From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: Re: [PATCH 1/1] gnu: weex: Fix CVE-2005-3150. Date: Sat, 5 Nov 2016 13:53:18 -0400 Message-ID: <20161105175318.GA28799@jasmine> References: <665ebef4734c7a27067a5f3cdad30e65b562f4f7.1478324741.git.leo@famulari.name> <87eg2q6vui.fsf@kirby.i-did-not-set--mail-host-address--so-tickle-me> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="9amGYk9869ThD9tj" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:60586) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1c359g-0005YI-Ig for guix-devel@gnu.org; Sat, 05 Nov 2016 13:53:25 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1c359d-0006OS-Hh for guix-devel@gnu.org; Sat, 05 Nov 2016 13:53:24 -0400 Received: from out2-smtp.messagingengine.com ([66.111.4.26]:43898) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1c359d-0006Ns-EZ for guix-devel@gnu.org; Sat, 05 Nov 2016 13:53:21 -0400 Content-Disposition: inline In-Reply-To: <87eg2q6vui.fsf@kirby.i-did-not-set--mail-host-address--so-tickle-me> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Marius Bakke Cc: guix-devel@gnu.org --9amGYk9869ThD9tj Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sat, Nov 05, 2016 at 10:53:57AM +0000, Marius Bakke wrote: > Leo Famulari writes: >=20 > > * gnu/packages/patches/weex-CVE-2005-3150.patch: New file. > > * gnu/local.mk (dist_patch_DATA): Add it. > > * gnu/packages/ftp.scm (weex)[source]: Use it. >=20 > Wow, an 11 year-old CVE. There is a 2.8.0 release of weex from last year > on http://weex.sf.net, is that still affected? We have 2.6.15. And a 2.8.2 release! Updating is a better idea; I didn't realize it was an option. Done as 2d125a9b21306919e6123f76c0970988b14dadcf If your to-do list needs more entries, you can try increasing the values of 'past-years' and 'past-ttls' in (guix cve). --9amGYk9869ThD9tj Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIcBAEBCAAGBQJYHhyOAAoJECZG+jC6yn8IRgwP/0Dl4N7bolimk719oKlhtHFY pnEPGu+5qZ4EAMh1AwV6F9qfMQT766G84uRi03fPQCBppAYK9VoVCLgUx39qkpjt gIVWfl7fYagl1Zv+vmOHOsVFooMHc3BH/cbKZMdUBg2c/9Y+iGnHjLpYoXLrKkZ2 /nEXx3WvuZKeZan72HOc1XaS6+cKWzkDflhFVvewvL8utIh8dr+eO4Ssg/CWKJye EAIYoXaH3wKZrv2j0MForYbmhzfWUTgIe31Ujr7jl5g7nLEivrJxzWOCyCydAH4B 2P33ZTr52yEJhBnincBVZwTqL9xMJ3Fj+2u0VkDLxd1kgE4DS7F/wyxWfmPbLtDM 5HwiS9z8EFXYs+Ye32wj+DCqPDOqzL8Lya5eCBv3iQp+ADsFR+d+ECIEd1h0q70R 42ECOOfZNQ5V4oAd/PmJi8KGw8wb0y0oL5f6yMPIiXh0o7grnHECbfLFgqBhvSEo MWPwkFU/pYDhFScjbRYR7YaKRx4HUIbZLEB8P3iuWSe614a5w10c2Oy1QLUFIA3Z TQ6j8+xMZgnw2iFChVc4ONRMzJSsxFQ1tE5U8xGubbGQmLriye+fwco4k1wf3LpT k/3FVfVKQvMUEvhUdTcoF/P2S6IzF2c+XBE0cF9XpH27GcvtToTJOnWRHGSviMQd zBKx2D3lL1OC45SQIqax =znVj -----END PGP SIGNATURE----- --9amGYk9869ThD9tj--