[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Recent flex security announcement





On Fri, Aug 26, 2016 at 9:52 PM Greg Wooledge <wooledg@eeg.ccf.org> wrote:
On Fri, Aug 26, 2016 at 12:41:54PM +0000, Mark Fletcher wrote:
> Stretch and sid are quoting version 2.6.1 and I can't see where they got
> that from, as upstream (sourceforge) latest version seems to be 2.6.0. And
> 2.6.1 claims to be the version with the fix.

*sigh* ... it just figures, as soon as you ask this, I cannot reach
http://ftp.gnu.org/ or https://ftp.gnu.org/ to look at the actual
versions.

Nor can I reach http://www.gnu.org/.  Nor can I ping either site.
Looks like they're just totally down.

However, https://packages.debian.org/stretch/flex does have a
flex_2.6.1.orig.tar.gz on it.  That's what Debian is using as their
upstream tarball, wherever it came from.  And in theory, the copyright
file should say where they got it from.

Aha! Mystery solved!

Sourceforge isn't the home for the project any more. It's now hosted at https://github.com/westes/flex/releases

And there, in all its glory, is release 2.6.1.

Interestingly Google is still giving the old Sourceforge home first in search results.

It did wander through my head yesterday that Sourceforge might not be the home for the project any more, but Google seemed so sure... :)

Anyway thanks for the help Greg.

Mark
 

Reply to: