From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:39933) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gfCdl-0002DT-V4 for guix-patches@gnu.org; Thu, 03 Jan 2019 18:43:06 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gfCdi-0006yy-RU for guix-patches@gnu.org; Thu, 03 Jan 2019 18:43:05 -0500 Received: from debbugs.gnu.org ([208.118.235.43]:35080) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1gfCdi-0006yk-NF for guix-patches@gnu.org; Thu, 03 Jan 2019 18:43:02 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1gfCdi-0006Gm-H9 for guix-patches@gnu.org; Thu, 03 Jan 2019 18:43:02 -0500 Subject: bug#33933: [PATCH 0/4] gnu: libextractor: Fix CVE-2018-{20430, 20431}. Resent-To: guix-patches@gnu.org Resent-Message-ID: From: Alex Vong In-Reply-To: <20190103182056.GA2707@jasmine.lan> (Leo Famulari's message of "Thu, 3 Jan 2019 13:20:56 -0500") References: <87pntihaht.fsf@gmail.com> <20190103182056.GA2707@jasmine.lan> Date: Fri, 04 Jan 2019 07:42:30 +0800 Message-ID: <871s5txq8p.fsf@gmail.com> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: 33933-done@debbugs.gnu.org Cc: alexvong1995@gmail.com --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Leo Famulari writes: > On Mon, Dec 31, 2018 at 07:15:42AM +0800, Alex Vong wrote: >> Tags: security >>=20 >> Hello, >>=20 >> This patch series mainly fixes the latest CVEs found in libextractor, >> but it also upgrades other gnunet related packages to their latest >> version. >>=20 >> Please also note that the versioning scheme for guile-gnunet is changed >> to use that of 'git-version'. Unfortunately, this would break >> "guix package --upgrade". But I think this change needs to be made at >> some point anyway, so we may as well do it now. > > Thanks, please push :) Pushed as 1983a9b0a50ff759f2d192d7fa0f7ad0fb1e1384 - 5651e74cc6c1d1b8a2ef1d40e6f14e1123a7de97! --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEARYIAB0WIQQwb8uPLAHCXSnTBVZh71Au9gJS8gUCXC6d5wAKCRBh71Au9gJS 8tX2AP4kA/biaCtAJ51e1bGCUcICYnnjeGXDEyABe7i3z/nOVAD/Q9Esmh2WvcTv 8+XfHmArcOxZVJctpMz7EpoNk/q4Bwo= =uXRd -----END PGP SIGNATURE----- --=-=-=--