conda-forge / freetype-feedstock

A conda-smithy repository for freetype.
BSD 3-Clause "New" or "Revised" License
0 stars 15 forks source link

fix for CVE-2022-37434 #50

Closed ekomarova closed 1 year ago

ekomarova commented 1 year ago

Checklist

conda-forge-linter commented 1 year ago

Hi! This is the friendly automated conda-forge-linting service.

I just wanted to let you know that I linted all conda-recipes in your PR (recipe) and found it was in an excellent condition.

ekomarova commented 1 year ago

This is https://nvd.nist.gov/vuln/detail/CVE-2022-37434. This affects freetype since freetype contains zlib sources. Patch is here: https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1

ekomarova commented 1 year ago

By the way, it looks like this commit https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1 causes segfault in curl, so I'll update the patch now with a new change https://github.com/madler/zlib/commit/1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d

ocefpaf commented 1 year ago

Thanks @ekomarova!