>>> out of curiosity, has Apple contacted the FreeType dev group >>> concerning http://www.vupen.com/english/advisories/2010/2018 >>> ("FreeType Compact Font Format Two Buffer Overflow >>> Vulnerabilities")? >> >>Yes. Fixed in 2.4.2. > > Unfortunately, at least, Werner and me had not heard anything from > Apple (there is a possibility that we had overlooked their contact > in the spam messages).
This is not correct. Apple has contacted me privately. And indeed, I considered their mails as spam inadvertently, so they've fixed it in a slightly different way. Werner _______________________________________________ Freetype mailing list [email protected] http://lists.nongnu.org/mailman/listinfo/freetype
