From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: Re: [PATCH 0/1] fontconfig: CVE-2016-5384 Date: Mon, 8 Aug 2016 20:33:52 -0400 Message-ID: <20160809003352.GA3707@jasmine> References: <87bn12q28x.fsf@netris.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:35518) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bWuzh-0005hn-KD for guix-devel@gnu.org; Mon, 08 Aug 2016 20:34:10 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bWuzd-0006GY-Fk for guix-devel@gnu.org; Mon, 08 Aug 2016 20:34:08 -0400 Received: from out2-smtp.messagingengine.com ([66.111.4.26]:59900) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bWuzb-0006EU-1s for guix-devel@gnu.org; Mon, 08 Aug 2016 20:34:05 -0400 Content-Disposition: inline In-Reply-To: <87bn12q28x.fsf@netris.org> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Mark H Weaver Cc: guix-devel@gnu.org On Mon, Aug 08, 2016 at 07:17:50PM -0400, Mark H Weaver wrote: > Leo Famulari writes: > > > This patch uses a graft to apply the upstream fix to fontconfig for > > CVE-2016-5384. I learned about the bug from a Debian security advisory: > > > > https://security-tracker.debian.org/tracker/CVE-2016-5384 > > https://www.debian.org/security/2016/dsa-3644 > > Looks good to me. Please push. Thanks for the review! Pushed as 6b5e654d