From mboxrd@z Thu Jan 1 00:00:00 1970 From: Efraim Flashner Subject: Re: binutils CVEs Date: Sun, 17 Sep 2017 18:31:32 +0000 Message-ID: References: <20170917181927.GB16737@macbook42.flashner.co.il> <87a81tchdk.fsf@fastmail.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:52556) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dteLz-0007cE-VV for guix-devel@gnu.org; Sun, 17 Sep 2017 14:31:44 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dteLv-0008Iv-N6 for guix-devel@gnu.org; Sun, 17 Sep 2017 14:31:39 -0400 Received: from flashner.co.il ([178.62.234.194]:38334) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dteLv-0008Ik-GM for guix-devel@gnu.org; Sun, 17 Sep 2017 14:31:35 -0400 In-Reply-To: <87a81tchdk.fsf@fastmail.com> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Marius Bakke , guix-devel@gnu.org On September 17, 2017 9:25:11 PM GMT+03:00, Marius Bakke wrote: >Efraim Flashner writes: > >> There's a large number of CVEs against binutils@2=2E28=2E Gentoo=C2=B9 = has a >nice >> long list of the CVEs, and I've put together a patch to graft a >> replacement, but I'm getting grafting errors: >> ERROR: replacement length differs from the original length >"h9nqlf0c82c1sds4yzs60k7pm4f37si2-binutils-2=2E28" >"wl5dg3dnqvk2v2ahh5iadnv1s34rsbb6-binutils-2=2E28=2E1" > >This is because the replacement name is two bytes longer (=2E1)=2E > >To fix it, the version field of the replacement must be set to >something >with equal length of "2=2E28"=2E I suppose we can use just that and >hard-code the source URL? That is the obvious solution, but I don't like it=2E It does make it harde= r to verify that it's grafted correctly but I guess it'll just have to be t= hat way=2E --=20 Sent from my Android device with K-9 Mail=2E Please excuse my brevity=2E