From mboxrd@z Thu Jan 1 00:00:00 1970 From: Mark H Weaver Subject: Re: [PATCH 0/1] fontconfig: CVE-2016-5384 Date: Mon, 08 Aug 2016 19:17:50 -0400 Message-ID: <87bn12q28x.fsf@netris.org> References: Mime-Version: 1.0 Content-Type: text/plain Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:50637) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bWto7-0003vD-5f for guix-devel@gnu.org; Mon, 08 Aug 2016 19:18:08 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bWto3-0000wE-4z for guix-devel@gnu.org; Mon, 08 Aug 2016 19:18:07 -0400 Received: from world.peace.net ([50.252.239.5]:54031) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bWto3-0000wA-1V for guix-devel@gnu.org; Mon, 08 Aug 2016 19:18:03 -0400 In-Reply-To: (Leo Famulari's message of "Mon, 8 Aug 2016 18:59:40 -0400") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Leo Famulari Cc: guix-devel@gnu.org Leo Famulari writes: > This patch uses a graft to apply the upstream fix to fontconfig for > CVE-2016-5384. I learned about the bug from a Debian security advisory: > > https://security-tracker.debian.org/tracker/CVE-2016-5384 > https://www.debian.org/security/2016/dsa-3644 Looks good to me. Please push. Thank you! Mark