From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: OpenSSL 1.1.0c security update required Date: Thu, 10 Nov 2016 20:40:18 -0500 Message-ID: <20161111014018.GA19957@jasmine> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="IJpNTDwzlM2Ie8A6" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:53075) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1c50pR-0007hl-4K for guix-devel@gnu.org; Thu, 10 Nov 2016 20:40:30 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1c50pN-0004ad-7L for guix-devel@gnu.org; Thu, 10 Nov 2016 20:40:29 -0500 Received: from out4-smtp.messagingengine.com ([66.111.4.28]:59606) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1c50pM-0004aC-N7 for guix-devel@gnu.org; Thu, 10 Nov 2016 20:40:25 -0500 Received: from localhost (c-76-124-102-142.hsd1.pa.comcast.net [76.124.102.142]) by mail.messagingengine.com (Postfix) with ESMTPA id D632425073 for ; Thu, 10 Nov 2016 20:40:19 -0500 (EST) Content-Disposition: inline List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel@gnu.org --IJpNTDwzlM2Ie8A6 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline OpenSSL 1.1.0c was released today. It fixes CVE-2016-{7053,7054,7055}: https://www.openssl.org/news/secadv/20161110.txt This version of OpenSSL is *not* currently used by any packages, so it's not a critical "drop everything and get to work" update, in my opinion. They changed how library runpaths are recorded at build time, and so our packaging no longer works: https://github.com/openssl/openssl/pull/1699 I can tackle it in the next few days if nobody else gets to it first. --IJpNTDwzlM2Ie8A6 Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIcBAEBCAAGBQJYJSF+AAoJECZG+jC6yn8IQYAP/RUN3Cwk7Xu3H9ereoWg17hN KChtmBJr8k/qIKH+OOb+KxziPdl+Hd0EqywBBKO4qUk8i3fNNqC2kmMD9Tr50kOD j6ES+MD8JsJHkHZkOU/En2xfhlh+hnkB5fnGzkUm7P4eNKWYjZY0TdMcu4xRO7/k d7C5yFXeKv5Ffs8kiAh1aWL4S55Dyy/FqeV/O6ZtXYHgHY0wsnCGEzgkXiTLv4rH m+47WXz2VfM2CFuhjXkgHa4NdPutRfUFoxsnGcUFCPfEyhnU7txxngww2V+gFoTL 036+0Nh/wqT68Q6dzDfCTh5+W1SQl6K9iKJC//Env6o64UsG2/P8p2+ZzIAs1H8+ elTmNqPmo7m9hEm3RorNXSuwjvxXlL1lalEIw/n2Gta4UB4plYFQfNJqDj0H4YaB 0QAKPFIzgGFx4B5DAPklTyzNjJj+f/5q+iUqIPHS9kzkWmDSZMatiFHeQX29qVNY hKYSrF4XcfktuikKw7cf95ImrZnWrKsqRUUm4XquO13vRUkbPSxhuQbPFRKwL6zG z0cbdlgjf6/bZrfKuPV1sfNJd42yfYLQd/fjmsVfeCCNwyAgZYr5k7EwdxwRVRYG 9A0x+myOWBlRV26R0sU0qSjmjgq1pHeamdYJMIlPQ6WqzMsp5up4bpH+3s4QAJ3n UvT559ojjfd2VkIWWhz+ =fEXR -----END PGP SIGNATURE----- --IJpNTDwzlM2Ie8A6--