[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: New xpdf vulnerabilities related to CAN-2004-0888



Hi!

Frank Küster [2004-11-01 17:43 +0100]:
> Why do you think this is a bad habit? 

Because every time a security bug pops up in xpdf, one needs to fix
not only xpdf itself, but also cupsys, tetex, kpdf, gpdf, and the
other gazillion packages that include a million different versions of
the xpdf code.

> As long as xpdf does not provide a library which we could use, what
> other choice is there (except rewriting it)?

Please do not get me wrong, this was not a blame against you :-) I
know that xpdf does not export a library, so there is only little a
Debian maintainer can do. It's a matter of upstream coordination
(mainly).

Sorry for the misunderstanding, and have a nice evening!

Martin

-- 
Martin Pitt                       http://www.piware.de
Ubuntu Developer            http://www.ubuntulinux.org
Debian GNU/Linux Developer       http://www.debian.org

Attachment: signature.asc
Description: Digital signature


Reply to: