Am Samstag, den 01.09.2018, 15:36 -0400 schrieb Richard Kimberly Heck:
> > Here's a simple patch which would need a bit of additional work,
> > but can
> > be a kind of proof of concept (and be tested). Comments?
The one which you accidentally committed looks promising.
Jürgen
> Updated patch.
Richard Kimberly Heck wrote:
> Are available for testing at http://ftp.lyx.org/pub/lyx/devel/lyx-2.3/.
> I suppose we should wait to prepare binaries until we have some feedback.
Before we announce we might consider to issue new warning as part of release.
Or even as a separate entry.
After the r
On Sun, Sep 02, 2018 at 12:59:22PM +0200, Pavel Sanda wrote:
> Unfortuntaly there is very little we can directly for 2.3.1.
> We should at least signalize in announcement for distro maintainers that this
> *is*
> issue and perhaps add some hint how to allow users to locally enable things
> in po
On 09/02/2018 10:50 AM, Scott Kostyshak wrote:
> On Sun, Sep 02, 2018 at 12:59:22PM +0200, Pavel Sanda wrote:
>
>> In longer-term -- if this ban continues -- we might try to ask Qt to do the
>> conversions instead of imagemagick, but that's is definitely not for 2.3.1.
> That might be a good backup
On 02/09/2018 12:59, Pavel Sanda wrote:
Richard Kimberly Heck wrote:
Are available for testing at http://ftp.lyx.org/pub/lyx/devel/lyx-2.3/.
I suppose we should wait to prepare binaries until we have some feedback.
Before we announce we might consider to issue new warning as part of release.
O
Am Sonntag, den 02.09.2018, 12:59 +0200 schrieb Pavel Sanda:
> After the recent discovery of ghoscript vulnerabilities distributions
> seem to
> actually follow suggestion of the security researcher who announced
> them
> and broadly ban any conversions from ps/eps/pdf/xps in imagemagick no
> matt
Daniel wrote:
>> in policy.xml so they can continue their work.
>> In longer-term -- if this ban continues -- we might try to ask Qt to do
>> the
>> conversions instead of imagemagick, but that's is definitely not for
>> 2.3.1.
>> Other ideas?
>> Pavel
>> https://www.bleepingcomputer.com/news/sec
On 09/02/2018 05:27 PM, Pavel Sanda wrote:
> Daniel wrote:
>>> in policy.xml so they can continue their work.
>>> In longer-term -- if this ban continues -- we might try to ask Qt to do
>>> the
>>> conversions instead of imagemagick, but that's is definitely not for
>>> 2.3.1.
>>> Other ideas?
>>