unofficial mirror of guix-patches@gnu.org 
 help / color / mirror / code / Atom feed
* bug#26828: Update libetpan to 1.8 (CVE-2017-8825)
@ 2017-05-08 14:43 Julien Lepiller
  2017-05-08 17:35 ` Leo Famulari
  0 siblings, 1 reply; 3+ messages in thread
From: Julien Lepiller @ 2017-05-08 14:43 UTC (permalink / raw)
  To: 26828

[-- Attachment #1: Type: text/plain, Size: 136 bytes --]

Hi,

here is a patch to update libetpan to version 1.8. This update also
fixes CVE-2017-8825. Should it be mentionned in the commit log?

[-- Attachment #2: 0001-gnu-libetpan-Update-to-1.8.patch --]
[-- Type: text/x-patch, Size: 1565 bytes --]

From a14e603dcfcba7164741dd5948a310515405c37e Mon Sep 17 00:00:00 2001
From: Julien Lepiller <julien@lepiller.eu>
Date: Mon, 8 May 2017 16:37:53 +0200
Subject: [PATCH] gnu: libetpan: Update to 1.8.

* gnu/packages/mail.scm (libetpan): Update to 1.8.
[license]: Change to bsd-3.
---
 gnu/packages/mail.scm | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/gnu/packages/mail.scm b/gnu/packages/mail.scm
index 014c77d91..39d394140 100644
--- a/gnu/packages/mail.scm
+++ b/gnu/packages/mail.scm
@@ -837,14 +837,14 @@ useful features.")
 (define-public libetpan
   (package
     (name "libetpan")
-    (version "1.7.2")
+    (version "1.8")
     (source (origin
              (method url-fetch)
              (uri (string-append "https://github.com/dinhviethoa/" name
                    "/archive/" version ".tar.gz"))
              (file-name (string-append name "-" version ".tar.gz"))
              (sha256
-               (base32 "081ixgj3skglq9i7v0jb835lmfx21zi4i5b7997igwr0lj174y9j"))))
+               (base32 "1sxnaglp5hb0z78sgnfzva4x8m4flqhicvm1dz0krkxdmfsafrsf"))))
     (build-system gnu-build-system)
     (native-inputs `(("autoconf" ,(autoconf-wrapper))
                      ("automake" ,automake)
@@ -875,7 +875,7 @@ useful features.")
 framework for different kinds of mail access: IMAP, SMTP, POP and NNTP.  It
 provides an API for C language.  It's the low-level API used by MailCore and
 MailCore 2.")
-    (license (non-copyleft "file://COPYING"))))
+    (license bsd-3)))
 
 (define-public compface
   (package
-- 
2.12.2


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* bug#26828: Update libetpan to 1.8 (CVE-2017-8825)
  2017-05-08 14:43 bug#26828: Update libetpan to 1.8 (CVE-2017-8825) Julien Lepiller
@ 2017-05-08 17:35 ` Leo Famulari
  2017-05-09 17:26   ` Leo Famulari
  0 siblings, 1 reply; 3+ messages in thread
From: Leo Famulari @ 2017-05-08 17:35 UTC (permalink / raw)
  To: Julien Lepiller; +Cc: 26828

[-- Attachment #1: Type: text/plain, Size: 514 bytes --]

On Mon, May 08, 2017 at 04:43:13PM +0200, Julien Lepiller wrote:
> Hi,
> 
> here is a patch to update libetpan to version 1.8. This update also
> fixes CVE-2017-8825. Should it be mentionned in the commit log?

Thanks! Yes, I would add [fixes CVE-2017-8825] to the end of the first
line of the commit message.

I bet the majority of updates include fixes for exploitable bugs (at
least for C programs), but it's still useful to include these bug
identifiers in the commit log, when we know about them.

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

* bug#26828: Update libetpan to 1.8 (CVE-2017-8825)
  2017-05-08 17:35 ` Leo Famulari
@ 2017-05-09 17:26   ` Leo Famulari
  0 siblings, 0 replies; 3+ messages in thread
From: Leo Famulari @ 2017-05-09 17:26 UTC (permalink / raw)
  To: Julien Lepiller; +Cc: 26828-done

[-- Attachment #1: Type: text/plain, Size: 698 bytes --]

On Mon, May 08, 2017 at 01:35:38PM -0400, Leo Famulari wrote:
> On Mon, May 08, 2017 at 04:43:13PM +0200, Julien Lepiller wrote:
> > Hi,
> > 
> > here is a patch to update libetpan to version 1.8. This update also
> > fixes CVE-2017-8825. Should it be mentionned in the commit log?
> 
> Thanks! Yes, I would add [fixes CVE-2017-8825] to the end of the first
> line of the commit message.
> 
> I bet the majority of updates include fixes for exploitable bugs (at
> least for C programs), but it's still useful to include these bug
> identifiers in the commit log, when we know about them.

Hi Julien,

I pushed the patch on your behalf as
a979eea9c2132d35cba30e7fcd4184ec159310a6.

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2017-05-09 17:27 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-05-08 14:43 bug#26828: Update libetpan to 1.8 (CVE-2017-8825) Julien Lepiller
2017-05-08 17:35 ` Leo Famulari
2017-05-09 17:26   ` Leo Famulari

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/guix.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).