From mboxrd@z Thu Jan 1 00:00:00 1970 From: Tobias Geerinckx-Rice Subject: Re: Expat in GuixSD, please update Date: Wed, 25 Oct 2017 19:29:28 +0200 Message-ID: <80ea924e-4707-1ad0-bdd1-0a9749ecf6e5@tobias.gr> References: <20171025172241.GB9611@jasmine.lan> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="jK7WRCChMmuja7mnFrOUDBlSnC5JGVsDs" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:36733) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1e7PSV-0000YI-Oz for guix-devel@gnu.org; Wed, 25 Oct 2017 13:27:16 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1e7PSU-0006pX-RA for guix-devel@gnu.org; Wed, 25 Oct 2017 13:27:15 -0400 Received: from tobias.gr ([2001:470:cc92::1]:58566) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1e7PSU-0006mt-Ex for guix-devel@gnu.org; Wed, 25 Oct 2017 13:27:14 -0400 In-Reply-To: <20171025172241.GB9611@jasmine.lan> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: leo@famulari.name Cc: guix-devel@gnu.org This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --jK7WRCChMmuja7mnFrOUDBlSnC5JGVsDs Content-Type: multipart/mixed; boundary="BGMSVmJuIskoTq9BTbJd8mIowOOmQXVKJ"; protected-headers="v1" From: Tobias Geerinckx-Rice To: leo@famulari.name Cc: guix-devel@gnu.org Message-ID: <80ea924e-4707-1ad0-bdd1-0a9749ecf6e5@tobias.gr> Subject: Re: Expat in GuixSD, please update References: <20171025172241.GB9611@jasmine.lan> In-Reply-To: <20171025172241.GB9611@jasmine.lan> --BGMSVmJuIskoTq9BTbJd8mIowOOmQXVKJ Content-Type: text/plain; charset=utf-8 Content-Language: en-GB Content-Transfer-Encoding: quoted-printable Leo Famulari wrote on 25/10/17 at 19:22: > Expat 2.2.3's release notes only mentioned CVE-2017-11742, which is a > Windows vulnerability and out of scope for Guix. And I didn't see > security issues disclosed in the 2.2.4 release notes. Ah, sorry to spread misinfo. I don't have Web access at the moment and erred on the side of caution. I'll adjust the patch accordingly & push. Kind regards, T G-R --BGMSVmJuIskoTq9BTbJd8mIowOOmQXVKJ-- --jK7WRCChMmuja7mnFrOUDBlSnC5JGVsDs Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- iIMEARYKACsWIQT12iAyS4c9C3o4dnINsP+IT1VteQUCWfDJ+w0cbWVAdG9iaWFz LmdyAAoJEA2w/4hPVW15qZQBAI5IqVUQvYHcnPIMM/mjAAfef7BYfu6euBhGO3qp aJR8AQCHd5Axscr6knf3bMq1/uvUOEwiw17vf9EXdlNyP4OrDg== =4/75 -----END PGP SIGNATURE----- --jK7WRCChMmuja7mnFrOUDBlSnC5JGVsDs--