Subject: CVS commit: pkgsrc/print/atril
From: Maya Rashish
Date: 2019-10-28 22:49:22
Message id: 20191028214922.BC2EBFA8D@cvs.NetBSD.org

Log Message:
atril: don't enable dvi support by default. bump pkgrevision.

This option is pulling in t1lib. t1lib is an enormous security risk.
It hasn't seen maintenance since 2011 and we have local patches for
security issues from 2011.

Given the lack of attention, it's likely there are more security
issues lurking.

Documents are usually obtained from untrusted sources, and thus are
considered a remote attack vector
Documents may embed their own fonts. If one embeds a T1 font, it might
be parsed by this unmaintained library.

To avoid this risk, rip out the t1lib dependency.

Files:
RevisionActionfile
1.50modifypkgsrc/print/atril/Makefile
1.4modifypkgsrc/print/atril/options.mk