Remotely triggerable crash in libpurple

Mark Doliner mark at kingant.net
Thu Oct 15 19:56:21 EDT 2009


On Mon, Oct 12, 2009 at 10:51 AM, John Bailey <rekkanoryo at rekkanoryo.org> wrote:
> Mark Doliner wrote:
> <snip>
>> If all looks well with the patch then I propose throwing together a
>> lightweight 2.6.3, which is 2.6.2+this fix+any other small and
>> important bug fixes, with a minimum of string changes.
>>
>> -Mark
>
> Have there actually *been* enough string changes to be worth the effort to
> branch from i.p.p for one release?

Good question.  I'll try to do the release tonight.  I'll check if
there have been many string changes since 2.6.2.  If there have not
been then I'll release from trunk, otherwise I'll create a branch from
2.6.2 and cherrypick a few changes.

If anyone gets a hankerin' to work on any of this, feel free.  I don't
think I'll be able to start for at least a few more hours.

-Mark


More information about the security mailing list