pkgsrc-Users archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: xdg-utils-1.0.2 (Re: [HEADSUP] Removing vulnerable packages



| From: Thomas Klausner <wiz%NetBSD.org@localhost>
| Subject: Re: xdg-utils-1.0.2 (Re: [HEADSUP] Removing vulnerable packages
| Date: Tue, 5 Apr 2011 14:06:34 +0200
| Message-ID: <20110405120634.GR7727%danbala.tuwien.ac.at@localhost>

wiz> Also, drochner reported that the patches break the scripts on most
wiz> shells. So either we additionally depend on bash (which we'd like to
wiz> avoid) or we fix them differently.

wiz> I've backed out the patches for now, waiting for a better solution.
Thank you, drochner and Thomas.

I think I have collected the shell problem fix.
  http://www.ki.nu/~makoto/pkgsrc/misc/xdg-utils-1.0.2-2008-2009-2

Now includes two following.
--------
commit a0584be27324d6fe161c0b1c498b29be1b6f79de
Author: Kevin Krammer <kevin.krammer%gmx.at@localhost>
Date:   Thu Jan 24 20:24:51 2008 +0000

    Fixing security issue reported by Lubomir Kundrak 
<lkundrak%redhat.com@localhost>

---------
commit 485554bb64325e112a273cd41f8d735c4ec121c5
Author: Fathi Boudra <fabo%freedesktop.org@localhost>
Date:   Mon Oct 12 14:03:56 2009 +0000

    Remove bash requirement to xdg-open and xdg-email.
    Fix xdg-open to handle URL with '#' symbol.
----------
(I have omitted simply-removing-trailing-blank part.)  

Thanks,
---
Makoto Fujiwara, 
Chiba, Japan, Narita Airport and Disneyland prefecture.


Home | Main Index | Thread Index | Old Index