guix-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH 0/1] Help wanted grafting Expat (CVE-2016-0718)


From: Ludovic Courtès
Subject: Re: [PATCH 0/1] Help wanted grafting Expat (CVE-2016-0718)
Date: Thu, 19 May 2016 14:19:59 +0200
User-agent: Gnus/5.13 (Gnus v5.13) Emacs/24.5 (gnu/linux)

Hi!

Leo Famulari <address@hidden> skribis:

> On Wed, May 18, 2016 at 12:36:50PM -0400, Leo Famulari wrote:
>> I've attached my attempt at fixing CVE-2016-0718 in Expat [0]. The
>> grafted expat updates to 2.1.1 and applies the patch from [1].
>> 
>> The problem is that, when trying build something that depends on expat,
>> I seem to have to rebuild *many* things.
>
> Of course this would happen, since I had removed the CVE-2015-1283 patch
> from expat package definition. D'oh.
>
> I've attached an updated patch that seems to work as expected.
>
> This patch uses the CVE-2016-0718 patch from Debian [0], which has the
> same diffs but does not require use of (patch-flags).
>
> It also includes an update to the patch for CVE-2015-1283 [1], which
> apparently relied on undefined behavior.
>
> Finally, it does not upgrade to 2.1.1. This patch series does apply to
> 2.1.0.

This variant LGTM.

> --- /dev/null
> +++ b/gnu/packages/patches/expat-CVE-2016-0718.patch
> @@ -0,0 +1,757 @@
> +Copied from Debian

Could you add a URL here, for reference?

> +++ b/gnu/packages/patches/expat-CVE-2016-0718.patch
> @@ -0,0 +1,757 @@
> +Copied from Debian

Same here.

Thank you!

Ludo’.



reply via email to

[Prev in Thread] Current Thread [Next in Thread]