On Thu, Jun 23, 2005 at 09:40:11AM -0600, Gary V wrote:

# Correct me if I'm wrong, but I believe this problem applies to all
# versions between (and including) 2.61 to 2.72.

Well, AFAICT the offending line of code was introduced in the most
recent release cycle.  This is not to say that the original crash was
not present from a different bug(s) in the code; just that this
particular single byte overwrite past the end of the buffer is brand
new to the 2.7x series.

# Jordan, has any thought been given to publishing patches for major
# older versions? I know that Debian 3.1 (Sarge stable) uses 2.67 and
# something like that might be of value to package maintainers of
# distros like Debian that maintain older versions.

Only enough thought to dismiss the idea altogether.

The old versions have serious problems, many of which were finally
addressed in this latest release cycle (see 2.7x release notes for
full list).  Plus, frankly, the older code is overcomplicated and
painfully difficult to maintain or extend (current is only an
iterative improvement, if that).  Finally, the latest versions have
signficant accuracy improvements.

So, aside from this recent (admittedly serious) mea culpa which we
will address shortly, there is no real reason for people not to
upgrade.  It's Better.

Best,
--jordan

Attachment: pgpDrcpMHkulE.pgp
Description: PGP signature

Reply via email to