From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:48118) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ejsfu-0002vS-3l for guix-patches@gnu.org; Thu, 08 Feb 2018 15:20:07 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ejsfr-0003Zs-0L for guix-patches@gnu.org; Thu, 08 Feb 2018 15:20:06 -0500 Received: from debbugs.gnu.org ([208.118.235.43]:54675) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1ejsfq-0003YN-Nv for guix-patches@gnu.org; Thu, 08 Feb 2018 15:20:02 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1ejsfq-0005Bp-Fz for guix-patches@gnu.org; Thu, 08 Feb 2018 15:20:02 -0500 Subject: bug#30378: [PATCH] gnu: mpv: Fix CVE-2018-6360. Resent-To: guix-patches@gnu.org Resent-Message-ID: Date: Thu, 8 Feb 2018 15:19:03 -0500 From: Leo Famulari Message-ID: <20180208201903.GB21732@jasmine.lan> References: <87tvuts33b.fsf@gmail.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="JP+T4n/bALQSJXh8" Content-Disposition: inline In-Reply-To: <87tvuts33b.fsf@gmail.com> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: Alex Vong Cc: 30378-done@debbugs.gnu.org --JP+T4n/bALQSJXh8 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Feb 07, 2018 at 02:53:12PM +0800, Alex Vong wrote: > Tags: security >=20 > Hello, >=20 > This patch fixes CVE-2018-6360, which is about mpv maybe get tricked > into playing unsafe url returned by youtube-dl. >=20 > From 2a6538067bdad659672f1d19811bad8a5b8d9d56 Mon Sep 17 00:00:00 2001 > From: Alex Vong > Date: Wed, 7 Feb 2018 14:39:40 +0800 > Subject: [PATCH] gnu: mpv: Fix CVE-2018-6360. >=20 > * gnu/packages/patches/mpv-CVE-2018-6360-1.patch, > gnu/packages/patches/mpv-CVE-2018-6360-2.patch, > gnu/packages/patches/mpv-CVE-2018-6360-3.patch: New files. > * gnu/local.mk (dist_patch_DATA): Add them. > * gnu/packages/video.scm (mpv)[source]: Use them. Pushed as e61da2e8848782052d6d5d69f111520a7f772e52 --JP+T4n/bALQSJXh8 Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAlp8sLcACgkQJkb6MLrK fwhRXQ//RaZVFtezmFT35SVxD+ScOa1++LBgSvj6m9hMMqELXb4pk6DOmVfgmNJY 922DbT5tF089EdaMiKCcIV2uHSqu7D3R0EL1/IhEmMcGD+VHt93w6EmRbjzqqe9Y SxYNVOt3C7j18DO/29z79vlhKv4LaYlN+XIwZPu59o7rsPUrA+LNPcg/m6jgPDZA zyZKQKL+ewUYGdbfTdQcz2yh4RWbk3QmYtu9sdd5iBxy5JF45INMILBQJhRzUOxm ZUKU4opK0DNwVZtfXSHgKC79JLeJnDWpLKW8mQYu84p7wB84JmkOfAEHWyO+ecUP r5x44NWvPNPdHvfKFtUJXAHQxMn+ZxEZ4qAtYeMM2eYEbCMIS3JeM044H1LaYUvC m8jLkc9bMQsOMaZC5lNuzus3DdlMwgQfdrByxqrcT57N4/CNljedViwIt4taRcua b5iZnMfoY35DmDRr5lxBdGM0Q+Yj5de+TEdVBYIugiGdRm4St1a878+mCbMuu/5e RS267JjiZKLr6Q2zm/4g0xR1mnJYT/Ros+jHrtraCcutR7i+o4IRoWuXfQRNPKhg mcPmZzjispTe+t/jwoK0zQPtznPscJdP3dEFqFyxbehaKf3Gbmw8HDOpHu/9+zHp LaDXj/C6Kf1cIMCTPMfC5ryyDRiXNtmQ8Qiw/72aDxBUUEvhvaA= =5Our -----END PGP SIGNATURE----- --JP+T4n/bALQSJXh8--