From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:45314) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fUH2Q-0004OY-Sm for guix-patches@gnu.org; Sat, 16 Jun 2018 15:39:07 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fUH2M-0004c8-UW for guix-patches@gnu.org; Sat, 16 Jun 2018 15:39:06 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:44163) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1fUH2M-0004bx-R4 for guix-patches@gnu.org; Sat, 16 Jun 2018 15:39:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1fUH2M-0004Ph-Hb for guix-patches@gnu.org; Sat, 16 Jun 2018 15:39:02 -0400 Subject: [bug#31797] [PATCH] gnu: perl: Fix CVE-2018-12015. Resent-Message-ID: From: Marius Bakke In-Reply-To: <87wov3oku0.fsf@gnu.org> References: <20180612092514.16080-1-mbakke@fastmail.com> <87wov3oku0.fsf@gnu.org> Date: Sat, 16 Jun 2018 21:38:28 +0200 Message-ID: <87tvq2o72j.fsf@fastmail.com> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: Ludovic =?UTF-8?Q?Court=C3=A8s?= Cc: 31797@debbugs.gnu.org --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable ludo@gnu.org (Ludovic Court=C3=A8s) writes: > Hello Marius, > > Marius Bakke skribis: > >> * gnu/packages/patches/perl-archive-tar-CVE-2018-12015.patch: New file. >> * gnu/local.mk (dist_patch_DATA): Register it. >> * gnu/packages/perl.scm (perl-5.26.2)[source](patches): Use it. > > LGTM. Thanks for taking care of it! Excellent, pushed! > I wonder if it=E2=80=99s an option to remove some of the bundled librarie= s that > come with Perl, or whether packages rely of them as part of Perl proper. That would be great. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEu7At3yzq9qgNHeZDoqBt8qM6VPoFAlslZzQACgkQoqBt8qM6 VPoouwf/ddU6LeCT9doAtq6t1TIyWFMPAlVJrXFImOt/urs4wPVc8bloLIKejuzo pHy8LiBehh+N3fK1j89mbgAyuf82AxhqUranOyFCK86AFkS4dEH9pfUQaTjKQyMD /h2GLX42dqRAmhdcWi1anGi/ao5PJ8MrPFltxWAY9KRI2sz57xN26zLiOaYD4Y3l J7Dke7X1KJL93ylltG+EqsEzadURzNaRzpqTDk5DJxRdutOjD0nbZ82zflL4dUpW Ch43qWtgJMNmrTQt760SrDp5RfLM0NDkIFsEFkWMKPYx+0rLP/fv5e7F9aZGVlfH A2t+htGq4qCI//EocPADT57Jxcu+Yg== =D8rO -----END PGP SIGNATURE----- --=-=-=--