Status of libXpm? - Xwindows

This is a discussion on Status of libXpm? - Xwindows ; What is up with libXpm? There was a "recent" alert regarding security vulnerabilities in this library. I checked what is alleged to be the "official home page" for this library. Still the latest version noted there and in ftp.x.org/contrib/libraries is ...

+ Reply to Thread
Results 1 to 3 of 3

Thread: Status of libXpm?

  1. Status of libXpm?

    What is up with libXpm? There was a "recent" alert regarding
    security vulnerabilities in this library. I checked what is alleged
    to be the "official home page" for this library. Still the latest
    version noted there and in ftp.x.org/contrib/libraries is 3.4k. The
    maintainer's (Arnaud Le Hors) email address appears to be no longer
    valid, either at the email address noted there nor at another one I
    found for him.

    I tried applying each of the two patches mentioned in the security
    advisory against the 3.4k tarball, but multiple patch errors
    resulted.

    Suggestions?

    --
    Jim Seymour | PGP Public Key available at:
    WARNING: The "From:" address | http://www.uk.pgp.net/pgpnet/pks-commands.html
    is a spam trap. DON'T USE IT! |
    Use: jseymour@LinxNet.com | http://jimsun.LinxNet.com

  2. Re: Status of libXpm?

    jseymour@LinxNet.com (Jim Seymour) writes in comp.windows.x:
    |What is up with libXpm? There was a "recent" alert regarding
    |security vulnerabilities in this library. I checked what is alleged
    |to be the "official home page" for this library. Still the latest
    |version noted there and in ftp.x.org/contrib/libraries is 3.4k. The
    |maintainer's (Arnaud Le Hors) email address appears to be no longer
    |valid, either at the email address noted there nor at another one I
    |found for him.
    |
    |I tried applying each of the two patches mentioned in the security
    |advisory against the 3.4k tarball, but multiple patch errors
    |resulted.

    The patches issued by X.Org are meant to be applied against the version
    of libXpm in the X.Org X11R6.8 source tree. I don't know if the
    original libXpm distribution is being maintained by anyone anymore.

    --
    __________________________________________________ ______________________
    Alan Coopersmith * alanc@alum.calberkeley.org * Alan.Coopersmith@Sun.COM
    http://www.csua.berkeley.edu/~alanc/ * http://blogs.sun.com/alanc/
    Working for, but definitely not speaking for, Sun Microsystems, Inc.

  3. Re: Status of libXpm?

    In article ,
    Alan Coopersmith writes:
    [snip]
    >
    > The patches issued by X.Org are meant to be applied against the version
    > of libXpm in the X.Org X11R6.8 source tree.


    Yeah, I figured that, but I figured it wouldn't hurt to give it a go,
    either.

    > I don't know if the
    > original libXpm distribution is being maintained by anyone anymore.


    Apparently not. Not as an independent project, anyway.

    But it turns out the xc/extras/Xpm directory tree from the
    X11R6.8.1-src1.tar.gz tarball builds on its own, following the
    README.html instructions, same as xpm-3.4k did. It installs
    libXpm with the same library version number as 3.4k did.

    Thanks for the follow-up.

    --
    Jim Seymour | PGP Public Key available at:
    WARNING: The "From:" address | http://www.uk.pgp.net/pgpnet/pks-commands.html
    is a spam trap. DON'T USE IT! |
    Use: jseymour@LinxNet.com | http://jimsun.LinxNet.com

+ Reply to Thread