From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: Re: [PATCH] gnu: mupdf: Fix CVE-2016-8674. Date: Tue, 25 Oct 2016 13:12:35 -0400 Message-ID: <20161025171235.GA4569@jasmine> References: <87twc0s73r.fsf@openmailbox.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="CE+1k2dSO48ffgeK" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:60648) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bz5HG-0003cp-JL for guix-devel@gnu.org; Tue, 25 Oct 2016 13:12:43 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bz5HD-0003i5-82 for guix-devel@gnu.org; Tue, 25 Oct 2016 13:12:42 -0400 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:54817) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1bz5HD-0003i1-3W for guix-devel@gnu.org; Tue, 25 Oct 2016 13:12:39 -0400 Content-Disposition: inline In-Reply-To: <87twc0s73r.fsf@openmailbox.org> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Kei Kebreau Cc: guix-devel@gnu.org --CE+1k2dSO48ffgeK Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Oct 25, 2016 at 12:53:28PM -0400, Kei Kebreau wrote: > Fix for https://blogs.gentoo.org/ago/2016/09/22/mupdf-use-after-free-in-p= df_to_num-pdf-object-c/. > From 97312c3c9e13688081aa513d1c94a9fff1274f75 Mon Sep 17 00:00:00 2001 > From: Kei Kebreau > Date: Tue, 25 Oct 2016 12:49:52 -0400 > Subject: [PATCH] gnu: mupdf: Fix CVE-2016-8674. >=20 > * gnu/packages/patches/mupdf-CVE-2016-8674.patch: New file. > * gnu/local.mk (dist_patch_DATA): Add it. > * gnu/packages/pdf.scm (mupdf): Use it. Thank you, please push! --CE+1k2dSO48ffgeK Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJYD5J/AAoJECZG+jC6yn8It/QQAMxzUp904fJL2BGXu41sWRMj x4z6aWxMEr77ydt450XnMMz69T7NTKkpq8kpB3kioCT+Sj+qLrAEE79VIIbtmpKH OKCt0Rllj3nrKpRGm8BIvFLedgX96u7K3bEWSH5xyv/+6DQ4/19w1NPx9waLJONX b+UhPuad3pvLsKmaJa3NpMSpW3x9MEBGWLz5N/rZVINB/Vo/Uk8EuchnanVqHFXF MxQb8yA25vd4tg8iFkCBWtIDonlY53eZ/AaXVg2PgUj/o4JC5YAxH89pIyGE1/3i zHBgVGAZvYtlHTMnT//MSuc43LVRIcEttYro0TgNOl7pIXHlo+RejBPRvC98F+ag 76mLLsLwst+SWjwB+gX/8B61tWkldt0aKHdkhdr79T8Dvo+zqTpFfqm79Zf5ADLs oErbwnKwyPS/WxbHxopI8meyauPZCYLXH2xMISfzEIQZt2KW/oGW5pBrP5fMbnmE JI8UEVqQGZq3FvatmF3pKhDg8G7UA9dq1emJXQ+PYN7mgMRgOnM6dup0drfHkXPx S5xDa6jihwJW449L00Lcpn4WKVZTlRUApUcKVvLlxbHWHtyWSxSxkNzPRjUCLM37 +4D7dEzK4X4aXdz/3H7JRnW9VpP0LQcx03uFLXb3mHxHa568YkvhB90lhNHVvG7P s/MsOPKxqQ5graJipJ1+ =U60P -----END PGP SIGNATURE----- --CE+1k2dSO48ffgeK--