From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: Re: 03/04: gnu: openjpeg: Add fixes for CVE-2016-{9850,9851}. Date: Sun, 11 Dec 2016 02:13:27 -0500 Message-ID: <20161211071327.GA13305@jasmine> References: <20161210200323.4764.51747@vcs.savannah.gnu.org> <20161210200324.4B8C12201B9@vcs.savannah.gnu.org> <20161211060214.GA30740@jasmine> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:49387) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cFyKD-0001VV-DP for guix-devel@gnu.org; Sun, 11 Dec 2016 02:13:34 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cFyK9-0007uq-DO for guix-devel@gnu.org; Sun, 11 Dec 2016 02:13:33 -0500 Received: from out4-smtp.messagingengine.com ([66.111.4.28]:50597) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cFyK9-0007ul-6t for guix-devel@gnu.org; Sun, 11 Dec 2016 02:13:29 -0500 Received: from localhost (c-73-188-17-148.hsd1.pa.comcast.net [73.188.17.148]) by mail.messagingengine.com (Postfix) with ESMTPA id 68B01248EF for ; Sun, 11 Dec 2016 02:13:28 -0500 (EST) Content-Disposition: inline In-Reply-To: <20161211060214.GA30740@jasmine> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel@gnu.org On Sun, Dec 11, 2016 at 01:02:14AM -0500, Leo Famulari wrote: > While poking around, I noticed there is a newer OpenJPEG release > (2.1.2), and a bunch of recent bugs: > > https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=openjpeg > > Especial CVE-2016-8332: > > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8332 I updated the replacement package to version 2.1.2 in 0e8b7b1c351a2307bfc33211b4d76dbe7dfa01ef.