Freetype GitHub Mirror (was: CVE-2015-9383 - freetype)

2019-12-13 Thread Bob Proulx
Werner LEMBERG wrote: > Bob, while I have your attention, would it be eventually possible to > make the FreeType mirroring on github work as Armin has detailed out > some months ago? Initially the work to do this didn't seem too bad. But the devil is in the details and the initial setup to push

Re: CVE-2015-9383 - freetype

2019-12-13 Thread Werner LEMBERG
> Many many thanks for all your (Werner and all savannah hackers) > efforts on put that on place again and thanks for such a detailed > explanation. > > It was amazing. Indeed, interesting stuff, and thanks for the quick fix! Bob, while I have your attention, would it be eventually possible

Re: CVE-2015-9383 - freetype

2019-12-13 Thread Marco Benatto
Hi Bob, everything seems to be working fine now! Many many thanks for all your (Werner and all savannah hackers) efforts on put that on place again and thanks for such a detailed explanation. It was amazing. Thanks once more and good luck with the migration! Marco Benatto Red Hat Product

Re: CVE-2015-9383 - freetype

2019-12-13 Thread Bob Proulx
I believe the attachments should all be available again. Very sorry for the disruption. The attachment directory was recently moved onto an nfs mounted volume and that volume was not mounted when you found those attachments inaccessible. The volume is mounted again now and therefore all of the

Re: CVE-2015-9383 - freetype

2019-12-13 Thread Marco Benatto
Hi Werner and Ineiev, thank you very much for your help on this! Much appreciated! Marco Benatto Red Hat Product Security On Fri, Dec 13, 2019 at 4:57 AM Ineiev wrote: > > On Fri, Dec 13, 2019 at 06:59:12AM +0100, Werner LEMBERG wrote: > > > > > > Generally, they don't disappear unless users

Re: CVE-2015-9383 - freetype

2019-12-12 Thread Ineiev
On Fri, Dec 13, 2019 at 06:59:12AM +0100, Werner LEMBERG wrote: > > > > Generally, they don't disappear unless users remove them. > > OK, thanks for confirmation. With 'removing' you mean pressing the > trashbin button, right? Yes, exactly. > I'm quite sure that this didn't happen.

Re: CVE-2015-9383 - freetype

2019-12-12 Thread Werner LEMBERG
>> > I'm working on the analysis for the vulnerability described at >> > CVE-2015-9383. I know it has been a long time but I'm tried to >> > have access to its reproducer at: >> > >> > https://savannah.nongnu.org/bugs/?46346 >> > >> > so you still have access to it and could share with me? >>

Re: CVE-2015-9383 - freetype

2019-12-12 Thread Ineiev
Hello, On Thu, Dec 12, 2019 at 09:08:22PM +0100, Werner LEMBERG wrote: > > > I'm working on the analysis for the vulnerability described at > > CVE-2015-9383. I know it has been a long time but I'm tried to have > > access to its reproducer at: > > > > https://savannah.nongnu.org/bugs/?46346

Re: CVE-2015-9383 - freetype

2019-12-12 Thread Werner LEMBERG
Buona sera, Marco! > I'm working on the analysis for the vulnerability described at > CVE-2015-9383. I know it has been a long time but I'm tried to have > access to its reproducer at: > > https://savannah.nongnu.org/bugs/?46346 > > so you still have access to it and could share with me?