From mboxrd@z Thu Jan 1 00:00:00 1970 From: Maxim Cournoyer Subject: Re: Guix IceCat users have had early access to security fixes Date: Wed, 14 Dec 2016 18:53:08 -0800 Message-ID: References: <87oa0e3t1r.fsf@netris.org> <877f72vsoy.fsf@dustycloud.org> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary=001a11405cbed898970543a98dca Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:45185) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cHMBT-0000du-S9 for guix-devel@gnu.org; Wed, 14 Dec 2016 21:54:17 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cHMBQ-0003l7-PO for guix-devel@gnu.org; Wed, 14 Dec 2016 21:54:15 -0500 Received: from mail-qt0-f177.google.com ([209.85.216.177]:35563) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1cHMBQ-0003kv-KD for guix-devel@gnu.org; Wed, 14 Dec 2016 21:54:12 -0500 Received: by mail-qt0-f177.google.com with SMTP id c47so44527919qtc.2 for ; Wed, 14 Dec 2016 18:54:12 -0800 (PST) In-Reply-To: <877f72vsoy.fsf@dustycloud.org> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Christopher Allan Webber Cc: guix-devel@gnu.org --001a11405cbed898970543a98dca Content-Type: text/plain; charset=UTF-8 Very nice! Thanks :) On Wed, Dec 14, 2016 at 6:20 PM, Christopher Allan Webber < cwebber@dustycloud.org> wrote: > Mark H Weaver writes: > > > Yesterday, Mozilla released Firefox ESR 45.6 and announced several CVEs > > fixed by it: > > > > https://www.mozilla.org/en-US/security/advisories/mfsa2016-95/ > > > > I'm pleased to announce that Guix users of IceCat have had early access > > all of these fixes. > > > > Since November 30 (commit 9689e71d2f2b5e766415a40d5f5ab267768d217d), > > we've had fixes for CVE-2016-9897, CVE-2016-9898, CVE-2016-9899, > > CVE-2016-9900, CVE-2016-9904, and 4 out of 11 patches for CVE-2016-9893. > > > > Since December 3 (commit 5bdec7d634ce0058801cd212e9e4ea56e914ca0c), > > we've had the fixes that were later announced as CVE-2016-9901, > > CVE-2016-9902, CVE-2016-9905, and another patch for CVE-2016-9893. > > > > On December 10 (commit 56c394ee4397015d6144dab002ee43fc7e32a331), I > > cherry-picked the remaining fixes from the not-yet-released Firefox > > ESR 45.6: CVE-2016-9895, and the final six patches for CVE-2016-9893. > > > > Mark > > Wow! Thank you for staying on top of things, Mark! > > --001a11405cbed898970543a98dca Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable
Very nice! Thanks :)
<= br>
On Wed, Dec 14, 2016 at 6:20 PM, Christopher = Allan Webber <cwebber@dustycloud.org> wrote:
Mark H Weav= er writes:

> Yesterday, Mozilla released Firefox ESR 45.6 and announced several CVE= s
> fixed by it:
>
>=C2=A0 =C2=A0https://www.mozilla.o= rg/en-US/security/advisories/mfsa2016-95/
>
> I'm pleased to announce that Guix users of IceCat have had early a= ccess
> all of these fixes.
>
> Since November 30 (commit 9689e71d2f2b5e766415a40d5f5ab267768d217= d),
> we've had fixes for CVE-2016-9897, CVE-2016-9898, CVE-2016-9899, > CVE-2016-9900, CVE-2016-9904, and 4 out of 11 patches for CVE-2016-989= 3.
>
> Since December 3 (commit 5bdec7d634ce0058801cd212e9e4ea56e914ca0c= ),
> we've had the fixes that were later announced as CVE-2016-9901, > CVE-2016-9902, CVE-2016-9905, and another patch for CVE-2016-9893.
>
> On December 10 (commit 56c394ee4397015d6144dab002ee43fc7e32a331),= I
> cherry-picked the remaining fixes from the not-yet-released Firefox > ESR 45.6: CVE-2016-9895, and the final six patches for CVE-2016-9893.<= br> >
>=C2=A0 =C2=A0 =C2=A0 =C2=A0Mark

Wow!=C2=A0 Thank you for staying on top of things, Mark!


--001a11405cbed898970543a98dca--