<p dir="ltr">It is worth remembering that the described tampered web font scenario doesn't normally apply to XeTeX use scenarios.</p>
<div class="gmail_quote">Den 19 feb 2016 06:26 skrev "maxwell" <<a href="mailto:maxwell@umiacs.umd.edu">maxwell@umiacs.umd.edu</a>>:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">There is a vulnerability in the Graphite library:<br>
<a href="http://news.softpedia.com/news/vulnerability-in-font-processing-library-affects-linux-openoffice-firefox-500027.shtml" rel="noreferrer" target="_blank">http://news.softpedia.com/news/vulnerability-in-font-processing-library-affects-linux-openoffice-firefox-500027.shtml</a><br>
Reportedly the problems have been patched in version 1.3.5 of Graphite2. But the version of xetex I'm using (3.14159265-2.6-0.99992, from the TeX Live 2015 distro) says it uses Graphite2 v1.2.3. Will the next TeX Live distro's version of xetex use >= v.1.3.5?<br>
-- <br>
Mike Maxwell<br>
<a href="mailto:maxwell@umiacs.umd.edu" target="_blank">maxwell@umiacs.umd.edu</a><br>
"I cannot believe that our existence in this universe<br>
is a mere quirk of fate, an accident of history, an<br>
incidental blip in the great cosmic drama. Our<br>
involvement is too intimate. The physical species<br>
Homo may count for nothing, but the existence of<br>
mind in some organism on some planet in the universe<br>
is surely a fact of fundamental significance. Through<br>
conscious beings the universe has generated<br>
self-awareness." --Paul Davies<br>
<br>
<br>
--------------------------------------------------<br>
Subscriptions, Archive, and List information, etc.:<br>
<a href="http://tug.org/mailman/listinfo/xetex" rel="noreferrer" target="_blank">http://tug.org/mailman/listinfo/xetex</a><br>
</blockquote></div>