Opened 9 years ago
Closed 9 years ago
#7498 closed enhancement (fixed)
graphite-1.3.6 was graphite2
Reported by: | Owned by: | ||
---|---|---|---|
Priority: | high | Milestone: | 7.10 |
Component: | BOOK | Version: | SVN |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
http://downloads.sourceforge.net/silgraphite/ as before.
For some reason, this one appears to be called graphite not graphite2. I have seen references to vulnerabilities flying around, and I now see that fedora committed this version with
update to latest release with unspecified security fixes
This is for 7.10.
Change History (6)
comment:1 by , 9 years ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
follow-up: 5 comment:2 by , 9 years ago
comment:3 by , 9 years ago
Summary: | graphite-1.3.6 → graphite-1.3.6 was graphite2 |
---|
Making summary changes to satisfy daily currency scripts.
comment:4 by , 9 years ago
Thanks for the link - I confirm they are identical, and both untar to graphite2-1.3.6/ : hopefully sf will be better under its new owners, but linking to github will be better. I have not yet tried wget, must remember to do that when I get around to the edit.
comment:5 by , 9 years ago
Replying to bdubbs@…:
We probably need to update the url to github:
https://github.com/silnrsi/graphite/releases
But with a note that it doesn't download with wget to the correct name. See http://www.linuxfromscratch.org/blfs/view/stable/general/liblinear.html for an example.
wget https://github.com/silnrsi/graphite/releases/download/1.3.6/graphite-1.3.6.tgz
got me graphite-1.3.6.tgz
comment:6 by , 9 years ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
Done in r17108. FWIW, the vulnerabilities (from a malicious graphite font) can be seen by clicking on the links in the security link from the firefox-45.0 release notes. I did not realise that firefox is using a current version (perhaps modified), even though it cannot be forced to use a system version - I assumed their code was based on an old version.
We probably need to update the url to github:
https://github.com/silnrsi/graphite/releases
But with a note that it doesn't download with wget to the correct name. See http://www.linuxfromscratch.org/blfs/view/stable/general/liblinear.html for an example.