From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:36435) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dn8Bh-0008I6-0E for guix-patches@gnu.org; Wed, 30 Aug 2017 14:58:05 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dn8Be-0002JW-Eu for guix-patches@gnu.org; Wed, 30 Aug 2017 14:58:05 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:54529) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1dn8Be-0002JI-9B for guix-patches@gnu.org; Wed, 30 Aug 2017 14:58:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1dn8Bd-0003R3-Vj for guix-patches@gnu.org; Wed, 30 Aug 2017 14:58:02 -0400 Subject: [bug#28294] [PATCH] gnu: libxml2: Fix CVE-2017-{0663, 7375, 7376, 9047, 9048, 9049, 9050}. Resent-Message-ID: From: Marius Bakke In-Reply-To: <87inh5uqpd.fsf@gmail.com> References: <87inh5uqpd.fsf@gmail.com> Date: Wed, 30 Aug 2017 20:57:37 +0200 Message-ID: <87inh4lw7y.fsf@fastmail.com> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: Alex Vong , 28294@debbugs.gnu.org --=-=-= Content-Type: text/plain Alex Vong writes: > Severity: important > Tags: patch security > > Hi, > > This patch fixes CVEs of libxml2. The changes to 'runtest.c' in > 'libxml2-CVE-2017-9049+CVE-2017-9050.patch are removed since they > introduce test failure. The changes only enable new tests so it should > be fine to remove them. Thanks for this! I think we have to graft this fix since changing 'libxml2' would rebuild 2/3 of the tree. Can you try that? PS: Do you have a Savannah account? I'm sure Ludo or someone can add you given the steady rate of quality commits. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEu7At3yzq9qgNHeZDoqBt8qM6VPoFAlmnCqEACgkQoqBt8qM6 VPpgUAgAt8wF7MOg7CNzSWdo75yanqUCZizJmlk8hOCRZuXCWbOLoZw7eRQcmL8W Lolnv1HfuW12ds1pBV2b0LT97CsFvA1fYpncogvIdRDBexQGYcYXNOqB/AhQoTjI 8hscQ0edaoAjNXOx3lnYbxH5JcxpQhhYbQlks0xHz1VzTTnqfduOI+FMNhve79dm uqr0i85zdfNfDgGA9H4/bTgyd6ghN6K9UZHbrkyDJFOapGrp9y14rlbd29iPz6xA wLZPucdvyBcEq9r+alc8F/xPdmyxTvk0qujWmGJcX/cKAcxaFQXhmnwcH9bXemCo 2gAyVjR0A9Xn9xedci2achKvMLlK2A== =s9Cq -----END PGP SIGNATURE----- --=-=-=--