From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from NAM10-DM6-obe.outbound.protection.outlook.com (mail-dm6nam10on2104.outbound.protection.outlook.com [40.107.93.104]) by sourceware.org (Postfix) with ESMTPS id 4A44E385E83A for ; Wed, 21 Oct 2020 21:20:28 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.3.2 sourceware.org 4A44E385E83A ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Dq+alAKBi4K2JDOeLRgacC9CWOrZCgOltTY6FPpByTtUVGgS1BIUPdeJzpbn9tmlcJ1VW/RaKTK5PFAfo5j2jU6JMkfzglS9/j4wWbiPw3PvmmsB8E1lahvOMCunKVIq1InkycCc+Hn/+kxJdmte3MoOiM10VvkctosZX3py3jYvAya7n3JbuJwYr7X7XftkhMenYCG9k9kIeTtkKh5kPB38POBD+OoyJk3hqpLcYtafX1O4+aNDnwbzo4fEY3gX/h5+kTZO7VpW0H7488ehEn5Kmkc2Mv2k+wJ6p8q+bDyIje7tek3X5FD146yMxgLfSRXx/IK5mfbDYY9iTK9xNw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=+TZxnQhzZrJNodOwmibJgWjecPGEzKx5OqwDiHHGMlI=; b=PoPy04vLmP7ZYv0B5sdg99O3eK7I8zHcdiCZJ1uhpnaPrtvjyI+5cAtUopXt7CuKMgi4gZLqYd6omg7B1MrrFD212z7lz34IX8kkQ490FHDww96oKKZZJFVGN3Ka+81VowAW4Epix9swNp+gkXzjwzsIdmT9sFJ6Fbal2S0FCnVWRBDluaw5Wko6iBZpBMA93IKA6WP1jsiozhV5MHfRSR4f6bM+jJ1xsg1vjO6XTeQu+DmAfavAYto1ep4xutqKjalgCPyc4Kxt3fr8Xc+bkOMe7JE6SD//aV8iqIdZFpcRr2Ab5p3hyNub18oc+uJzf0qNoBYFS1lkvMxkHrU37Q== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cornell.edu; dmarc=pass action=none header.from=cornell.edu; dkim=pass header.d=cornell.edu; arc=none Received: from MN2PR04MB6176.namprd04.prod.outlook.com (2603:10b6:208:e3::13) by MN2PR04MB5583.namprd04.prod.outlook.com (2603:10b6:208:da::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3455.29; Wed, 21 Oct 2020 21:20:26 +0000 Received: from MN2PR04MB6176.namprd04.prod.outlook.com ([fe80::c144:d206:c369:af44]) by MN2PR04MB6176.namprd04.prod.outlook.com ([fe80::c144:d206:c369:af44%7]) with mapi id 15.20.3477.028; Wed, 21 Oct 2020 21:20:26 +0000 Subject: Re: libfreetype CVE FYI To: cygwin-apps@cygwin.com References: <3375f26a-9c09-9fba-387e-3ba07618eb9f@cornell.edu> <38e606cc-4c32-5067-dc86-a9d22cc88311@SystematicSw.ab.ca> <87mu0fmryr.fsf@Rainer.invalid> From: Ken Brown Message-ID: <5a53014f-1c97-0081-7b8f-e5a8d927912a@cornell.edu> Date: Wed, 21 Oct 2020 17:20:24 -0400 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:68.0) Gecko/20100101 Thunderbird/68.12.1 In-Reply-To: <87mu0fmryr.fsf@Rainer.invalid> Content-Type: text/plain; charset=windows-1252; format=flowed Content-Language: en-US Content-Transfer-Encoding: 7bit X-Originating-IP: [68.175.129.7] X-ClientProxiedBy: CH2PR18CA0031.namprd18.prod.outlook.com (2603:10b6:610:55::11) To MN2PR04MB6176.namprd04.prod.outlook.com (2603:10b6:208:e3::13) MIME-Version: 1.0 X-MS-Exchange-MessageSentRepresentingType: 1 Received: from [192.168.0.17] (68.175.129.7) by CH2PR18CA0031.namprd18.prod.outlook.com (2603:10b6:610:55::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3499.18 via Frontend Transport; Wed, 21 Oct 2020 21:20:26 +0000 X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: 5e758f62-19a5-4de6-635f-08d87607211d X-MS-TrafficTypeDiagnostic: MN2PR04MB5583: X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:8882; X-MS-Exchange-SenderADCheck: 1 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: XzoBLJUpJWDlL09qIQoDQbeayfV3BkMK8auv59p6H3SydzLVXBtTDUaQq6ivyytGVXVldy14C8iRJw2iVj1b0jK2axabaojgQ7toLElfgAcJOx4EE43s4VciNgbhe5+Nfb/TypgjiVwyS+S1fKkQZzCaUAcwXVu1XcJK5Y18PucvRK92XmjVfCaXKo0olSHXMUCMg24DkgMNYSvSxx7MRmkPu13Aw/61y3zT48DuSo2BZIh06qVI7h34MtuGfJiXhXpQQO1FuXQ0lYsmlLeEZ2Esim+wlN0LGGQ9PsADcJV6b1kWYDWqhTpmlg8gZJLm/XWGQA32/C12NPGyKcEXswBgmZth1KndDF0Nj/QdKloHilBMbpmnYh2tvNy/YM6W/5cvXIVn16iRyYGNwhN0nE9fjd5F+Ejoikxel724pR6GftWsRJ9O4gssxenAOW8a4awayzIG5ujwgmBIhHMZtg== X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR04MB6176.namprd04.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(39860400002)(346002)(376002)(136003)(396003)(366004)(5660300002)(316002)(83380400001)(2906002)(31696002)(16576012)(786003)(966005)(186003)(8936002)(53546011)(16526019)(3480700007)(478600001)(86362001)(8676002)(52116002)(6916009)(956004)(36756003)(6486002)(2616005)(26005)(75432002)(66946007)(66556008)(66476007)(31686004)(7116003)(4744005)(43740500002); DIR:OUT; SFP:1102; X-MS-Exchange-AntiSpam-MessageData: BbC/QYSSrVvPitJw4+Nn2OBNp1BMRCKa8rWRgJMgvMexiTMR8052EAA+k1e/AfFDZd4Fiahykoin/LJbC8B8THRmdiH2/aZMwGTyQ/KIqRVf5k2aIVb8GUfSH2sgiJoZV12vS7TVEM6RaPmPXyf04QB8Wr2npad9ttt1B856NtJQ3qDXf9lQLOXuQKXlseNsZxBhTr29mrhJLsoGZe6wOXKrgcsIO7+u0cXF78V5CKmH9rIsIKmMO8acRC2sF3k2+K9x8uCf435oygtXhQPPi2YLu6BXN0dwDyX8HKEiaOIP7jupV43x1rNXjUuzd2lNx8PHxKsNcPYV43BEPGzW1z+g4k1ij53MqtOrth6JRlaZnmTcVRFZc+MTHZbgrFICuIxkg5Y5oUGj1cwPfynY2AkfKqU1SyW+uU/O6HaeDuq4Z9HjjqZ3ociAc/W8X4vEW9Oq3BMoGpIiy0oSWAfYr3Pjy4aD809/3sDd3+nZ5HXG4YBhSjOIs7gGRnTiKeqFnE8gS8A5tTwGAFRf2gxYz1OvXbqpTMNsKx9muDrd62caMFw+ya39mSLqHRhCFL21O0nbuCblSqC0QIOh1JYgs6WaEtoO8nzJCYGObRtaCe2/EmgPG+H+KV+t/PvVTJ4fD5zQet0kWEecJ1v9a9NxqA== X-OriginatorOrg: cornell.edu X-MS-Exchange-CrossTenant-Network-Message-Id: 5e758f62-19a5-4de6-635f-08d87607211d X-MS-Exchange-CrossTenant-AuthSource: MN2PR04MB6176.namprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Oct 2020 21:20:26.6947 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 5d7e4366-1b9b-45cf-8e79-b14b27df46e1 X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: LX8axc0Z+06LQvuj8I74SUnZoYpri5Q2h+ZmlZcGBv8BNgvOc/yVxZGdXb5QVMt4KhdvIu80HjAhXPIRriwQIw== X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR04MB5583 X-Spam-Status: No, score=-4.4 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, MSGID_FROM_MTA_HEADER, NICE_REPLY_A, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H2, SPF_HELO_PASS, SPF_PASS, TXREP autolearn=ham autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on server2.sourceware.org X-BeenThere: cygwin-apps@cygwin.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Cygwin package maintainer discussion list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Oct 2020 21:20:50 -0000 On 10/21/2020 1:03 PM, Achim Gratz wrote: > Ken Brown via Cygwin-apps writes: >>> https://sourceforge.net/projects/freetype/files/freetype2/2.10.4/ >> >> Thanks, Brian. I'll update it. > > Did you intend to release this security / minor version update as a test > release? It would seem more prudent to just update the package or do > you expect problems? I did that because Fedora is still on 2.10.2, and I generally try to avoid getting ahead of Fedora on package releases. That's because (a) the Fedora maintainers are more knowledgeable than I am about many of the packages that I maintain, and (b) the update will get much more testing once Fedora releases it. That said, I agree that a security update should get high priority. So I'll wait a few more days for Fedora, and then I'll go ahead and promote the test release to "current", regardless of what Fedora does. Ken