RSS/Atom feed Twitter
Site is read-only, email is disabled

Bogus/corrupted GIMP 2.6.2 distribution file

This discussion is connected to the gimp-developer-list.gnome.org mailing list which is provided by the GIMP developers and not related to gimpusers.com.

This is a read-only list on gimpusers.com so this discussion thread is read-only, too.

3 of 3 messages available
Toggle history

Please log in to manage your subscriptions.

Bogus/corrupted GIMP 2.6.2 distribution file David Evans 31 Oct 20:22
  Bogus/corrupted GIMP 2.6.2 distribution file Michael Schumacher 31 Oct 22:21
   Bogus/corrupted GIMP 2.6.2 distribution file David Evans 31 Oct 22:33
David Evans
2008-10-31 20:22:18 UTC (about 16 years ago)

Bogus/corrupted GIMP 2.6.2 distribution file

As the current maintainer for GIMP on MacPorts, I wanted to report that we had an incident this morning where the file checksums (md5, sha1, rmd160) for the new 2.6.2 gimp distribution on one of the GIMP mirrors

http://gimp.site2nd.org/v2.6/

failed to match those of the official GIMP site and the other mirrors for that matter.[1]

The offending site has been removed from our list of GIMP mirrors but I thought that someone in the GIMP developer community might want to know about it as it could represent a possible attack.

Hope this is the right forum for this.

[1] http://trac.macports.org/ticket/17057

Michael Schumacher
2008-10-31 22:21:06 UTC (about 16 years ago)

Bogus/corrupted GIMP 2.6.2 distribution file

David Evans wrote:

As the current maintainer for GIMP on MacPorts, I wanted to report that we had an incident this morning where the file checksums (md5, sha1, rmd160) for the new 2.6.2 gimp distribution on one of the GIMP mirrors

http://gimp.site2nd.org/v2.6/

failed to match those of the official GIMP site and the other mirrors for that matter.[1]

I have removed this site from the mirrors list in svn (the update of the site might take some time, though). It looks like it is just redirecting to ftp.gimp.org, though...

Michael

David Evans
2008-10-31 22:33:54 UTC (about 16 years ago)

Bogus/corrupted GIMP 2.6.2 distribution file

Michael Schumacher wrote:

David Evans wrote:

As the current maintainer for GIMP on MacPorts, I wanted to report that we had an incident this morning where the file checksums (md5, sha1, rmd160) for the new 2.6.2 gimp distribution on one of the GIMP mirrors

http://gimp.site2nd.org/v2.6/

failed to match those of the official GIMP site and the other mirrors for that matter.[1]

I have removed this site from the mirrors list in svn (the update of the site might take some time, though). It looks like it is just redirecting to ftp.gimp.org, though...

Michael

That's what I see too so maybe the problem is in the redirection. Maybe MacPorts isn't handling that well.
So what's the good of a mirror site that just redirects to the master?

Dave