From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp0 ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms11 with LMTPS id yKQoC+EJUl8BNQAA0tVLHw (envelope-from ) for ; Fri, 04 Sep 2020 09:33:21 +0000 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp0 with LMTPS id QA8sB+EJUl8yEQAA1q6Kng (envelope-from ) for ; Fri, 04 Sep 2020 09:33:21 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id A917A94051E for ; Fri, 4 Sep 2020 09:33:20 +0000 (UTC) Received: from localhost ([::1]:41342 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1kE85v-0002P0-Hr for larch@yhetil.org; Fri, 04 Sep 2020 05:33:19 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:42928) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kE85e-0001nv-SG for guix-patches@gnu.org; Fri, 04 Sep 2020 05:33:02 -0400 Received: from debbugs.gnu.org ([209.51.188.43]:54145) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1kE85e-0005uK-C9 for guix-patches@gnu.org; Fri, 04 Sep 2020 05:33:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1kE85e-00016w-8P for guix-patches@gnu.org; Fri, 04 Sep 2020 05:33:02 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#42890] [PATCH] gnu: taglib: Include patch to prevent OGG corruption. Resent-From: Ludovic =?UTF-8?Q?Court=C3=A8s?= Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Fri, 04 Sep 2020 09:33:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 42890 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: Pierre Langlois Cc: 42890@debbugs.gnu.org, mail@brendan.scot Received: via spool by 42890-submit@debbugs.gnu.org id=B42890.15992119444222 (code B ref 42890); Fri, 04 Sep 2020 09:33:02 +0000 Received: (at 42890) by debbugs.gnu.org; 4 Sep 2020 09:32:24 +0000 Received: from localhost ([127.0.0.1]:37458 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1kE852-000161-2A for submit@debbugs.gnu.org; Fri, 04 Sep 2020 05:32:24 -0400 Received: from eggs.gnu.org ([209.51.188.92]:60796) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1kE850-00015o-4H for 42890@debbugs.gnu.org; Fri, 04 Sep 2020 05:32:22 -0400 Received: from fencepost.gnu.org ([2001:470:142:3::e]:58013) by eggs.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1kE84t-0005pb-Hn; Fri, 04 Sep 2020 05:32:15 -0400 Received: from [2001:660:6102:320:e120:2c8f:8909:cdfe] (port=46510 helo=ribbon) by fencepost.gnu.org with esmtpsa (TLS1.2:RSA_AES_256_CBC_SHA1:256) (Exim 4.82) (envelope-from ) id 1kE84r-0004hv-IN; Fri, 04 Sep 2020 05:32:14 -0400 From: Ludovic =?UTF-8?Q?Court=C3=A8s?= References: <87r1s6oam4.fsf@gmx.com> <98bfcbfa-4142-2985-864f-c146ac8d1f92@brendan.scot> <87blj82tt6.fsf@gmx.com> <87pn7ndee3.fsf@gmx.com> Date: Fri, 04 Sep 2020 11:32:09 +0200 In-Reply-To: <87pn7ndee3.fsf@gmx.com> (Pierre Langlois's message of "Tue, 18 Aug 2020 18:59:00 +0100") Message-ID: <874kodvqee.fsf@gnu.org> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.3 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Spam-Score: -2.3 (--) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-Spam-Score: -3.3 (---) X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: "Guix-patches" X-Scanner: scn0 Authentication-Results: aspmx1.migadu.com; dkim=none; dmarc=none; spf=pass (aspmx1.migadu.com: domain of guix-patches-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-patches-bounces@gnu.org X-Spam-Score: -1.01 X-TUID: RwDvsOF8xw5s Hi! Pierre Langlois skribis: >>>From 97a5d71bd50c72d2d7562a7d22baca04f4987657 Mon Sep 17 00:00:00 2001 > From: Pierre Langlois > Date: Tue, 18 Aug 2020 18:38:01 +0100 > Subject: [PATCH] gnu: taglib: Update to 1.12-beta-1. > > This switches to a yet unreleased version of taglib, to make sure long > standings issues and CVEs are covered until a proper release is made upst= ream. > > Among these, we have: > > - CVE-2017-12678 > - CVE-2018-11439 > - https://github.com/taglib/taglib/issues/864 > > * gnu/packges/mp3.scm (taglib): Update to 1.12-beta-1. > [source]: Switch to using git-fetch. It=E2=80=99s a good idea to add =E2=80=9C[security fixes]=E2=80=9D or to li= st CVEs in the subject line of the commit log. Otherwise LGTM! You can now use your new super commit powers to push it. :-) Thanks, Ludo=E2=80=99.