From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp11.migadu.com ([2001:41d0:403:478a::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms9.migadu.com with LMTPS id 6Hk5D3T/JmURYgAA9RJhRA:P1 (envelope-from ) for ; Wed, 11 Oct 2023 22:03:00 +0200 Received: from aspmx1.migadu.com ([2001:41d0:403:478a::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp11.migadu.com with LMTPS id 6Hk5D3T/JmURYgAA9RJhRA (envelope-from ) for ; Wed, 11 Oct 2023 22:03:00 +0200 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id D36A856C39 for ; Wed, 11 Oct 2023 22:02:59 +0200 (CEST) Authentication-Results: aspmx1.migadu.com; dkim=none; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org"; dmarc=none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1697054580; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding:resent-cc: resent-from:resent-sender:resent-message-id:in-reply-to:in-reply-to: references:references:list-id:list-help:list-unsubscribe: list-subscribe:list-post; bh=nzQeh0KS9bKKqYi+9Ucf1B9NA0KbTpyGMSsQyLOFDd0=; b=aej1z5l+fVm7Wnur6eYMLhwKLzbaQ6D5NJ8TQ69B+iTglJTaqGoBeRCvaCL6ljTQVmyVQu kDy5ztUFOqvD/ogPdt2Aetf6tv5Fylt6wseDerugRA+fDFJfZ5IVq3rnVIohQHpnNFh90f N66D5PKUpXcFG+IunLnVoVPzsy4xYYwwoa7s+Z0SUZi/DIN3zvqRu3++f7RtXOvI4y7c3v dpI+BXI/Ws+x7XO42raSJ2EXj3vfA88jWcZy/uBML8nDQIxMY24DSfUNCqnMMNYlxqZKdP UAtzIWSC4d5V+iWQsHRJ3CaVlE8Q9oEGertwh9VGkKzY4qLcSYGUo1xnajrYHg== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1697054580; a=rsa-sha256; cv=none; b=dhw3bDDAAQho/kDTgk0okQu8VAyLbDWnCE7EBnl72kyBiaDlK7fJhANvkjcnh5oX4iLm75 +2xXWPDYnOhXf2htvez4rTaYXwp4aalx/bglX6s9WEHOEpQxI1e3tkqQQUuoD8I+Zuugvr xc+p//vDxgrknNJJC4jE87lC5MHdVOKQuI4q8wnK6mZRk6QLubXxaVY/I0nGhxZ85sYsY3 HRMmpMB0GuB3ybJXmhsQrD3SW/A03jTPicwK0gSwSmBFKJfyKbqAyfE8EKOKmThMATFQYE +U5KMHsXTFVqP15Dg3ntRt0Zvou8uaoXV39DPgmBtKB6mZ19xE+eGaG1jNydBw== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=none; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org"; dmarc=none Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1qqfPn-0004Aw-RX; Wed, 11 Oct 2023 16:02:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1qqfPk-0004Ad-Gs for guix-patches@gnu.org; Wed, 11 Oct 2023 16:02:40 -0400 Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1qqfPj-0004Br-Vy for guix-patches@gnu.org; Wed, 11 Oct 2023 16:02:40 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1qqfQ5-0003yg-OH for guix-patches@gnu.org; Wed, 11 Oct 2023 16:03:01 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#66428] [PATCH] gnu: libcue: Fix CVE-2023-43641. Resent-From: Bruno Victal Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Wed, 11 Oct 2023 20:03:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 66428 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: Leo =?UTF-8?Q?Nikkil=C3=A4?= Cc: 66428@debbugs.gnu.org Received: via spool by 66428-submit@debbugs.gnu.org id=B66428.169705456315250 (code B ref 66428); Wed, 11 Oct 2023 20:03:01 +0000 Received: (at 66428) by debbugs.gnu.org; 11 Oct 2023 20:02:43 +0000 Received: from localhost ([127.0.0.1]:40106 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1qqfPm-0003xt-TQ for submit@debbugs.gnu.org; Wed, 11 Oct 2023 16:02:43 -0400 Received: from smtpm1.myservices.hosting ([185.26.105.232]:45676) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1qqfPh-0003xW-Nw for 66428@debbugs.gnu.org; Wed, 11 Oct 2023 16:02:41 -0400 Received: from mail1.netim.hosting (unknown [185.26.106.173]) by smtpm1.myservices.hosting (Postfix) with ESMTP id 72E4E2056B; Wed, 11 Oct 2023 22:02:14 +0200 (CEST) Received: from localhost (localhost [127.0.0.1]) by mail1.netim.hosting (Postfix) with ESMTP id CA1C3800A3; Wed, 11 Oct 2023 22:02:13 +0200 (CEST) X-Virus-Scanned: Debian amavisd-new at mail1.netim.hosting Received: from mail1.netim.hosting ([127.0.0.1]) by localhost (mail1-2.netim.hosting [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id y03xrmC0_lFZ; Wed, 11 Oct 2023 22:02:13 +0200 (CEST) Received: from [192.168.1.116] (unknown [10.192.1.83]) (Authenticated sender: lumen@makinata.eu) by mail1.netim.hosting (Postfix) with ESMTPSA id 0048980060; Wed, 11 Oct 2023 22:02:08 +0200 (CEST) Message-ID: <987a1b4c-07e1-4284-9f58-ea0c0ce6c420@makinata.eu> Date: Wed, 11 Oct 2023 21:02:04 +0100 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Content-Language: en-US References: <20231009201647.9891-1-hello@lnikki.la> From: Bruno Victal In-Reply-To: <20231009201647.9891-1-hello@lnikki.la> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: guix-patches-bounces+larch=yhetil.org@gnu.org X-Migadu-Flow: FLOW_IN X-Migadu-Country: US X-Spam-Score: -5.88 X-Migadu-Queue-Id: D36A856C39 X-Migadu-Scanner: mx0.migadu.com X-Migadu-Spam-Score: -5.88 X-TUID: nd9OZgpzTp5n Hi Leo, I see that libcue 2.3.0 has been recently released to address this. How about updating the package instead? -- Furthermore, I consider that nonfree software must be eradicated. Cheers, Bruno.