From mboxrd@z Thu Jan 1 00:00:00 1970 From: Tobias Geerinckx-Rice Subject: Re: [PATCH 1/2] gnu: Add libjpeg-turbo. Date: Sun, 27 Nov 2016 22:12:13 +0100 Message-ID: <5d79f3b3-6acf-54d8-d790-b4ec0d77656d@tobias.gr> References: <20161127201707.3789-1-me@tobias.gr> <20161127205519.GB27187@jasmine> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="PFwsQTTODhcEjKjiDvogrd8VTOd5uThMJ" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:42629) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cB6kI-0006OV-75 for guix-devel@gnu.org; Sun, 27 Nov 2016 16:12:23 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cB6kF-0007bB-13 for guix-devel@gnu.org; Sun, 27 Nov 2016 16:12:22 -0500 Received: from relay6-d.mail.gandi.net ([2001:4b98:c:538::198]:60798) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cB6kE-0007ao-Qt for guix-devel@gnu.org; Sun, 27 Nov 2016 16:12:18 -0500 In-Reply-To: <20161127205519.GB27187@jasmine> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: leo@famulari.name Cc: guix-devel@gnu.org This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --PFwsQTTODhcEjKjiDvogrd8VTOd5uThMJ Content-Type: multipart/mixed; boundary="M4a9xJ2L6vRkjnvdmf1XiQraXEFJrF42D"; protected-headers="v1" From: Tobias Geerinckx-Rice To: leo@famulari.name Cc: guix-devel@gnu.org Message-ID: <5d79f3b3-6acf-54d8-d790-b4ec0d77656d@tobias.gr> Subject: Re: [PATCH 1/2] gnu: Add libjpeg-turbo. References: <20161127201707.3789-1-me@tobias.gr> <20161127205519.GB27187@jasmine> In-Reply-To: <20161127205519.GB27187@jasmine> --M4a9xJ2L6vRkjnvdmf1XiQraXEFJrF42D Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Leo, On 27/11/16 21:55, Leo Famulari wrote: > Can you double-check that there are no unpatched named bugs in this > version? Already did ;-) According to [1], there are three known CVEs, all fixed by 1.4.2. I didn't find any third party security patches being applied anywhere, either. Do you have suspicions otherwise? Kind regards, T G-R [1]: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=3Dlibjpeg-turbo --M4a9xJ2L6vRkjnvdmf1XiQraXEFJrF42D-- --PFwsQTTODhcEjKjiDvogrd8VTOd5uThMJ Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- iQEqBAEBCgAUBQJYO0wtDRxtZUB0b2JpYXMuZ3IACgkQkczbm0hUG5mj5gf/ffyQ eUJWGF8MN38lX0KqMhX1FZEunl5pJMx2moJcF6HRwK3oIEZTTBFYR4ZxUsDS2Dy7 tE8aooucwxJb07JhDPb192Sr36+XCe1YbF7SAhP6SHhu1E/D1cAH/ch229Ir1nsd rqEYl9QHnkHIoxjMXbHLYrMRk8fnpzqrWXMiq9k4Vd7n9IbTbUVNnF/X9AsyGUQe 4VccxzvaM/2E0UdVvkf7cWI34TBVMSecYyLNDNHCOfJnsBpuyHIySxUO45+7A+Yh Fe6Qc7i4p8Zw+3sDtB9TrGn6Ge+bm1HFypVsbDxYxfyyQ3JglRx/j6tacFBorKRp ohek4MHGklEmHej2aw== =gvwN -----END PGP SIGNATURE----- --PFwsQTTODhcEjKjiDvogrd8VTOd5uThMJ--