GNU bug report logs

#32877 Python-2 CVE-2018-1060 CVE-2018-1061 CVE-2018-14647 CVE-2018-1000802

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #21 received at 32877-done@debbugs.gnu.org (full text, mbox, reply):

Received: (at 32877-done) by debbugs.gnu.org; 17 Oct 2018 18:35:56 +0000
From debbugs-submit-bounces@debbugs.gnu.org Wed Oct 17 14:35:56 2018
Received: from localhost ([127.0.0.1]:55620 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1gCqfk-0001U1-Cq
	for submit@debbugs.gnu.org; Wed, 17 Oct 2018 14:35:56 -0400
Received: from out3-smtp.messagingengine.com ([66.111.4.27]:59651)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <mbakke@fastmail.com>) id 1gCqfh-0001Ts-SS
 for 32877-done@debbugs.gnu.org; Wed, 17 Oct 2018 14:35:54 -0400
Received: from compute5.internal (compute5.nyi.internal [10.202.2.45])
 by mailout.nyi.internal (Postfix) with ESMTP id 7B04D220A5;
 Wed, 17 Oct 2018 14:35:53 -0400 (EDT)
Received: from mailfrontend1 ([10.202.2.162])
 by compute5.internal (MEProxy); Wed, 17 Oct 2018 14:35:53 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fastmail.com; h=
 from:to:cc:subject:in-reply-to:references:date:message-id
 :mime-version:content-type; s=fm1; bh=y4XG6LcbHSXJZJogR7j3zL3BYw
 onWczfLM2R2w/859U=; b=jNtPm0CbChX/3STcX+mhY7a2oU9jg0iHVN1deu7Iif
 QZX5V7QhxSjOvmI7mksKzAdC/MzHQ65cz//G/y1eKVRdcVJF3hN3w/kdd64yDneS
 E93q2GjNiv7MNtNaY0US4xhW/b/foQ7nHt1Ral6cIFBD+ZuA6D2Kj7TTNsL5w/+X
 lIyG0BxBhKSQOeW9iiQxVN0EavXK87aERz8sQpZGpSDDCEXj7m0Q2XsHeZ03mHfj
 ghJdPutek9pdVkPbSj+oU4iKB5wmMsqfkvYFapVnZF+E9S48lH28PYTSZHnhl3Yd
 BqofNFgAVNHK5i9JMG7VwW1wDxI35pKBvjr5RMENF9Bw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
 messagingengine.com; h=cc:content-type:date:from:in-reply-to
 :message-id:mime-version:references:subject:to:x-me-proxy
 :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; bh=y4XG6L
 cbHSXJZJogR7j3zL3BYwonWczfLM2R2w/859U=; b=R35EgJJkoCdGdVCG/9fVjk
 0YrOpiajQKciI1Ywi5brOze9vl8tA6bb7mevpUHn542wzishYPPrhfquFqgD1rQN
 xtMsyWrHMYkB31wr40+FZOZj+AeIois5Cl9apVFN+/H5R3cOTBuG4kCrTbXfXQ0P
 ddGKyh7FUGy4pvUEyFdbyfT7TL9iAJwFERRzAV0BY+Xtt1196mjkfdoMOurH6RR/
 v9sZP3zE9JLZ55h/XxfzYrNKLA7mQflM5LuHM/elWlKKSMQV99Qs31Io0wp7IPRr
 RhqOa1jLJ7DM+qrmdcdyOc2RASSxB7R15ZJFPUWDGhGLo8KZupNsnQMx69KLq9eg
 ==
X-ME-Sender: <xms:B4HHW3mIQQP-lJ1qSgnoyiEFX0EC2cLal14kKYI7MAep6USj6PbCLg>
X-ME-Proxy: <xmx:B4HHW9TO6Ldri-QVx5zDAy-JjaW72Jb8Z1p0Gq9CisVWGqFyJfvecg>
 <xmx:B4HHW5YRPM95Knz5OyCXAOuXepe5Th-D1pyHE-OBbUDmV_EodmkGaA>
 <xmx:B4HHW3ES5AAjyGKR4Bch0511GAtr6ZdOgo8T8NyO-hkIGKFiqoFckw>
 <xmx:B4HHWwa1hykwieKSJte89SF4ms5WXiiRU3ti9KqN1xE9lxSzpPeTGA>
 <xmx:B4HHW13GM-T9gTOM_ZYhvmwunLMBg0fDv_kIoUBfecTv4bUrI3MTCw>
 <xmx:CYHHW-dWS90qJsIbS3_CDVOWY4k9-cb8WkmUf-4P_0tg5jAsbCWFjg>
Received: from localhost (140.226.16.62.customer.cdi.no [62.16.226.140])
 by mail.messagingengine.com (Postfix) with ESMTPA id 1CD10E421C;
 Wed, 17 Oct 2018 14:35:50 -0400 (EDT)
From: Marius Bakke <mbakke@fastmail.com>
To: Mark H Weaver <mhw@netris.org>, Leo Famulari <leo@famulari.name>
Subject: Re: bug#32877: Python-2 CVE-2018-1060 CVE-2018-1061 CVE-2018-14647
 CVE-2018-1000802
In-Reply-To: <87o9c0ykol.fsf@netris.org>
References: <20180929191827.GA17619@jasmine.lan> <87in2fhv8v.fsf@fastmail.com>
 <20181010191425.GA22832@jasmine.lan> <87o9c0ykol.fsf@netris.org>
User-Agent: Notmuch/0.27 (https://notmuchmail.org) Emacs/26.1
 (x86_64-pc-linux-gnu)
Date: Wed, 17 Oct 2018 20:35:49 +0200
Message-ID: <875zy0h14q.fsf@fastmail.com>
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-=";
 micalg=pgp-sha512; protocol="application/pgp-signature"
X-Spam-Score: -0.7 (/)
X-Debbugs-Envelope-To: 32877-done
Cc: 32877-done@debbugs.gnu.org
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -1.7 (-)
[Message part 1 (text/plain, inline)]
Mark H Weaver <mhw@netris.org> writes:

> Leo Famulari <leo@famulari.name> writes:
>
>> On Sat, Oct 06, 2018 at 06:53:36PM +0200, Marius Bakke wrote:
>>> From 2891a9acb7704c3397ef34fbb520b46936504422 Mon Sep 17 00:00:00 2001
>>> From: Marius Bakke <mbakke@fastmail.com>
>>> Date: Sat, 6 Oct 2018 18:50:47 +0200
>>> Subject: [PATCH] gnu: python2: Add upstream security fixes.
>>> 
>>> This addresses CVE-2018-{1060,1061,14647,1000802}.
>>> 
>>> * gnu/packages/patches/python2-CVE-2018-1000802.patch,
>>> gnu/packages/patches/python2-CVE-2018-1060.patch,
>>> gnu/packages/patches/python2-CVE-2018-1061.patch,
>>> gnu/packages/patches/python2-CVE-2018-14647.patch: New files.
>>> * gnu/local.mk (dist_patch_DATA): Register it.
>>> * gnu/packages/python.scm (python-2/fixed): New variable.
>>> (python-2.7)[replacement]: New field.
>>> (python2-minimal): Use PACKAGE/INHERIT.
>>
>> Thanks! I did some basic tests and things seem to work.
>
> I added this commit to my private branch a few days ago, along with the
> Python-3 CVE-2018-14647 fix (with the added hunk), updated my GuixSD
> GNOME 3 system and user profile, and everything seems to be working
> well.
>
> I think they are both ready to push to master.

Hi Mark,

Thank you very much for testing.  I've pushed these patches now, sorry
for the delay!
[signature.asc (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sun Dec 22 03:28:19 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.