Re: Security fix for libtool

2009-11-24 Thread Bob Friesenhahn
On Tue, 24 Nov 2009, Philipp Thomas wrote: I'm maintaining libtool for SuSE/Novell and have a problem where I would need help from upstreams. You just released 2.2.6a to fix the local load problem. You need 2.2.6b (not 'a'!) to fix the problem. If the local load problem does affect 1.5.x I

Security fix for libtool

2009-11-24 Thread Philipp Thomas
I'm maintaining libtool for SuSE/Novell and have a problem where I would need help from upstreams. You just released 2.2.6a to fix the local load problem. The CVE says that libtool 1.x is also affected but sources have changed enough so that the fix for 2.x can't be applied. In particular the li

Re: Backport of libltdl changes to branch-1-5

2009-11-24 Thread Ralf Wildenhues
Hi Peter, * Peter O'Gorman wrote on Mon, Nov 16, 2009 at 05:06:26PM CET: > If you happen to be stuck using an older libltdl for some reason, > the attached untested patch should give you the same changes in > behavior as the badly numbered 2.2.6b release. If this passes the branch-1-5 testsuite f