From mboxrd@z Thu Jan 1 00:00:00 1970 From: Marius Bakke Subject: Re: 01/01: gnu: curl: Update replacement to 7.52.0 [fixes CVE-2016-{9586, 9952, 9953}]. Date: Wed, 21 Dec 2016 20:27:09 +0100 Message-ID: <8737hhaxrm.fsf@kirby.i-did-not-set--mail-host-address--so-tickle-me> References: <20161221140321.28790.1100@vcs.savannah.gnu.org> <20161221140321.922BB220166@vcs.savannah.gnu.org> <20161221165844.GA7240@jasmine> Mime-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:39698) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cJmXl-0004S0-53 for guix-devel@gnu.org; Wed, 21 Dec 2016 14:27:18 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cJmXh-0008M7-FN for guix-devel@gnu.org; Wed, 21 Dec 2016 14:27:17 -0500 Received: from out3-smtp.messagingengine.com ([66.111.4.27]:53077) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cJmXh-0008Km-8r for guix-devel@gnu.org; Wed, 21 Dec 2016 14:27:13 -0500 In-Reply-To: <20161221165844.GA7240@jasmine> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Leo Famulari , guix-devel@gnu.org --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Leo Famulari writes: > On Wed, Dec 21, 2016 at 02:03:21PM +0000, Marius Bakke wrote: >> mbakke pushed a commit to branch master >> in repository guix. >>=20 >> commit 42366b35c3f9f8dc8b059d3369b8196a4b832c18 >> Author: Marius Bakke >> Date: Wed Dec 21 14:56:34 2016 +0100 >>=20 >> gnu: curl: Update replacement to 7.52.0 [fixes CVE-2016-{9586,9952,9= 953}]. >>=20=20=20=20=20 >> * gnu/packages/curl.scm (curl)[replacement]: Update to 7.52.0. >> (curl-7.51.0): Replace with ... >> (curl-7.52.0): ... this. > > ng0 pointed out this message from the curl maintainers: > > "Attention! We will release a patch update within a few days to fix a > serious security problem found in curl 7.52.0. You may consider holding > off until then." > > https://curl.haxx.se/download.html Thanks for catching that! I think that message must have appeared after I downloaded it from there, difficult to miss that notice. The page was updated about 25 minutes after the commit was pushed: $ curl -v https://curl.haxx.se/download.html >/dev/null [...] < Last-Modified: Wed, 21 Dec 2016 14:28:41 GMT It was reverted around 16:52 UTC. I hope those who upgraded in between those five hours reads this list! --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEu7At3yzq9qgNHeZDoqBt8qM6VPoFAlha140ACgkQoqBt8qM6 VPp+kwf9GOVazrLWja6Tiwr4o7AXknYtJ+XiF/ptCth/uhwCE7YOIew+LyVAfTHN YilA8fa1r2OBzY6iDQMOpo9BfEhgbh9wYLrvX7MgptBn7HPpWZ+R1Vc3rA8ZAidV OFP34A3j94HMJZ9+L75cYZU2mV3rPz1wN7oeh5YxKE5w3c9sEAmyLJi/dJ6+xBQt nkWjEylsa17EcpFfRZHZBfH97nZ0WKy7cqNjrlH2AoFEakF1HFF/91KPEtgoFnGb PJZWeBJjXiW7Ta24CsJuA3T5uFg6dWQ0Xr3Z0XllNEDAJGu3QCMqjXp6BqTYOiKa FZ/zk9yqrBVcmt3k4kDz6jLpWmplQA== =h1U4 -----END PGP SIGNATURE----- --=-=-=--