From mboxrd@z Thu Jan 1 00:00:00 1970 From: ludo@gnu.org (Ludovic =?utf-8?Q?Court=C3=A8s?=) Subject: Re: Adding packages with vulnerabilities (was Re: [PATCH 1/2] gnu: Add perl-net-psyc. [pcre]) Date: Mon, 03 Oct 2016 17:44:04 +0200 Message-ID: <87twcta14r.fsf@gnu.org> References: <20160913113237.17434-1-ng0@we.make.ritual.n0.is> <20160913191644.GC5986@jasmine> <87twdjmw4y.fsf@we.make.ritual.n0.is> <87twdj8qqg.fsf@we.make.ritual.n0.is> <878tulr4qk.fsf@we.make.ritual.n0.is> <8737ktr17c.fsf@we.make.ritual.n0.is> <87shstccqg.fsf@we.make.ritual.n0.is> <20160927165640.GB2497@jasmine> <87twczrsju.fsf@we.make.ritual.n0.is> <20161002015022.GB26660@jasmine> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:56854) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1br5PW-0008Gd-Su for guix-devel@gnu.org; Mon, 03 Oct 2016 11:44:12 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1br5PT-0008Ah-Ly for guix-devel@gnu.org; Mon, 03 Oct 2016 11:44:10 -0400 In-Reply-To: <20161002015022.GB26660@jasmine> (Leo Famulari's message of "Sat, 1 Oct 2016 21:50:22 -0400") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Leo Famulari Cc: guix-devel@gnu.org Leo Famulari skribis: > On Thu, Sep 29, 2016 at 08:58:29AM +0000, ng0 wrote: >> Leo Famulari writes: >> > On Wed, Sep 21, 2016 at 06:46:31PM +0000, ng0 wrote: >> >> Subject: [PATCH 1/2] gnu: Add psyclpc. >> >>=20 >> >> * gnu/packages/psyc.scm (psyclpc): New variable. > >> >> + (inputs >> >> + `(("zlib" ,zlib) >> >> + ("openssl" ,openssl))) >> >> + ;; pcre is bundled to ensure the version is compatible. XXX: loo= k into >> >> + ;; unbundling it. Upstream should update from pcre 4.5 to 8.38. = For >> >> + ;; functionality reasons we can not unbundle it now. >> >> + ;; ("pcre" ,pcre))) >> > >> > That version of PCRE was released in 2003. We might want to add a >> > warning to the package description... >> > >> > https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=3Dpcre >>=20 >> Update on this: the pcre bundling was inherited from ldmud, current >> ldmud has unbundled pcre, so we will be able to unbundle pcre. >>=20 >> I'd still like to have the patches in their current form and update >> psyclpc when the next version without pcre is out. > > I'd like some more opinions on this. Should we add this package even > though we know it contains some security bugs (linked above)? I don=E2=80=99t think so. >From the comment above, it seems difficult to have this package use a current version of PCRE, right? Then I would suggest discussing it with upstream. After all, they=E2=80=99re developing network-facing software, so they=E2=80=99re probably interested in avoiding security issues. ng0, could you take it with them? TIA, Ludo=E2=80=99.