--===============2042834312== Content-Type: multipart/alternative; boundary="Boundary-00=_i5c1Jg6Ma+fSuJr" Content-Transfer-Encoding: 7bit Content-Disposition: inline --Boundary-00=_i5c1Jg6Ma+fSuJr Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Hi, We have discovered that a poorly craft patch for a security fix in lcms 1.17 (as far as I know distribution including the fix are Fedora Core, OpenSuse and Ubuntu) trigger a major issue in krita (it breaks loading of nearly all .kra files), the recently released 1.18 doesn't have, either the security issue, nor the problem, since even if we were to write a better patch for lcms, it is now impossible to be certain that the installed lcms 1.17 isn't contaminated. Which means that in a week, we will have to up the requirement for both branch and trunk to lcms 1.18. -- Cyrille Berger --Boundary-00=_i5c1Jg6Ma+fSuJr Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Hi,


We have discovered that a poorly craft patch for a security fix in lcms 1.17
(as far as I know distribution including the fix are Fedora Core, OpenSuse and
Ubuntu) trigger a major issue in krita (it breaks loading of nearly all .kra
files), the recently released 1.18 doesn't have, either the security issue, nor
the problem, since even if we were to write a better patch for lcms, it is now
impossible to be certain that the installed lcms 1.17 isn't contaminated.


Which means that in a week, we will have to up the requirement for both branch and trunk to lcms 1.18.


--
Cyrille Berger

--Boundary-00=_i5c1Jg6Ma+fSuJr-- --===============2042834312== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ koffice-devel mailing list koffice-devel@kde.org https://mail.kde.org/mailman/listinfo/koffice-devel --===============2042834312==--