Skip to content

[xpm-nox] Current libXpm is very, very old. #27360

@mal359

Description

@mal359

Description / Steps to reproduce the issue

The current XPM library is based upon a version sourced from an XFree86 release from 1999. Since then, multiple vulnerabilities have been reported.

I have tinkered with rebasing upon the latest libXpm from FreeDesktop, and I'm happy to report that in my test environment, no programs have been broken.

Cygwin packages the latest release version, as well.

Expected behavior

Expected to have decently-aged libraries upon pacman -Syu.

Actual behavior

Actual packaged libXPM is very old and has unpatched vulnerabilities, per the PKGBUILD.

Verification

Windows Version

MINGW64_NT-10.0-26100

MINGW environments affected

  • MINGW64
  • MINGW32
  • UCRT64
  • CLANG64
  • CLANGARM64

Are you willing to submit a PR?

Yes

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions