[Top][All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Gnu-arch-users] Emgergency release of tla-1.2.1pre1

From: James Blackwell
Subject: [Gnu-arch-users] Emgergency release of tla-1.2.1pre1
Date: Sat, 17 Apr 2004 02:41:53 -0400
User-agent: Mutt/

The version of libneon that is packaged with tla 1.2.0 contains a format
string vulnerability. For more information, visit the disclosure at or
visit the libneon page at Tla users can be
affected if they download archives from untrusted sources. 

As such, I have put together tla-1.2.1pre1. This version of tla has
libneon .25.5 included. I have tested downloading with HTTP and WebDAV,
and they seem to work fine. Uploading with WebDAV has not been tested.

tla-1.2.1pre1 is available at The detached signature 
can be found at

I recommend that all people that download arch archives from untrusted 
locations upgrade to tla-1.2.1pre1 immediately.

For those that are used to building tla straight from the archive the
following steps may work for you: 

$ tla register-archive{archives}/2004
$ tla get address@hidden/dists--jblack--1.1 tla-1.2.1pre1
$ cd tla-1.2.1pre1
$ tla buildcfg -r configs/devo.tla-1.2.1pre1
$ cd src
$ mkdir =build
$ cd =build
$ ../configure
$ make
$ su
[enter password]
# cp tla/tla/tla /usr/local/bin


James Blackwell

James Blackwell          Please do not send me carbon copies of mailing
Smile more!              list posts. Such mail is unsolicited. Thank you!

GnuPG (ID 06357400) AAE4 8C76 58DA 5902 761D  247A 8A55 DA73 0635 7400

Attachment: signature.asc
Description: Digital signature

reply via email to

[Prev in Thread] Current Thread [Next in Thread]