This is the mail archive of the
cygwin-apps
mailing list for the Cygwin project.
Re: joe problem on the main list
- From: "Yaakov (Cygwin Ports)" <yselkowitz at users dot sourceforge dot net>
- To: cygwin-apps at cygwin dot com
- Date: Mon, 04 Aug 2008 17:56:49 -0500
- Subject: Re: joe problem on the main list
- References: <20080729093110.GA30864@calimero.vinschen.de>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Corinna Vinschen wrote:
| are you still with us? There was a joe problem reported on the main
| list two weeks ago.
Jari,
There are also outstanding security issues with three of your packages:
mercurial: Directory traversal (CVE-2008-2942)
http://www.gentoo.org/security/en/glsa/glsa-200807-09.xml
http://sources.gentoo.org/viewcvs.py/gentoo-x86/dev-util/mercurial/files/mercurial-1.0.1-87c704ac92d4-git-patch.patch
pngcrush: User-assisted execution of arbitrary code (CVE-2008-1382)
http://www.gentoo.org/security/en/glsa/glsa-200805-10.xml
http://sources.gentoo.org/viewcvs.py/gentoo-x86/media-gfx/pngcrush/
python-paramiko: Information disclosure (CVE-2008-0299)
http://www.gentoo.org/security/en/glsa/glsa-200803-07.xml
Yaakov
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Cygwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iEYEAREIAAYFAkiXiTEACgkQpiWmPGlmQSOE4gCguJ+2ak9kpzteK/2cOHqgSMYN
O6sAoNmvQG0punY9xp65IFlvA+KF1D12
=Ohus
-----END PGP SIGNATURE-----