Remotely-triggerable crash in libpurple

Ethan Blanton elb at pidgin.im
Mon Jul 19 11:38:28 EDT 2010


Tomas Hoger spake unto us the following wisdom:
> Hi!
> 
> On Wed, 14 Jul 2010 01:18:24 -0700 Mark Doliner wrote:
> 
> > Public: no
> > Embargo date: How does August 5th sound?  That gives us one week to
> > finish making string changes, one week for translators to translate,
> > and one week for us to give you the 2.7.2 tarball and let you prepare
> > packages in advance.
> 
> We came across:
>   https://bugs.gentoo.org/show_bug.cgi?id=328667
> 
> which seems to be based on:
>   http://repos.archlinux.org/wsvn/packages/pidgin/?op=revision&rev=85620
> 
> So not really non-public any more.

This is Not OK.  I'm now taking suggestions on how to make sure
packagers understand their responsibilities.  :-P

So ... maybe we should do a 2.7.2 with nothing but this patch;
thoughts?

Ethan

-- 
The laws that forbid the carrying of arms are laws [that have no remedy
for evils].  They disarm only those who are neither inclined nor
determined to commit crimes.
		-- Cesare Beccaria, "On Crimes and Punishments", 1764
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 482 bytes
Desc: Digital signature
URL: <http://pidgin.im/cgi-bin/mailman/private/packagers/attachments/20100719/7dd50abe/attachment.pgp>


More information about the Packagers mailing list