Leo Famulari writes: > * gnu/packages/patches/bazaar-CVE-2017-14176.patch: New file. > * gnu/local.mk (dist_patch_DATA): Add it. > * gnu/packages/version-control.scm (bazaar)[source]: Use it. [...] > diff --git a/gnu/packages/patches/bazaar-CVE-2017-14176.patch b/gnu/packages/patches/bazaar-CVE-2017-14176.patch > new file mode 100644 > index 000000000..0e9083b97 > --- /dev/null > +++ b/gnu/packages/patches/bazaar-CVE-2017-14176.patch > @@ -0,0 +1,166 @@ > +Fix CVE-2017-14176: > + > +https://bugs.launchpad.net/bzr/+bug/1710979 > +https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14176 > + > +Patch copied from Debian's Bazaar package version bzr_2.7.0+bzr6619-7+deb9u1: > + > +https://alioth.debian.org/scm/loggerhead/pkg-bazaar/bzr/2.7/revision/4204 I was looking for a fix for this a couple of days ago as well, but could not find anything in the upstream repository: https://code.launchpad.net/bzr LGTM, and thanks!