[Secure-testing-team] Embedded xpdf code: new incarnation found

Frank Küster frank at kuesterei.ch
Mon Jul 16 10:09:13 UTC 2007


harl at marsmenschen.com wrote:

> Hi Frank,
>
> there is a wiki page @ http://wiki.debian.org/EmbeddedCodeCopies

... which refers to http://svn.debian.org/wsvn/secure-testing/data/embedded-code-copies?op=file

You might want to add ipe to xpdf copies, but it uses only a tiny
amount of code.  What makes it a bit harder is that it doesn't use
original filenames, instead three files contain "Taken from Xpdf 2.01,
Copyright 2001-2002 Glyph & Cog, LLC" (or without the version number).
Those are src/ipecanvas/ipestdfonts.cpp, src/ipecanvas/ipefonts.cpp, and
src/ipelib/ipedct.cpp. 

I don't think that xpdf security issues, if they show up at all, are
much of a problem in this case.

Regards, Frank
-- 
Frank Küster
Single Molecule Spectroscopy, Protein Folding @ Inst. f. Biochemie, Univ. Zürich
Debian Developer (teTeX/TeXLive)



More information about the Secure-testing-team mailing list