Re: setup.exe: feature request with patch

2006-03-10 Thread Igor Peshansky
On Thu, 9 Mar 2006, Joshua Daniel Franklin wrote: On Mon, 6 Mar 2006, Dr. F. Lee wrote: I deploy cygwin using unattended (http://unattended.sf.net/) and wpkg (http://www.wpkg.org/). It's useful for me to be able to specify additional packages to be installed on the command line.

Re: cygwin setup.exe reverse-video bug

2006-03-10 Thread Robert J. Cristel
Eric Blake wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 According to Robert J. Cristel on 3/6/2006 6:55 AM: settings - control panel - display - appearance - Scheme - High Contrast Black (Extra Large) Now run setup and you cannot read from the main program selection widow. Try to

Re: cygwin setup.exe reverse-video bug

2006-03-10 Thread Brian Dessent
Robert J. Cristel wrote: Here's a workaround: settings - control panel - display - appearance - item -window - font color palette is now activated select something that's not white Or you could just use a setup.exe snapshot with the fix. Brian

SECURITY: tar (CVE-2006-0300)

2006-03-10 Thread Yaakov S (Cygwin Ports)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 A malicious tar archive could trigger a Buffer overflow in GNU tar, potentially resulting in the execution of arbitrary code. Solution: apply this patch to 1.15.1:

SECURITY: tetex (CVE-2005-3193)

2006-03-10 Thread Yaakov S (Cygwin Ports)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 teTeX includes vulnerable XPdf code to handle PDF files, making it vulnerable to the execution of arbitrary code. Solution: apply this patch:

Re: SECURITY: tar (CVE-2006-0300)

2006-03-10 Thread Eric Blake
A malicious tar archive could trigger a Buffer overflow in GNU tar, potentially resulting in the execution of arbitrary code. Thanks for the heads up. I'll get on that right away, although it may be a day or two before I have the next compilation uploaded. -- Eric Blake volunteer cygwin tar