From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: bug#27993: Oniguruma (PHP and Ruby) security issues Date: Mon, 25 Feb 2019 21:08:28 -0500 Message-ID: <20190226020828.GA26247@jasmine.lan> References: <20170806202933.GA21954@jasmine.lan> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="GvXjxJ+pjyke8COw" Return-path: Received: from eggs.gnu.org ([209.51.188.92]:54633) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gySB4-0004bG-RK for bug-guix@gnu.org; Mon, 25 Feb 2019 21:09:03 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gySB4-0007S5-6F for bug-guix@gnu.org; Mon, 25 Feb 2019 21:09:02 -0500 Received: from debbugs.gnu.org ([209.51.188.43]:38493) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1gySB4-0007RG-0d for bug-guix@gnu.org; Mon, 25 Feb 2019 21:09:02 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1gySB3-0001LC-RA for bug-guix@gnu.org; Mon, 25 Feb 2019 21:09:01 -0500 Sender: "Debbugs-submit" Resent-To: bug-guix@gnu.org Resent-Message-ID: Content-Disposition: inline In-Reply-To: <20170806202933.GA21954@jasmine.lan> List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: 27993-done@debbugs.gnu.org --GvXjxJ+pjyke8COw Content-Type: text/plain; charset=us-ascii Content-Disposition: inline On Sun, Aug 06, 2017 at 04:29:33PM -0400, Leo Famulari wrote: > Recently several serious bugs were fixed in Oniguruma, > CVE-2017-{9224,9225,9226,9227,9228,9229}: [...] > I'm not sure exactly which Oniguruma release fixed the bugs. I'm still not sure, but our PHP package is using the latest Oniguruma, and a lot of time has passed since this bug was opened. Closing... --GvXjxJ+pjyke8COw Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAlx0n5wACgkQJkb6MLrK fwjKFxAAkuMQQl0Bz5ln6DUwBrc4uBVz7jGQ1W4JIWuVmen0h+th1EXzb/6ys88W vVsFkLGGCG7UNS/z9d5WI+NE4WYvRoUjfWrZQQvzUlvWixGyQ2Wqt7Cyw0zhi0Df S/zFxs0d3fRWci5I0ibwDjzt5UQb1D5V3/xJdz4NlS+dAYOzE9pd7Fc5KJiMyb/+ 4xnVdB3F9Hf6lmf6yKvQLJO8FsHUyCSUSGJktNXJnTb8dOWlcv3fTxQYqoDhOwP6 q53+Ro9+R0DShrx5UQ0XbIH/REWH2H1UIwOj6+r0ZmH9/s0CUrMu+I5G4Q10O2zT GZXFu9zVW04QB1Nif4YQVOmRsXc8dsNYnLmP5U2XRy1hJbDNwz/lKSwps3LxVs0c IBemIZpSc7c8jAOkVWmbhmKYeUqRX7V447Ml9CfYvHMZ2ObcBlfIE43RB7EZ5NoE aqHuYWRh5h6RdvlA0zvUvhpwjiLPdOgD4UkBGI8ydNN/sGXwZvYcnkyXBOv02PA6 QFCnILimMXeRF0DJC1xWpHHABXytDj2Vpi24QZlpOaXS5ZGyGEeSsq8nYvGbouqX vITmOeASVCYPYCbruWgajbjYqwEjM72Lxv8GaBXrSRAGDxLS6EWGLnhgg8SwNy+l pIPvJpoKdrf+9CRW3GX95JEIUTmNX2CcTtLU56R/Ch4HKWrLLH0= =NuR+ -----END PGP SIGNATURE----- --GvXjxJ+pjyke8COw--