-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Open
Labels
Description
Description / Steps to reproduce the issue
The current XPM library is based upon a version sourced from an XFree86 release from 1999. Since then, multiple vulnerabilities have been reported.
I have tinkered with rebasing upon the latest libXpm from FreeDesktop, and I'm happy to report that in my test environment, no programs have been broken.
Cygwin packages the latest release version, as well.
Expected behavior
Expected to have decently-aged libraries upon pacman -Syu.
Actual behavior
Actual packaged libXPM is very old and has unpatched vulnerabilities, per the PKGBUILD.
Verification
- I have verified that my MSYS2 is up-to-date before submitting the report (see https://www.msys2.org/docs/updating/)
Windows Version
MINGW64_NT-10.0-26100
MINGW environments affected
- MINGW64
- MINGW32
- UCRT64
- CLANG64
- CLANGARM64
Are you willing to submit a PR?
Yes