Re: [blfs-dev] Okular CVE.

2018-11-27 Thread Ken Moffat via blfs-dev
On Tue, Nov 27, 2018 at 05:45:43PM -0600, Bruce Dubbs via blfs-dev wrote: > > > Should we just update okular to 18.08.1 ? Or use 18.08.3 ? > > > > > > > Will try 18.08.3 when I get to that, if it builds on top of > > everything else that is in current BLFS. > > I think we can wait two weeks and

Re: [blfs-dev] Okular CVE.

2018-11-27 Thread Bruce Dubbs via blfs-dev
On 11/27/2018 04:44 PM, Ken Moffat via blfs-dev wrote: On Tue, Nov 27, 2018 at 10:40:37PM +, Ken Moffat via blfs-dev wrote: https://nvd.nist.gov/vuln/detail/CVE-2018-1000801 okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchiv

Re: [blfs-dev] Okular CVE.

2018-11-27 Thread Ken Moffat via blfs-dev
On Tue, Nov 27, 2018 at 10:40:37PM +, Ken Moffat via blfs-dev wrote: > https://nvd.nist.gov/vuln/detail/CVE-2018-1000801 > > okular version 18.08 and earlier contains a Directory Traversal > vulnerability in function "unpackDocumentArchive(...)" in > "core/document.cpp" that can result i

[blfs-dev] Okular CVE.

2018-11-27 Thread Ken Moffat via blfs-dev
https://nvd.nist.gov/vuln/detail/CVE-2018-1000801 okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be explo

Re: [blfs-dev] perl module issues

2018-11-27 Thread Ken Moffat via blfs-dev
On Tue, Nov 27, 2018 at 10:54:44AM -0600, Bruce Dubbs via blfs-dev wrote: > On 11/27/2018 10:07 AM, Pierre Labastie via blfs-dev wrote: > > > Well, > > Up to now, I believed that we were trying to avoid bundled libraries in > > book packages. This is a small example: Perl Error is a small standalo

[blfs-dev] gvfs

2018-11-27 Thread Roger Koehler via blfs-dev
libusb is required to build gvfs. -- http://lists.linuxfromscratch.org/listinfo/blfs-dev FAQ: http://www.linuxfromscratch.org/blfs/faq.html Unsubscribe: See the above information page

Re: [blfs-dev] volume-key

2018-11-27 Thread Bruce Dubbs via blfs-dev
On 11/27/2018 11:07 AM, Roger Koehler via blfs-dev wrote: SWIG should be added to the list of required packages to build volume-key. It is not optional. Confirmed. It will be in my next commit. -- Bruce -- http://lists.linuxfromscratch.org/listinfo/blfs-dev FAQ: http://www.linuxfromscratch

[blfs-dev] volume-key

2018-11-27 Thread Roger Koehler via blfs-dev
SWIG should be added to the list of required packages to build volume-key. It is not optional. Roger -- http://lists.linuxfromscratch.org/listinfo/blfs-dev FAQ: http://www.linuxfromscratch.org/blfs/faq.html Unsubscribe: See the above information page

Re: [blfs-dev] perl module issues

2018-11-27 Thread Bruce Dubbs via blfs-dev
On 11/27/2018 10:07 AM, Pierre Labastie via blfs-dev wrote: On 26/11/2018 19:28, Alain Toussaint via blfs-dev wrote: Le lundi 26 novembre 2018 à 12:24 -0600, Bruce Dubbs via blfs-dev a écrit : Reference: http://wiki.linuxfromscratch.org/blfs/ticket/11246 (git and shipped perl modules) http://wi

Re: [blfs-dev] perl module issues

2018-11-27 Thread Pierre Labastie via blfs-dev
On 26/11/2018 19:28, Alain Toussaint via blfs-dev wrote: Le lundi 26 novembre 2018 à 12:24 -0600, Bruce Dubbs via blfs-dev a écrit : Reference: http://wiki.linuxfromscratch.org/blfs/ticket/11246 (git and shipped perl modules) http://wiki.linuxfromscratch.org/blfs/ticket/11295 (Error-0.17027 (Per