From mboxrd@z Thu Jan 1 00:00:00 1970 From: Marius Bakke Subject: Re: Libxslt CVE-2016-4738 Date: Wed, 09 Nov 2016 00:57:50 +0000 Message-ID: <87lgwt79m9.fsf@kirby.i-did-not-set--mail-host-address--so-tickle-me> References: <20161108221616.GA2468@jasmine> Mime-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:38979) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1c4HDC-0008WU-Q3 for guix-devel@gnu.org; Tue, 08 Nov 2016 19:57:59 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1c4HD9-0007FX-EE for guix-devel@gnu.org; Tue, 08 Nov 2016 19:57:58 -0500 Received: from out4-smtp.messagingengine.com ([66.111.4.28]:57873) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1c4HD9-0007FG-6n for guix-devel@gnu.org; Tue, 08 Nov 2016 19:57:55 -0500 In-Reply-To: <20161108221616.GA2468@jasmine> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Leo Famulari , guix-devel@gnu.org --=-=-= Content-Type: text/plain Leo Famulari writes: > Here is a patch to fix CVE-2016-4738 in libxslt. > From 1cbfeb5bb98924eddf1726fe56987fd1d282e7f8 Mon Sep 17 00:00:00 2001 > From: Leo Famulari > Date: Tue, 8 Nov 2016 17:12:01 -0500 > Subject: [PATCH] gnu: libxslt: Fix CVE-2016-4738. > > * gnu/packages/patches/libxslt-CVE-2016-4738.patch: New file. > * gnu/local.mk (dist_patch_DATA): Add it. > * gnu/packages/xml.scm (libxslt)[replacement]: New field. > (libxslt/fixed): New variable. Yay, more grafts ;) Anyway, LGTM, thanks! --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEcBAEBCgAGBQJYInSOAAoJEKKgbfKjOlT67l8IAIwxlFBWDfrdIHhOxMVFEOiA LDwcYnDpsS2RWJm4VijYUGJZAbI+Wqc1M+gvuPo6FA4TLJ3o/JkaDMPZTAvbK39z /llR5gO5JERErPz+fybItvPj5eKSRssx7OdtGOqE4TYJpaD5m4Bsz9I0biV2D5kQ 6K2+vu4rO3wNadeQ9tsoS4BhAHUD1dD0/CgjcgN1TDR/Eowj5aI9qa7Tw23B77fC JM2Z1xoWxL3TjXxMarLL7+z9Mf2x46sDO9SGlcVD/j8UKPsMWY8knvmdSNhsHf1m QlJ+mvzV7n8XHDlWHb5yP16VPRfr5wZU7RARIFk7xwDYLOkZOhV4GpD7BP3TFZA= =dZ9l -----END PGP SIGNATURE----- --=-=-=--