fontfile.diff applicable license, and general security issues

John Bradford <[email protected]>
Newsgroups gmane.comp.xfree86.forum
Message-ID <[email protected]>
Hi,

Could somebody please clarify the license that applies to:

ftp://ftp.xfree86.org/pub/XFree86/4.3.0/fixes/fontfile.diff

(It is noted on the XFree86.org site that the 1.1 license applies to
all versions of the software including and after 4.3.99.903, and that
the 1.0 license applies to 4.3.99.902, and prior XFree86 versions.
Since this patch has a timestamp which is inbetween these versions, it
is not clear which license applies to it.

Of course, I am aware that the license which applies to the original
file to be patched also needs to be considered, but I know that in
versions up to 4.3.99.902, that won't be the 1.1 license.)

Also, was there ever a separated out patch for 4.3.0 to fix the
integer overflows documented in CAN-2003-0730, or whether it is
necessary to use 4.3.99.13 and patch with the above fontfile.diff
patch to avoid all font-related security issues?

Unfortunately, the simple, "use the latest version" approach to fixing
security issues has become increasing difficult with XFree86, for two
reasons:

1. I have never been able to find a policy as to whether your
experimental releases include fixes for all known security issues,
(for example, note that Linux kernel development policy is that known
security issues in the stable series are not necessarily fixed in the
development series).

http://xfree86.org/security implies, but doesn't exactly spell out
anywhere that some security issues are only fixed in future
experimental snapshots.

2. I can see no way to verify the integrity of the development
snapshots, no checksums or gpg signatures, and assume that users are
just expected to hope for the best that your server is never
compromised.  At least stable releases can, (in addition to being
verified against the md5 sums hosted on the same machine, which does
little but guard against a man-in-the-middle attack, or a corrupted
download), be verified against the copies being distributed by large
Linux distributions such as Slackware.

Please, make it easier for end users to stay up to date with security
issues, licensing issues, and to check the integrity of data from your
server and it's mirrors.

John.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.