Hi Santiago,

On Sun, May 21, 2017 at 04:38:51PM +0200, Santiago Vila wrote:
> severity 779207 wishlist
> thanks
> 
> This is still a feature request. Granted, a feature request that many
> people request, but still a feature request.
> 
> The proposed patch, even if it's "well tested", may or may not be
> compatible with whatever thing upstream finally implements.
> 
> If we only had some assurance that the upstream patch will be like
> this, then yes, it would be fine to apply the patch (I would be happy
> to backport the changes from upstream git or whatever source control
> version they have), but we don't really know, so no, I still do not
> feel like deviating from upstream, not under freeze, and not after
> the freeze.

How is this bug going?

I think we can assume upstream patch is like this.

The upstream has a 610beta release on 2010.
https://sourceforge.net/projects/infozip/files/unreleased%20Betas/UnZip%20betas/

It adds the support of -O/-I option for non-UTF8 encoding.

I checked the code in 610beta, and the patch applied in archlinux AUR[1][2],
most code are same, except:

1. Upstream code is surrounded by USE_ICONV_MAPPING.
2. 610b has a big refactor of command line parser. So the code of command parser
   is a big difference.

The left code is just same.

Cloud you backport this lovely feature in Debian?

[1] https://aur.archlinux.org/packages/unzip-iconv
[2] 
http://www.conostix.com/pub/adv/06-unzip60-alt-iconv-utf8_CVE-2015-1315.patch

Attachment: signature.asc
Description: PGP signature

Reply via email to