From mboxrd@z Thu Jan 1 00:00:00 1970 From: Marius Bakke Subject: Re: binutils CVEs Date: Sun, 17 Sep 2017 20:25:11 +0200 Message-ID: <87a81tchdk.fsf@fastmail.com> References: <20170917181927.GB16737@macbook42.flashner.co.il> Mime-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:49529) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dteFs-00060B-CJ for guix-devel@gnu.org; Sun, 17 Sep 2017 14:25:25 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dteFn-0004do-N8 for guix-devel@gnu.org; Sun, 17 Sep 2017 14:25:20 -0400 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:43057) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1dteFn-0004dG-Ed for guix-devel@gnu.org; Sun, 17 Sep 2017 14:25:15 -0400 In-Reply-To: <20170917181927.GB16737@macbook42.flashner.co.il> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Efraim Flashner , guix-devel@gnu.org --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Efraim Flashner writes: > There's a large number of CVEs against binutils@2.28. Gentoo=C2=B9 has a = nice > long list of the CVEs, and I've put together a patch to graft a > replacement, but I'm getting grafting errors: > ERROR: replacement length differs from the original length "h9nqlf0c82c1s= ds4yzs60k7pm4f37si2-binutils-2.28" "wl5dg3dnqvk2v2ahh5iadnv1s34rsbb6-binuti= ls-2.28.1" This is because the replacement name is two bytes longer (.1). To fix it, the version field of the replacement must be set to something with equal length of "2.28". I suppose we can use just that and hard-code the source URL? --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEu7At3yzq9qgNHeZDoqBt8qM6VPoFAlm+vgcACgkQoqBt8qM6 VPqepwf/ewimrW6gk/eeryQmEtcjHLHB0s7yAJwrRCnWNHyUlnG9LZO2QOoSMqLx LXIViWT3GyVOW/gMPW7jAdtp6o4q2Oor33VVf7H/EjhF0VsIwPddQ3o9aGR9g9sF obd3yYHOktz2WcjoNhOwQgzgu08c919fCUueiWu3kmdl9BQbtWyAoLoLDLaKHhYX KrHnf7fIDHW8YM8xU51CzmdKpMTbqO7T6RLmV7txjP0kw3wxWZKWBdOZ3/8uuopx LMhCwp/ymZiqGuNbn1Muwi+uaSo3P1G7whD1Xq5cQGn6CSJ18U61RTe3qIV3puBe jBOKl7RnGVb4/7Li0ZyGoaOjRtdzNQ== =CFZB -----END PGP SIGNATURE----- --=-=-=--