Chris Travers wrote:
If TexLive had been around in 2002 and was statically linking to zlib, it would have been affected too. TeX does not link against zlib but LaTeX and XeTeX do. Similarly, arbitrary code execution vulnerabilities have been found in 2005 in libjpeg (also linked to by LaTeX and XeTeX). Again these predate TexLive.
Chris, these statements have to be wrong, at least in part : if TeX does not link against Zlib, then neither does LaTeX -- they are one and the same engine. -- ditto -- LibJpeg. Philip Taylor -------------------------------------------------- Subscriptions, Archive, and List information, etc.: http://tug.org/mailman/listinfo/xetex