From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: mcrypt CVE-2012-{4409,4527} [was Re: [PATCH 1/1] gnu: unrtf: Fix CVE-2016-10091.] Date: Wed, 4 Jan 2017 02:50:05 -0500 Message-ID: <20170104075005.GA29636@jasmine> References: <049f6fc2d37899df14579e04092582e3382489d5.1483302566.git.leo@famulari.name> <8760lwqeau.fsf@kirby.i-did-not-set--mail-host-address--so-tickle-me> <20170104071325.GA8103@jasmine> <20170104072757.GA18888@jasmine> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="zhXaljGHf11kAtnf" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:45100) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cOgKr-00013E-B2 for guix-devel@gnu.org; Wed, 04 Jan 2017 02:50:14 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cOgKm-0006rG-FT for guix-devel@gnu.org; Wed, 04 Jan 2017 02:50:13 -0500 Received: from out2-smtp.messagingengine.com ([66.111.4.26]:35992) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cOgKm-0006qk-9F for guix-devel@gnu.org; Wed, 04 Jan 2017 02:50:08 -0500 Content-Disposition: inline In-Reply-To: <20170104072757.GA18888@jasmine> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Marius Bakke Cc: guix-devel@gnu.org --zhXaljGHf11kAtnf Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Jan 04, 2017 at 02:27:57AM -0500, Leo Famulari wrote: > Of course, the patch I sent on January 1 was completely broken. >=20 > The patch it included from Debian was meant to be applied to the Debian > package tree, not the UnRTF source code. I found another instance of this in mcrypt, which I just fixed in 324f4fc559b4cf9f7df0bc334ac8a0a4fa040c22. --zhXaljGHf11kAtnf Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAlhsqS0ACgkQJkb6MLrK fwg0aRAAwmk63iLfgCZPZhAOdYqtP76qCl6Ys4kYdoYyQxX9GlcfijtX3cHoiXFP FzUWraynKX33/SL91uEk5p0SVUPY/7c3idU8KSeYdFxZkUCBiAVHX/1HDrF9bobq SvJgeSAPS9Rz4xsgnCCFGT9zB351W16bXUVugdb74jgEGXNTpm15JkKrTrwCZ8m6 Odb/hJyDmCD7Zd7IK1rWe4FaF5NkfSONdkHE6ZRJasEKX1IUFSE23/pCBob6BHVH ZdWmbnNZgtL/R3LRknH3f5pb8p91Pxh4stKVT1rWeF3xULanhEhHlXz4kvc5O6rm CUS1bRkGKQvi4BL9WjLXErTzToaJ6omppxXyCFTW695NitkgsWzVCLK5GYrWFRgu lC0SUsKuj3RX5hEfqrKboe6CIXLBvNLUylQy2IZkcJZa2/uBG7/qog9IeISkhmB9 brbAiP/CyKN3wgaHz8ZkUYahAyiDztNaahIJe9JixQaLskKgpRCDO6WLyWVEwy1A a0dMtwW+gLI6vI4wzqiGtzA62IzISSwcwaBwyje+QcGcCDV9LGqa+NIaiolz73NQ kc3/HotZC5fPfGQilX/7Cv9wQfVffPPGcHY1rHo9rRojrTu9620gTqQvLBUr5BI8 XlgWdpOfrDzxsoJXn/9/8zLbmAigacjW1z9N2vFghL4TwXOEb/s= =2Qco -----END PGP SIGNATURE----- --zhXaljGHf11kAtnf--