From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: Re: [PATCH] gnu: tar: Fix CVE-2016-6321. Date: Sun, 1 Jan 2017 20:24:15 -0500 Message-ID: <20170102012415.GA14952@jasmine> References: <87h95kplte.fsf@gmail.com> <87tw9km9ht.fsf@gmail.com> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="liOOAslEiF7prFVr" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:54654) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cNrMR-0005gJ-6Q for guix-devel@gnu.org; Sun, 01 Jan 2017 20:24:28 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cNrMO-0003Ly-3W for guix-devel@gnu.org; Sun, 01 Jan 2017 20:24:27 -0500 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:55635) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cNrMN-0003Lh-L1 for guix-devel@gnu.org; Sun, 01 Jan 2017 20:24:24 -0500 Content-Disposition: inline In-Reply-To: <87tw9km9ht.fsf@gmail.com> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Alex Vong Cc: guix-devel@gnu.org --liOOAslEiF7prFVr Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sat, Dec 31, 2016 at 10:57:50PM +0800, Alex Vong wrote: > This is an updated version of the patch. There is only a minor stylish > change, spaces in local.mk are changed to tabs. >=20 > From 0cf96ac1167906565c560a12ab730d2192779315 Mon Sep 17 00:00:00 2001 > From: Alex Vong > Date: Sat, 31 Dec 2016 00:05:49 +0800 > Subject: [PATCH] gnu: tar: Fix CVE-2016-6321. >=20 > * gnu/packages/patches/tar-CVE-2016-6321.patch: New file. > * gnu/local.mk (dist_patch_DATA): Add it. > * gnu/packages/base.scm (tar)[source]: Add it. Thanks! Pushed to core-updates with some minor edits to the patch file commentary. --liOOAslEiF7prFVr Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAlhpq78ACgkQJkb6MLrK fwgbLg//UNoD5zG+rUmeu5Wgjht7d8cZTR7aktZJo/8AvVmW3SwYNcK+Sz93/kH+ eLp5+woOD3xmYAsM0uCDQYANbavPwoMjkm7K9hkchlP9I060v5psRSuCeuq/ss9z EIas6VX7Z6LYsHWTUojZ5kYShf3AuQf+IDr0z6WaBLm/ezW3C1+xbYt2ZCbv02gA 7VQlIGSwAl649CI2cUsNrJg7v7PD89Z9luMFRUENqBRsp616Sofe3SSyYu9j2RWx QgsrHCzFb9Vp1KaXSl/hCIFIvRo+ytIj2q2aDqVg3KdmZN11LdjA1Yw3uFN6tFrO t8+mPDCxpzmFJcJGX7JpfxnCmeBukCJ/fVmY+qToHakmYDiipOjjy7em0vIhx37h pcNbf8T8UUDflznRcHD3IbF1EiMBt2DkJwqeUQIXOKK3OFN3Pe/smgiBSe54/8MV 4DqNE8iidLpQAiXLIYImUbnyTANIgh7WNjhTOtlLHBKg/1sOzIMlXchI0n82raLA wIvc+4eTzis6q0nXPny6IXwk8dz3pqFecb007PnG8SwL5VyzCLMnF0vwFEtNkvzL 2tmVwSmF0ZyHlbYJjsTpWwhTAH8zrxQ4GqGUyZyhQXlUTGMoFdw/jqUQJQd8OLgI Upg4RtV8CwpZmP/RpMMeFfjyGVJcimBJNmszUGF+M1xNCvvWoek= =pjm7 -----END PGP SIGNATURE----- --liOOAslEiF7prFVr--