On 23.05.2024 21:29, Bernd Böckmann via Freedos-devel wrote:
I already incorporated rugxulos changes to my local copy of the ZOO
FreeDOS package repository. I will push the changes as soon as I get
write access to the repo. This is ZOO version 2.1.
Hey, that's really nice! :)
Unfortunately Debian and its derivatives no longer have zoo in the their
package repositories, but while playing with NetBSD I had stumbled upon
a directory traversal bug. You may want to take a look at
<https://gnats.netbsd.org/cgi-bin/query-pr-single.pl?number=55684> for
more information and further links. If this security flaw is fixed, it
might be applied to NetBSD (pkgsrc) and FreeBSD too.
There's also someone who has been updating zoo with bug fixes for
UNIX-like platforms on <https://github.com/troglobit/zoo>, maybe
cherry-picking some of them could make sense.
Thanks a lot for your work on this Bernd, and if you have time, I may
dig another zoo bug I had reported to Ubuntu back in the day but that's
for another time.
_______________________________________________
Freedos-devel mailing list
Freedos-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/freedos-devel