First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 233962
Alias:
Product:
Component:
Status: RESOLVED
Resolution: DUPLICATE of bug 225851
Assigned To: Gentoo Linux bug wranglers <bug-wranglers@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Qian Qiao <qian.qiao@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 233962 depends on: Show dependency tree
Bug 233962 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-08-05 11:26 0000
app-text/texlive-2007-r3 depends on =media-libs/freetype-1* which has a
security vulnerability[1].

A quick look on all textlive's dependencies seem to suggest that the dependency
on =freetype-1* is redundant.

1. http://www.gentoo.org/security/en/glsa/glsa-200806-10.xml

Reproducible: Always

Steps to Reproduce:

------- Comment #1 From Rafał Mużyło 2008-08-05 14:58:39 0000 -------
It's not quite redundant,
there a certain tool, that has never been ported to
freetype 2.
It's ttf2tfm.

------- Comment #2 From Qian Qiao 2008-08-05 15:35:03 0000 -------
(In reply to comment #1)
> It's not quite redundant,
> there a certain tool, that has never been ported to
> freetype 2.
> It's ttf2tfm.
> 

It doesn't look like the author is having much time to port it to freetype
2[1].

So it looks like unless the fix for glsa-200806-10[2] is ported to freetype 1,
we are pretty stuck.

1.
http://groups.google.com/group/comp.text.tex/browse_thread/thread/3b41b0176fe8de6b/39fa200217617ac1
2. http://www.gentoo.org/security/en/glsa/glsa-200806-10.xml

------- Comment #3 From David Leverton 2008-08-05 16:22:00 0000 -------
(In reply to comment #2)
> So it looks like unless the fix for glsa-200806-10[2] is ported to freetype 1,
> we are pretty stuck.

The ChangeLog entry for freetype-1.4_pre20080316-r1 claims that it fixes the 3
CVEs referenced by that GLSA.  If you think it doesn't, I'm sure the fonts team
would like to know, otherwise the GLSA should be updated to mark that version
as unaffected.

------- Comment #4 From Jeroen Roovers 2008-08-05 16:29:32 0000 -------
Please refer to the last few comments in the bug I reference. AFAIK this is a
known issue.

*** This bug has been marked as a duplicate of bug 225851 ***

First Last Prev Next    No search results available      Search page      Enter new bug