Report forwarded
to bug-guix@gnu.org: bug#41525; Package guix.
(Mon, 25 May 2020 12:08:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Lars-Dominik Braun <lars@6xq.net>:
New bug report received and forwarded. Copy sent to bug-guix@gnu.org.
(Mon, 25 May 2020 12:08:02 GMT) (full text, mbox, link).
Hello,
Lars-Dominik Braun <lars@6xq.net> writes:
> Hi,
>
> our package json-c is vulnerable to CVE-2020-12762[1]. Be careful when
> applying the “fix”, since it broke a lot of packages on Ubuntu and
> Gentoo[2] in the past week.
>
> Lars
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2020-12762
> [2] https://bugs.gentoo.org/722150
Thanks for the report!
This was fixed by Efraim on the 6th of August, with commit
10b40489742bdaa0d193c00dff1446b11c081f6a.
Closing,
Maxim
bug archived.
Request was from Debbugs Internal Request <help-debbugs@gnu.org>
to internal_control@debbugs.gnu.org.
(Wed, 18 Nov 2020 12:24:05 GMT) (full text, mbox, link).
Debbugs is free software and licensed under the terms of the
GNU Public License version 2. The current version can be
obtained from https://bugs.debian.org/debbugs-source/.