GNU bug report logs

#27749 gnu: heimdal: Update to 7.4.0.

PackageSource(s)Maintainer(s)
guix-patches PTS Buildd Popcon
Full log

Message #33 received at 27749@debbugs.gnu.org (full text, mbox, reply):

Received: (at 27749) by debbugs.gnu.org; 19 Oct 2017 14:57:38 +0000
From debbugs-submit-bounces@debbugs.gnu.org Thu Oct 19 10:57:38 2017
Received: from localhost ([127.0.0.1]:50497 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1e5CGQ-0001CA-DB
	for submit@debbugs.gnu.org; Thu, 19 Oct 2017 10:57:38 -0400
Received: from mail-pf0-f177.google.com ([209.85.192.177]:45416)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <alexvong1995@gmail.com>) id 1e5CGM-0001Bs-0P
 for 27749@debbugs.gnu.org; Thu, 19 Oct 2017 10:57:37 -0400
Received: by mail-pf0-f177.google.com with SMTP id d28so6770059pfe.2
 for <27749@debbugs.gnu.org>; Thu, 19 Oct 2017 07:57:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;
 h=from:to:cc:subject:references:date:in-reply-to:message-id
 :user-agent:mime-version;
 bh=+EAsASmBvoUfu1GKwQyKgy62xgtcAY4Fgmxi5nYcUEQ=;
 b=WdQgDp4eWUkOVd44Ke4p5wG3xu9AKLDScAjyX/tlbKeqUzQR6owgsQ2qx1Mokk4PzN
 R8iqP9lp1zRqbgLokxM1m8LRxI6WXkzf8hkUX8PpQ9kNqFTDeKMSKmlMCFVeRFWotLYm
 hUzXJahR9D1NnXjlVuEiQ1HUCgmd76gjwOHPW4A0dn50Nj3OCKYgQeTJ6K4EdQC0YwsS
 mSf9p0CT2gvgzI9x9oxCTWasoJg9XfcOnBGgLm1ueGGw9w+YlzlNiZVZBgCzrzEyUzGb
 bOIUEHYt3G8ls4m89AyMt2Hl+ml4VjwVTR2WLvqYDyuyg5SKp9yNXI7IvIFX0ZN1Bi46
 1SzQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20161025;
 h=x-gm-message-state:from:to:cc:subject:references:date:in-reply-to
 :message-id:user-agent:mime-version;
 bh=+EAsASmBvoUfu1GKwQyKgy62xgtcAY4Fgmxi5nYcUEQ=;
 b=fmfC9B6JX+G/fN61lEXiiWaVfMFFnx/cvty/FRFTN6BeFwVLDkMfc6sv1ema5xq7a2
 cLwEi0fYSON8ileyaO6WYpfRJrZYdgM7TYiy0P7x4ps9yVnpZ1yM508+SDkflcyg6Br5
 Gkyy3dxK1KTU+rwcD7LZrW/woXMqYw5dDvP5hwcdVfJP96owJUHrJI2aCrvU7WODludR
 2CI90DPrb+W7X3QGg4of7b5lZ+i8rcKCWc2b7X+Cyahv2yGXY7IGu/mZnC1erPYOFnVC
 hwjrhHjxT8snqWDCaHNMwy1Khtxpa2QdchYSxMeX+jkVnB3rbdy6JTD7UwGtcf+W+x6E
 2RRg==
X-Gm-Message-State: AMCzsaWK/7DcWMv2ewkbCTgE1Oqk+lF9TeCpExHpSelzt/rCvl/uwwi/
 gGm8rHqP4p96sV9HHaK7rUo=
X-Google-Smtp-Source: ABhQp+RBbZjz4DL5bDWbTnsChfgskV2HlBf1zIp0ScGccXgfV+zkg23jaWNzqwJ3QXvxCz99KpESng==
X-Received: by 10.98.19.212 with SMTP id 81mr1830413pft.46.1508425048071;
 Thu, 19 Oct 2017 07:57:28 -0700 (PDT)
Received: from debian (1-64-81-208.static.netvigator.com. [1.64.81.208])
 by smtp.gmail.com with ESMTPSA id y27sm26909282pfi.107.2017.10.19.07.57.26
 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256);
 Thu, 19 Oct 2017 07:57:27 -0700 (PDT)
From: Alex Vong <alexvong1995@gmail.com>
To: Ricardo Wurmus <rekado@elephly.net>
Subject: Re: [bug#27749] [PATCH] gnu: heimdal: Update to 7.4.0 [fixes
 CVE-2017-11103].
References: <87wp76kv68.fsf@gmail.com> <20170718154906.GB16798@jasmine.lan>
 <87bmogzspe.fsf@gmail.com> <877ez4znze.fsf@gmail.com>
 <20170720195134.GA19680@jasmine.lan> <871sm03zyd.fsf@elephly.net>
Date: Thu, 19 Oct 2017 22:57:12 +0800
In-Reply-To: <871sm03zyd.fsf@elephly.net> (Ricardo Wurmus's message of "Wed,
 18 Oct 2017 23:31:38 +0200")
Message-ID: <87vajbchiv.fsf@gmail.com>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/25.3 (gnu/linux)
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-=";
 micalg=pgp-sha512; protocol="application/pgp-signature"
X-Spam-Score: -2.5 (--)
X-Debbugs-Envelope-To: 27749
Cc: 27749@debbugs.gnu.org, Leo Famulari <leo@famulari.name>
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -2.5 (--)
[Message part 1 (text/plain, inline)]
Ricardo Wurmus <rekado@elephly.net> writes:

> Hi Alex,
>
>> On Wed, Jul 19, 2017 at 07:04:53PM +0800, Alex Vong wrote:
>>> Here is the updated patch:
>>>
>>> From 33ae64ead2031e7707639302977d31487e992660 Mon Sep 17 00:00:00 2001
>>> From: Alex Vong <alexvong1995@gmail.com>
>>> Date: Wed, 19 Jul 2017 17:01:47 +0800
>>> Subject: [PATCH] gnu: heimdal: Fix CVE-2017-{6594,11103}.
>>>
>>> * gnu/packages/patches/heimdal-CVE-2017-6594.patch,
>>> gnu/packages/patches/heimdal-CVE-2017-11103.patch: New files.
>>> * gnu/local.mk (dist_patch_DATA): Add them.
>>> * gnu/packages/kerberos.scm (heimdal)[source]: Use them.
>>
>> Thanks! I recreated the commit since the patch no longer applied to
>> 'gnu/local.mk' and pushed as 81c35029d4ee4fa7cd517998844229a514b35531.
>>
>> I'm leaving this bug open for now so we can discuss the update.
>
> As mentioned before, the new release bundles a bunch of third party
> libraries.  It is not clear to me if *all* things under “lib” are
> external libraries or if some of them are part of the source code of
> heimdal.
>
No, I don't think so. At least the heimdal/ subdirectory[0] should
contain non-third-party code.

> Can we learn from the Debian package for heimdal here?
>
Good suggestion, I think the Build-Depends field in [1] will help. For
exmaples, we should not use the bundled sqlite.

> I think we really ought to update from the very old version we are using
> currently.
>
Agree, our version is even older than the one in Debian old stable.

> --
> Ricardo
>
> GPG: BCA6 89B6 3655 3801 C3C6  2150 197A 5888 235F ACAC
> https://elephly.net

[0]: https://anonscm.debian.org/cgit/collab-maint/heimdal.git/tree/lib.
[1]: https://anonscm.debian.org/cgit/collab-maint/heimdal.git/tree/debian/control
[signature.asc (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sat Dec 21 17:15:16 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.