[tex-live] Some minor patches against Build/source and perhaps something more important about ICU

Alexis Ballier aballier at gentoo.org
Fri Feb 29 19:27:23 CET 2008


Hi all,

For the time we've been using texlive 2007 here, I've had to patch it a
(very) little bit and since I've been slacking, now I have patches
pending that I forgot to send back to you for a while :)

So here they are, of course comments are very welcome:

100_all_build_mpost_at_compile_time.patch: It has been reported that
mpost was built during make install target and not during 'make' /
'make all' target. This patch should correct this. Refs [1].


120_all_omegafonts_parallel_make.patch: It seems texk/web2c/omegafonts/
is not parallel make safe due to a dependency problem in the makefiles.
This patch should correct this. Refs [2].


Now something that is probably more important: ICU has had a security
issue recently discovered (refs [3,4,5,6]). I've never been able to
make xetex build against system icu (either it uses internal headers or
icu does not install correctly all its headers; due to some things I've
seen in their headers I tend to think its the latter but I never really
jumped into that one); anyway, the fact is that it uses its own icu
copy that is vulnerable. I've patched this locally (better safe than
sorry) but I'm not sure if this vulnerability can affect xetex or not.
I don't know if its exploitable nor anything else, but I thought it
would be good to notify you about this.

Regards,

Alexis.




[1] https://bugs.gentoo.org/show_bug.cgi?id=201187
[2] https://bugs.gentoo.org/show_bug.cgi?id=209362
[3] http://secunia.com/advisories/28575
[4] https://bugzilla.redhat.com/show_bug.cgi?id=429023
[5] https://bugzilla.redhat.com/show_bug.cgi?id=429025
[6]
http://sourceforge.net/mailarchive/message.php?msg_name=d03a2ffb0801221538x68825e42xb4a4aaf0fcccecbd%40mail.gmail.com
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 120_all_omegafonts_parallel_make.patch
Type: text/x-patch
Size: 648 bytes
Desc: not available
Url : http://tug.org/pipermail/tex-live/attachments/20080229/16dd5493/attachment.bin 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 100_all_build_mpost_at_compile_time.patch
Type: text/x-patch
Size: 624 bytes
Desc: not available
Url : http://tug.org/pipermail/tex-live/attachments/20080229/16dd5493/attachment-0001.bin 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://tug.org/pipermail/tex-live/attachments/20080229/16dd5493/attachment-0002.bin 


More information about the tex-live mailing list