[SECURITY] gd: CVE-2014-2497

2015-01-19 Thread Yaakov Selkowitz
Dr. Volker Zell, A security vulnerability has been made public for gd. Could you please: 1) port this patch to 2.0.36RC1, for the benefit of those package currently linked against libgd2: http://git.php.net/?p=php-src.git;a=patch;h=cf47536 2) AND could you bump gd to 2.1.1, which already inclu

Re: [SECURITY] jasper: CVE-2014-8137, CVE-2014-8138

2015-01-19 Thread Yaakov Selkowitz
On Mon, 2014-12-08 at 01:40 -0600, Yaakov Selkowitz wrote: > Dr. Volker Zell, > > Could you please update jasper to 1.900.1-14 with the latest patchset > from Fedora: > > http://sourceforge.net/p/cygwin-ports/jasper/ci/master/tree/ Sorry, I had the wrong CVE in $SUBJECT. The ones that have yet

Re: [HEADSUP] Dropping libopenssl098 from distro

2015-01-19 Thread Dr. Volker Zell
Hi I'm on business, no access to the logs...I will come back to this on friday. Ciao Volker > Vin Shelton writes: > Volker - > I can build XEmacs on 32-bit Cygwin. What doesn't work for you? > Thanks, > Vin Shelton > On Thu, Jan 15, 2015 at 6:27 AM, Dr. Volker

Re: [RFU] ELFIO-3.0-1

2015-01-19 Thread Corinna Vinschen
On Jan 19 16:36, Serge Lamikhov-Center wrote: > Please upload ELFIO-3.0-1: > > --- > cd ELFIO > > #src: > wget http://elfio.sourceforge.net/ELFIO-3.0-1-src.tar.xz > > #32bit: > #64bit: > wget http://elfio.sourceforge.net/ELFIO-3

Re: [HEADSUP Maintainers] _autorebase

2015-01-19 Thread Corinna Vinschen
On Jan 19 09:42, Andrew Schulman wrote: > > On Jan 17 11:16, Achim Gratz wrote: > > > Corinna Vinschen writes: > > > > What would be most helpful is to get a piece of documentation for us > > > > maintainers how to use the new _autorebase facility, sent with a fat > > > > HEADSUP subject, and which

Re: cygport improvements: upload, fish, src_prep_fini_hook

2015-01-19 Thread Corinna Vinschen
On Jan 19 09:23, Andrew Schulman wrote: > > > If SSH_KEY is set (in the environment, or in ~/.cygport.conf), then > > > cygport will > > > load that key into an ssh-agent if necessary. > > > > Minor nit: SSH_KEY as env var is so generic and easily confused with > > the variables set by ssh-age

Re: [HEADSUP Maintainers] _autorebase

2015-01-19 Thread Andrew Schulman
> On Jan 17 11:16, Achim Gratz wrote: > > Corinna Vinschen writes: > > > What would be most helpful is to get a piece of documentation for us > > > maintainers how to use the new _autorebase facility, sent with a fat > > > HEADSUP subject, and which we can ideally add to setup.html. > > > > The _a

[RFU] ELFIO-3.0-1

2015-01-19 Thread Serge Lamikhov-Center
Please upload ELFIO-3.0-1: --- cd ELFIO #src: wget http://elfio.sourceforge.net/ELFIO-3.0-1-src.tar.xz #32bit: #64bit: wget http://elfio.sourceforge.net/ELFIO-3.0-1.tar.xz

Re: cygport improvements: upload, fish, src_prep_fini_hook

2015-01-19 Thread Andrew Schulman
> > If SSH_KEY is set (in the environment, or in ~/.cygport.conf), then cygport > > will > > load that key into an ssh-agent if necessary. > > Minor nit: SSH_KEY as env var is so generic and easily confused with > the variables set by ssh-agent. Wouldn't something with CYGPORT in its > name b

Re: perl-5.18.4

2015-01-19 Thread Corinna Vinschen
On Jan 19 10:36, Marco Atzeri wrote: > On 1/19/2015 9:55 AM, Corinna Vinschen wrote: > >On Jan 15 18:51, Achim Gratz wrote: > >>Corinna Vinschen writes: > >>>However, why does a bump from 5.x to 5.y require a rebuild of other > >>>packages? Is the perl stuff backward incompatible from one minor >

Re: perl-5.18.4

2015-01-19 Thread Marco Atzeri
On 1/19/2015 9:55 AM, Corinna Vinschen wrote: On Jan 15 18:51, Achim Gratz wrote: Corinna Vinschen writes: However, why does a bump from 5.x to 5.y require a rebuild of other packages? Is the perl stuff backward incompatible from one minor version to the other?!? Anything linked against the

Re: perl-5.18.4

2015-01-19 Thread Corinna Vinschen
On Jan 15 18:51, Achim Gratz wrote: > Corinna Vinschen writes: > > However, why does a bump from 5.x to 5.y require a rebuild of other > > packages? Is the perl stuff backward incompatible from one minor > > version to the other?!? > > Anything linked against the Perl DLL must be rebuilt. Still,

Re: [ITA] _autorebase

2015-01-19 Thread Corinna Vinschen
On Jan 17 11:05, Achim Gratz wrote: > Here's the new version that places its files into /var instead of /etc > as per our previous discussion. > > The control files that belong to other packages (for rebasing of dynamic > objects) and go into /var/lib/rebase/dynpath.d have been split out each > in

Re: cygport improvements: upload, fish, src_prep_fini_hook

2015-01-19 Thread Corinna Vinschen
On Jan 17 18:25, Andrew Schulman wrote: > > You're right, this isn't pretty. :-( Any progress since then? > > OK, here's what I've worked out. > > If SSH_KEY is set (in the environment, or in ~/.cygport.conf), then cygport > will > load that key into an ssh-agent if necessary. Minor nit: SS

Re: [HEADSUP Maintainers] _autorebase

2015-01-19 Thread Corinna Vinschen
On Jan 17 11:16, Achim Gratz wrote: > Corinna Vinschen writes: > > What would be most helpful is to get a piece of documentation for us > > maintainers how to use the new _autorebase facility, sent with a fat > > HEADSUP subject, and which we can ideally add to setup.html. > > The _autorebase pack