From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:55530) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dIdep-0003Dg-Qk for guix-patches@gnu.org; Wed, 07 Jun 2017 12:18:13 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dIdek-0007US-6s for guix-patches@gnu.org; Wed, 07 Jun 2017 12:18:07 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:59009) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1dIdek-0007U5-3h for guix-patches@gnu.org; Wed, 07 Jun 2017 12:18:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1dIdej-0007h2-Vz for guix-patches@gnu.org; Wed, 07 Jun 2017 12:18:02 -0400 Subject: bug#27263: [PATCH 2/2] gnu: perl: Fix CVE-2017-6512 in File::Path. Resent-To: guix-patches@gnu.org Resent-Message-ID: Date: Wed, 7 Jun 2017 12:17:53 -0400 From: Leo Famulari Message-ID: <20170607161752.GA5750@jasmine> References: <031e297c96cc7522ca42331605079a8462784466.1496718250.git.leo@famulari.name> <87shjc66z2.fsf@gnu.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="KsGdsel6WgEHnImy" Content-Disposition: inline In-Reply-To: <87shjc66z2.fsf@gnu.org> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: Ludovic =?UTF-8?Q?Court=C3=A8s?= Cc: 27263-done@debbugs.gnu.org --KsGdsel6WgEHnImy Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Jun 07, 2017 at 01:18:09AM +0200, Ludovic Court=C3=A8s wrote: > Leo Famulari skribis: >=20 > > * gnu/packages/perl.scm (perl)[replacement]: New field. > > (perl/fixed): New variable. > > * gnu/packages/patches/perl-file-path-CVE-2017-6512.patch: New file. > > * gnu/local.mk (dist_patch_DATA): Add it. >=20 > OK too. >=20 > I suppose we=E2=80=99ll have to apply it in core-updates too, right? And, done as c67d587f94173fd42d65097165afc5c512935646. I tested that this packaging of Perl 5.26.0 builds on master, then I "ported" the package to core-updates. I don't have the resources to build the Perl package on core-updates in a timely manner. --KsGdsel6WgEHnImy Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAlk4JzAACgkQJkb6MLrK fwhgbg//Re5AUMVXFYU4tUIEmuyddrFVUgeorCnW2nGEEMXvRn8cCCapsHsj2J/8 roZfRTErEnoCwg8IA/pzBgXhTbO8QlgUeWLc0T/xjUW2wQ0EPUOOOth9kVuV2Eci bCXzKyXIoQqoUS7WJqYljHWN2DW2pc8xQq442qfJkNz9EsVz7R9FCgtcmE1TdEXG TiWYVOA8z3tpt4pnf6Co2hoG2Ew2mcnzBJ0mIDqDe7X83yVhp5szpANXn4y9r4zm q7JAQqo1ViBn4GOxa7riC5DdnOUTs39khufsVcbMdK8B8THQpCr6c4mzs1+Q38q2 oy8b/eTgEyAjin4XMc85M98H5uow+/F+kM0UmPg6JEvsQ3eF1pVPWp9NKpcScxcQ 8ngWT4dDBE6ZVpWNNF7PtPm9xws77cN8hbm2dWqUK6Iuu5FyNzkRCAObIanBWy0I iJ6yK3r96IQdH9dL85293h0uHypjdpfXyOb2pcauMhIwt4ON8L/ixXExTWuzE0tu Fk1kPKOHfv6QHu6JmOWCYCDhYe/CvepuRJ4tLyfWTp5zFptlw/2Spjlwe+eFJg9w NKlJAZZLzuxpAgLhxLgeDuw3goRLe4PWfo9eK9lFwZCgdhRlCTvnb1+htZuGdu3V x9ROazsJEBqjoV9UJSJhrbO7BZq2WuLs42wOGDTTZoUKs4TbMJE= =4vHI -----END PGP SIGNATURE----- --KsGdsel6WgEHnImy--