Bug#709146: several security issues due embedded t1lib

2013-05-22 Thread Ondřej Surý
Hi Norbert, On Wed, May 22, 2013 at 3:17 AM, Norbert Preining wrote: > On Di, 21 Mai 2013, Ondřej Surý wrote: >> Thanks, there's also an issue of embedded freetype1 which get's >> compiled into ttf2pk, which is the most horrible one, since freetype1 >> is unsupported for several years now. > > Ye

Bug#709146: several security issues due embedded t1lib

2013-05-21 Thread Norbert Preining
Hi Ondřej new changelog: texlive-bin (2013.20130522.30620-1) unstable; urgency=low * remove libgd and t1lib copies by removing the need to configure these libraries at all (Closes: #709145, #709146) Thanks Ondřej Surý for providing the patch. * build with system zzlib and ice, remo

Bug#709146: several security issues due embedded t1lib

2013-05-21 Thread Ondřej Surý
Package: texlive-bin Version: 2012.20120628-4 Severity: grave Tags: security Due to embedding t1lib, but not (at least) pulling the security patches from t1lib package, the texlive-bin suffers from: CVE-2011-0764 CVE-2011-0433 CVE-2011-1552 CVE-2011-1553 CVE-2011-1554 CVE-2010-2642 seems to be f