Daniel Stenberg <[email protected]> writes: > On Tue, 30 Jun 2015, Ander Juaristi wrote: > >> the library user (me, us, in this case) doesn't have to know >> anything about UTF-8, so we should rely on the library for >> everything UTF-8-related. > > I fully agree with this and I will stand by this rule. That's why I > sent the "security notice" pointing out this problem without actually > providing any fix, since the fix is for the libidn team (and really, > the distros) to apply and ship.
This is the reply I got: http://lists.gnu.org/archive/html/help-libidn/2015-07/msg00000.html I don't like much the "You need to pass valid UTF-8 to libidn" in there. Regards, Giuseppe
