On Thu, Nov 14, 2002, Ian Alexander wrote:

> Problem is related to not having vsnprintf/snprintf on host system (in
> my case, solaris 2.5.1).  The first patch fixes this problem in rpm.
> You will also need to apply the second patch to the openpkg.spec.
> Hope this helps someone else out there.
> 
Dear Ian,
Ralf and i discussed the inclusion of your patch into OpenPKG today. We
decided not to include it. The use of sprintf(3) as a replacement for
snprintf(3) has a high potential to cause buffer overflows, leading to
program crashes and opening security issues. The price to support this
outdated Solaris v2.5.1 is too high. Nevertheless, the patch basically
works and i hope it will help you and probably others to use OpenPKG on
affected platforms.

--
[EMAIL PROTECTED]
Development Team, Application Services, Cable & Wireless Deutschland GmbH
______________________________________________________________________
The OpenPKG Project                                    www.openpkg.org
User Communication List                      [EMAIL PROTECTED]

Reply via email to