From mboxrd@z Thu Jan 1 00:00:00 1970 From: Marius Bakke Subject: Re: binutils CVEs Date: Sun, 17 Sep 2017 20:37:39 +0200 Message-ID: <87377lcgss.fsf@fastmail.com> References: <20170917181927.GB16737@macbook42.flashner.co.il> <87a81tchdk.fsf@fastmail.com> Mime-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:54784) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dteRu-0000d3-IO for guix-devel@gnu.org; Sun, 17 Sep 2017 14:37:51 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dteRp-0003Wh-Vt for guix-devel@gnu.org; Sun, 17 Sep 2017 14:37:46 -0400 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:34807) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1dteRp-0003W7-LP for guix-devel@gnu.org; Sun, 17 Sep 2017 14:37:41 -0400 In-Reply-To: List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Efraim Flashner , guix-devel@gnu.org --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Efraim Flashner writes: > On September 17, 2017 9:25:11 PM GMT+03:00, Marius Bakke wrote: >>Efraim Flashner writes: >> >>> There's a large number of CVEs against binutils@2.28. Gentoo=C2=B9 has a >>nice >>> long list of the CVEs, and I've put together a patch to graft a >>> replacement, but I'm getting grafting errors: >>> ERROR: replacement length differs from the original length >>"h9nqlf0c82c1sds4yzs60k7pm4f37si2-binutils-2.28" >>"wl5dg3dnqvk2v2ahh5iadnv1s34rsbb6-binutils-2.28.1" >> >>This is because the replacement name is two bytes longer (.1). >> >>To fix it, the version field of the replacement must be set to >>something >>with equal length of "2.28". I suppose we can use just that and >>hard-code the source URL? > > That is the obvious solution, but I don't like it. It does make it harder= to verify that it's grafted correctly but I guess it'll just have to be th= at way. Maybe "2281". Or "fixd". --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEu7At3yzq9qgNHeZDoqBt8qM6VPoFAlm+wPMACgkQoqBt8qM6 VPqlxAf5AbOaTii0Q1wPeCUTu/IxUhmtJjwQpHgg/HQ4Wl8dOZi2HbXF6L2BAzaK TCpx4GRUT7oGz6XlUW+Grj2vKmd3cPiAXN4k6JwbOhZcRQl/3VPpLK/eov4oo/UR lfkGVXH+Knu/U5TP+pc/7Rk8nUZNT/vYNBciIdnmS/7QyQQ/7ZLoVy81OLTKbksT fo1NL2TBh6vggRCceheDYDHk9ymKlJVNdIbHOWwbnMRQ5RINijI62Qw0E5P8X50F nP5mk/iDInErYzBsCSuMwM0dWtoWtm/8qK01NGFRZOEtMpTN/EKEo4keMQBW97P6 QbN2pyQ6fswicIkN4HO+P7icBE2RSg== =UAfC -----END PGP SIGNATURE----- --=-=-=--