From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: Re: [PATCH 1/1] gnu: libtiff: Fix some buffer overflows. Date: Wed, 16 Nov 2016 14:13:39 -0500 Message-ID: <20161116191339.GA5161@jasmine> References: <8760nne1n3.fsf@openmailbox.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="W/nzBZO5zC0uMSeA" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:42059) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1c75eX-0000ou-1n for guix-devel@gnu.org; Wed, 16 Nov 2016 14:13:50 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1c75eS-0001KQ-Br for guix-devel@gnu.org; Wed, 16 Nov 2016 14:13:49 -0500 Received: from out2-smtp.messagingengine.com ([66.111.4.26]:59183) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1c75eS-0001J0-5q for guix-devel@gnu.org; Wed, 16 Nov 2016 14:13:44 -0500 Content-Disposition: inline In-Reply-To: <8760nne1n3.fsf@openmailbox.org> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Kei Kebreau Cc: guix-devel@gnu.org --W/nzBZO5zC0uMSeA Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Nov 16, 2016 at 01:10:56PM -0500, Kei Kebreau wrote: > Leo Famulari writes: >=20 > > * gnu/packages/patches/libtiff-uint32-overflow.patch: New file. > > * gnu/local.mk (dist_patch_DATA): Add it. > > * gnu/packages/image.scm (libtiff/fixed)[source]: Use it. > The Guix linter tells me that ftp.remotesensing.org is not reachable. Is > it reachable for you? My connection could just be bad, or the server > temporarily down. The story of libtiff's domains is long and sordid. Here is the most recent chapter: http://www.asmail.be/msg0054885794.html We should update our packaging to address this. > Otherwise, LGTM. Thanks for the review! --W/nzBZO5zC0uMSeA Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIcBAEBCAAGBQJYLK/fAAoJECZG+jC6yn8IZ9EQANwpd8AO4oz+9QNj5IYwsEud Wgwde809yCyaEtOM6aBfZebXHMmD+UxQ0U/vKd6fKb2SO2+qBZUGgsxpi6zdQtyY KWWIudt7iYviE80VUdOHV+DgarwU549L37e0eyKx9XeN5pWAMsiabnJMxub+ohDH DGCMHcwcJVIFZAZKygcAKrLgtOyow6f55TLTpQ4ssUdQxpcy5p2901Lc003olCwg eJ6fz/Q8s5nkEQ5mRP2Y0fDWd05IOUfkQxVTBIhl5bv2UNMAWdH29hBGdMDTclsm b9dH210u+P3p2E7V5mwXzIw4QXxi6fVD1pS87ymMwSpNc6HOsUZ05VFasFxhml1C gF7fcWuMzc1AMuQ+dAtdHjfeNXebW9M1vZmNVcIKIvQFbEy43rfD5C7WrP56/dO0 kti0VjbZMwkdgS737PQEJ5uNcp/n0sNNnagf2LAGSE49p6VP1Y5+dMOUy/Tuusam HiaM/3Yd4Dl7Z+u4D/tLIz+rCITpnQEd4WpkXL5bf3tMuBf8BbFo6RUbWa7MNyTm vKAPzh75y2D4XJCzWmnP4fr+CTjl7UH+KDFlaEsL28y2mGeUnAQW9iz9JilArRKv kUMv8liM5liY38IHXYWkn4484+NBAAXp0aaOSbe6lLK0dYzl2dHY0c7jOiroJaU/ 3MOh9wKXrztc8Xbc1hDF =7I5e -----END PGP SIGNATURE----- --W/nzBZO5zC0uMSeA--