findutils duplicates usr/lib/charset.alias from gettext.  See
>>    http://cygwin.com/cgi-bin2/package-grep.cgi?grep=usr%2Flib%2Fcharset.alias
> Bah; I thought I had taken care of this at one point.  I would really like
> for this to be fixed in cygport, since any GNU package that uses gettext
> for i18n will attempt to create the same file as part of their package.
> Anyways, now that findutils has gone to 4.3.6 upstream, I was already
> planning on respinning the package soon.

What timing.  Right after I started building 4.3.6, I got an email stating
that 4.3.7 will be released shortly to resolve security issue
CVE-2007-2452.  So look for 4.3.7 instead, once it is ready to go.
Fortunately, cygwin is pretty much immune to CVE-2007-2452, since it is
pretty hard for cygwin's PATH_MAX of 260 to overflow the fixed buffer
length of 1026 in affected versions of locate :)

- --
Don't work too hard, make some time for fun as well!

Eric Blake             ebb9@byu.net
Version: GnuPG v1.4.5 (Cygwin)
Comment: Public key at home.comcast.net/~ericblake/eblake.gpg
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org


Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

More information about the Cygwin mailing list