fontfile.diff applicable license, and general security issues
John Bradford <[email protected]>
| Newsgroups | gmane.comp.xfree86.forum |
|---|---|
| Message-ID | <[email protected]> |
Hi, Could somebody please clarify the license that applies to: ftp://ftp.xfree86.org/pub/XFree86/4.3.0/fixes/fontfile.diff (It is noted on the XFree86.org site that the 1.1 license applies to all versions of the software including and after 4.3.99.903, and that the 1.0 license applies to 4.3.99.902, and prior XFree86 versions. Since this patch has a timestamp which is inbetween these versions, it is not clear which license applies to it. Of course, I am aware that the license which applies to the original file to be patched also needs to be considered, but I know that in versions up to 4.3.99.902, that won't be the 1.1 license.) Also, was there ever a separated out patch for 4.3.0 to fix the integer overflows documented in CAN-2003-0730, or whether it is necessary to use 4.3.99.13 and patch with the above fontfile.diff patch to avoid all font-related security issues? Unfortunately, the simple, "use the latest version" approach to fixing security issues has become increasing difficult with XFree86, for two reasons: 1. I have never been able to find a policy as to whether your experimental releases include fixes for all known security issues, (for example, note that Linux kernel development policy is that known security issues in the stable series are not necessarily fixed in the development series). http://xfree86.org/security implies, but doesn't exactly spell out anywhere that some security issues are only fixed in future experimental snapshots. 2. I can see no way to verify the integrity of the development snapshots, no checksums or gpg signatures, and assume that users are just expected to hope for the best that your server is never compromised. At least stable releases can, (in addition to being verified against the md5 sums hosted on the same machine, which does little but guard against a man-in-the-middle attack, or a corrupted download), be verified against the copies being distributed by large Linux distributions such as Slackware. Please, make it easier for end users to stay up to date with security issues, licensing issues, and to check the integrity of data from your server and it's mirrors. John.