GNU bug report logs

#47231 sqlite package is vulnerable to CVE-2020-11655, CVE-2020-11656, CVE-2020-13434, CVE-2020-13435, CVE-2020-13630, CVE-2020-13631, CVE-2020-13632, CVE-2020-15358 and CVE-2020-9327

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #16 received at submit@debbugs.gnu.org (full text, mbox, reply):

Received: (at submit) by debbugs.gnu.org; 25 Mar 2021 11:27:36 +0000
From debbugs-submit-bounces@debbugs.gnu.org Thu Mar 25 07:27:36 2021
Received: from localhost ([127.0.0.1]:37358 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1lPO9I-00028z-17
	for submit@debbugs.gnu.org; Thu, 25 Mar 2021 07:27:36 -0400
Received: from lists.gnu.org ([209.51.188.17]:40672)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <me@tobias.gr>) id 1lPO9F-00028p-Va
 for submit@debbugs.gnu.org; Thu, 25 Mar 2021 07:27:34 -0400
Received: from eggs.gnu.org ([2001:470:142:3::10]:33520)
 by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <me@tobias.gr>) id 1lPO9F-0002su-PV
 for bug-guix@gnu.org; Thu, 25 Mar 2021 07:27:33 -0400
Received: from tobias.gr ([2a02:c205:2020:6054::1]:45504)
 by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <me@tobias.gr>)
 id 1lPO9D-0005Hk-H5; Thu, 25 Mar 2021 07:27:33 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=tobias.gr; s=2018;
 bh=kGFuTIW+GMtgV/ntf4stIx4+E0QzmrC+Ep28MXz0RCI=; h=date:in-reply-to:
 subject:cc:to:from:references; b=a2Jk635QP5vs9hlhsQiQoZp9ht8LHJWmTUFXO
 LonzyVNMBB/4Q/ZvKG7waP9bn6fcf3LlkAIajBcMeaeSc08zpeyfyh1UcAfXfI0946tc66
 7ObJJp8igBxQRHl4KSV3MH+9wmf0AJnrS1uDYO0z83sDXcznyuqzgucK1oNrs2k2Q69Ite
 t6mkvIBWcHzE/BoapvKqghPCulcKsTt9/QDQVshBXHJtFosdWXkbV/JMIwcQNtr4NWaQbU
 u8I1DpeuvuJ3QRO2oysi0eE54BJFYlk20ajIpMybD0FgTuaMu9mzXe/qpzPPFHr8sStp3v
 4zdIPhRU+3LvpjVgcCOUHwXLw==
Received: by submission.tobias.gr (OpenSMTPD) with ESMTPSA id 2062aee3
 (TLSv1.2:ECDHE-ECDSA-AES256-GCM-SHA384:256:NO); 
 Thu, 25 Mar 2021 11:28:33 +0000 (UTC)
References: <0381641839f5d0e71cbb496b95b9947a2a2c2799.camel@zaclys.net>
 <e38a431d1fe6bd5b2a79746b04497cc3fec49c59.camel@zaclys.net>
 <b8543b82478ccf61691186795f331f6ff9679862.camel@zaclys.net>
From: Tobias Geerinckx-Rice <me@tobias.gr>
To: Léo Le Bouter <lle-bout@zaclys.net>, Ludovic
 Courtès <ludo@gnu.org>
Subject: Re: bug#47231: sqlite package is vulnerable to CVE-2020-11655,
 CVE-2020-11656, CVE-2020-13434, CVE-2020-13435, CVE-2020-13630,
 CVE-2020-13631, CVE-2020-13632, CVE-2020-15358 and CVE-2020-9327
In-reply-to: <b8543b82478ccf61691186795f331f6ff9679862.camel@zaclys.net>
BIMI-Selector: v=BIMI1; s=default;
Message-ID: <87y2ebh3rz.fsf@nckx>
Date: Thu, 25 Mar 2021 12:27:28 +0100
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
Received-SPF: pass client-ip=2a02:c205:2020:6054::1; envelope-from=me@tobias.gr;
 helo=tobias.gr
X-Spam_score_int: -20
X-Spam_score: -2.1
X-Spam_bar: --
X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001,
 SPF_PASS=-0.001 autolearn=ham autolearn_force=no
X-Spam_action: no action
X-Spam-Score: -1.4 (-)
X-Debbugs-Envelope-To: submit
Cc: 47231@debbugs.gnu.org, bug-guix@gnu.org
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -2.4 (--)
Thanks!

I'm currently rebuilding IceCat with this change as an extra 
precaution, but that shouldn't take long.  If that doesn't cause 
problems this LGTM for master.

Ludo', do you think the Guix test described here is a good one?

Kind regards,

T G-R




Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Thu Jan 2 15:13:43 2025; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.