From mboxrd@z Thu Jan 1 00:00:00 1970 From: Alex Vong Subject: Re: [PATCH] gnu: catdoc: Fix CVE-2017-11110. Date: Sun, 13 Aug 2017 00:21:21 +0800 Message-ID: <87shgwpxj2.fsf@gmail.com> References: <87zib5pyby.fsf@gmail.com> <878tio3o0y.fsf@fastmail.com> Mime-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:55574) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dgZAN-0004hG-NB for guix-devel@gnu.org; Sat, 12 Aug 2017 12:21:36 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dgZAJ-0002oa-L6 for guix-devel@gnu.org; Sat, 12 Aug 2017 12:21:35 -0400 Received: from mail-pf0-x242.google.com ([2607:f8b0:400e:c00::242]:35986) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1dgZAJ-0002o2-F9 for guix-devel@gnu.org; Sat, 12 Aug 2017 12:21:31 -0400 Received: by mail-pf0-x242.google.com with SMTP id t83so6088571pfj.3 for ; Sat, 12 Aug 2017 09:21:31 -0700 (PDT) In-Reply-To: <878tio3o0y.fsf@fastmail.com> (Marius Bakke's message of "Sat, 12 Aug 2017 15:37:33 +0200") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Marius Bakke Cc: guix-devel@gnu.org, 28058-done@debbugs.gnu.org --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Marius Bakke writes: > Alex Vong writes: > >> Severity: important >> Tags: patch security >> >> Hello, >> >> This patch fixes the latest CVE of catdoc. The upstream repo[0] is not >> updated for more than a year, so I grab the patch from openSUSE instead >> (which is also used by Debian). > > Thanks for this, pushed! > > [...] > Thanks! >> (I am re-sending this mail for the 3rd time since I didn't receive a >> reply from debbugs. This time I decide to mail to guix-devel as well >> just in case it doesn't work again.)=20 > > No idea what's up with that. Does it work if you omit the debbugs > control headers? Perhaps processing is disabled for guix-patches, or > something. This time it works. I guess debbugs was doing some maintaince work hence temporarily unavailable. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEdZDkzSn0Cycogr9IxYq4eRf1Ea4FAlmPKwEACgkQxYq4eRf1 Ea4r7g//ZUBmrpKsI+emofK9hOIMzGNZrGUOLuozZyG1Je385E1YzbpXRs9T9jhN 6kWQp+eX8SBfsZMfGQUSO/Rq/3o0nKaqt9RRf9SjmPVG7r03y8BanMJ/f8r3UxKa ALfdIOFgi44rkwvN13+QIXXAwPl2cbw70urkdOuVm+QMGQy44mKyqCW7KMJaKsoB EvcUCuAaZ8Or7oCfGmr4agczLWWVl1omT65k72yMT9Dz3DRVDuHIxaBM9B9niYNx fb6t99zvAsWfe+MELKX5ASotcXnVrl1P/D69mfRJhlueojeX+kznfuG58/6wSqD7 clJU/NVOCqiVdcgQ5mLYp5aL31kA+xoLqvP5vXeCivGs/6SwN+OWrKQhf9kJdTiX P2wrjDhR9vZ8JoMHGmiE4j4uZiCYTEC8nTeOm5DUIYZSzk4MvSGaT7X67xT0nbEG VYJfgaMXMTIrjrq2CYvjc7fT8QeXnOuINM/3GSRWD36vUk34s1g39ScQRz5F6iXv Tivz8MIo5aU+c1NeybYEDEYdonDJvwEiT7gYdFkjOl4jyLdUlBrKQbEobvJ+2Pnu M7nuRK80M/kVxAgYQupAwms8qKDBnqAvICgJYGuI2bnpZvi/CxYWEOJ5IOhTt5W8 yS2NpHb4sRLjpHwZGx3fKLFwoBl7EHlmAgxCLMkLzATi1tknKuE= =p1j7 -----END PGP SIGNATURE----- --=-=-=--