Re: [Lcms-user] LCMS 1.17 security fix issue

2009-04-04 Thread info
... Which are probably too strong words. I don't mean oCERT being a scam, or Andrea being untrustworthy. oCERT seems to me just a startup, and they did loud noise to gain popularity. What I dislike is they are doing loud noise using lcms. But there is nothing evil in Andreas or oCERT per se. Th

Re: [Lcms-user] LCMS 1.17 security fix issue

2009-04-04 Thread Cyrille Berger
On Saturday 04 April 2009, i...@littlecms.com wrote: > But for the rest it is ok, please make sure to always use lcms full > distributions. I only verify in full the release, not the candidates. Basically, the problem is that most distributions (at least the major ones) have a policy of not replac

Re: [Lcms-user] LCMS 1.17 security fix issue

2009-04-04 Thread Bob Friesenhahn
On Sat, 4 Apr 2009, i...@littlecms.com wrote: > > But for the rest it is ok, please make sure to always use lcms full > distributions. I only verify in full the release, not the candidates. Marti, It seems that candidate releases and full releases are distributed identically with same URLs and u

Re: [Lcms-user] LCMS 1.17 security fix issue

2009-04-04 Thread LittleCMS Support
> It seems that candidate releases and full releases are distributed identically with same URLs and using the same names. Oh, really? I am trying hard to avoid this, as obviously may cause lots of confusion. May be happened in past, but at least for now shouldn't happen. > There have also