public inbox for cygwin-apps@cygwin.com
 help / color / mirror / Atom feed
* [SECURITY] arj
@ 2015-06-02  7:08 Yaakov Selkowitz
  2015-06-26 17:09 ` Yaakov Selkowitz
  0 siblings, 1 reply; 3+ messages in thread
From: Yaakov Selkowitz @ 2015-06-02  7:08 UTC (permalink / raw)
  To: cygwin-apps

Jari,

The arj package is missing a number of security packages carried by
other distributions:

http://pkgs.fedoraproject.org/cgit/arj.git/plain/arj-3.10.22-security_format.patch
http://pkgs.fedoraproject.org/cgit/arj.git/plain/arj-3.10.22-security-afl.patch
http://pkgs.fedoraproject.org/cgit/arj.git/plain/arj-3.10.22-security-traversal-dir.patch
http://pkgs.fedoraproject.org/cgit/arj.git/plain/arj-3.10.22-security-traversal-symlink.patch

There are other patches in that repo which you may wish to consider as
well.

--
Yaakov


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [SECURITY] arj
  2015-06-02  7:08 [SECURITY] arj Yaakov Selkowitz
@ 2015-06-26 17:09 ` Yaakov Selkowitz
  2015-06-28  9:41   ` [SECURITY] arj (UPLOADED) Jari Aalto
  0 siblings, 1 reply; 3+ messages in thread
From: Yaakov Selkowitz @ 2015-06-26 17:09 UTC (permalink / raw)
  To: cygwin-apps; +Cc: jari.aalto

On Tue, 2015-06-02 at 02:08 -0500, Yaakov Selkowitz wrote:
> Jari,
> 
> The arj package is missing a number of security packages carried by
> other distributions:
> 
> http://pkgs.fedoraproject.org/cgit/arj.git/plain/arj-3.10.22-security_format.patch
> http://pkgs.fedoraproject.org/cgit/arj.git/plain/arj-3.10.22-security-afl.patch
> http://pkgs.fedoraproject.org/cgit/arj.git/plain/arj-3.10.22-security-traversal-dir.patch
> http://pkgs.fedoraproject.org/cgit/arj.git/plain/arj-3.10.22-security-traversal-symlink.patch
> 
> There are other patches in that repo which you may wish to consider as
> well.

Ping?

--
Yaakov


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [SECURITY] arj (UPLOADED)
  2015-06-26 17:09 ` Yaakov Selkowitz
@ 2015-06-28  9:41   ` Jari Aalto
  0 siblings, 0 replies; 3+ messages in thread
From: Jari Aalto @ 2015-06-28  9:41 UTC (permalink / raw)
  To: cygwin-apps

2015-06-26 20:09 Yaakov Selkowitz
<yselkowitz-rDBXBDvO6BXQT0dZR+AlfA(at)public.gmane.org>:
| On Tue, 2015-06-02 at 02:08 -0500, Yaakov Selkowitz wrote:
|
| > Jari,
| >
| > The arj package is missing a number of security packages carried by
| > other distributions:
| >
| > http://pkgs.fedoraproject.org/cgit/arj.git/plain/arj-3.10.22-security_format.patch
| > http://pkgs.fedoraproject.org/cgit/arj.git/plain/arj-3.10.22-security-afl.patch
| > http://pkgs.fedoraproject.org/cgit/arj.git/plain/arj-3.10.22-security-traversal-dir.patch
| > http://pkgs.fedoraproject.org/cgit/arj.git/plain/arj-3.10.22-security-traversal-symlink.patch
| >
| > There are other patches in that repo which you may wish to consider as
| > well.
|
| Ping?

Uploaded, thanks.
Jari

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2015-06-28  9:41 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2015-06-02  7:08 [SECURITY] arj Yaakov Selkowitz
2015-06-26 17:09 ` Yaakov Selkowitz
2015-06-28  9:41   ` [SECURITY] arj (UPLOADED) Jari Aalto

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).