GNU bug report logs

#47259 python-pillow-simd package vulnerable to at least CVE-2021-25293

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #15 received at 47259-done@debbugs.gnu.org (full text, mbox, reply):

Received: (at 47259-done) by debbugs.gnu.org; 23 Mar 2022 12:39:36 +0000
From debbugs-submit-bounces@debbugs.gnu.org Wed Mar 23 08:39:36 2022
Received: from localhost ([127.0.0.1]:43005 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1nX0H1-0006W6-QD
	for submit@debbugs.gnu.org; Wed, 23 Mar 2022 08:39:35 -0400
Received: from baptiste.telenet-ops.be ([195.130.132.51]:42762)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <maximedevos@telenet.be>) id 1nX0Gz-0006Vl-Ih
 for 47259-done@debbugs.gnu.org; Wed, 23 Mar 2022 08:39:34 -0400
Received: from [IPv6:2a02:2c40:200:b001::1:66ec]
 ([IPv6:2a02:2c40:200:b001::1:66ec])
 by baptiste.telenet-ops.be with bizsmtp
 id 9ofW2700G48ECPd01ofXil; Wed, 23 Mar 2022 13:39:32 +0100
Message-ID: <7318489400ae1f00a40463e55f9637fe41d8e35e.camel@telenet.be>
Subject: Re: bug#47259: python-pillow-simd package vulnerable to at least
 CVE-2021-25293
From: Maxime Devos <maximedevos@telenet.be>
To: Maxim Cournoyer <maxim.cournoyer@gmail.com>, Léo Le
 Bouter <lle-bout@zaclys.net>
Date: Wed, 23 Mar 2022 13:39:25 +0100
In-Reply-To: <87r16tz87g.fsf@gmail.com>
References: <932873dcc65d8416e419c95caf9ebb0536f2ae98.camel@zaclys.net>
 <87r16tz87g.fsf@gmail.com>
Content-Type: multipart/signed; micalg="pgp-sha512";
 protocol="application/pgp-signature"; boundary="=-A5pgcYY+txTQiPrtxBq7"
User-Agent: Evolution 3.38.3-1 
MIME-Version: 1.0
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=telenet.be; s=r22;
 t=1648039172; bh=37ZGnNKgive8iwBvgWUB57t3cFb3jhSEVoALYjYcpyE=;
 h=Subject:From:To:Cc:Date:In-Reply-To:References;
 b=f40xwS9qHYkt9umMxaWBQnwWPKt89bN5LNsTk8dL5WOihPBio33JRQacJpQbZUZNC
 bR35rJo6s8gM1nbrtahWc2AvWde6tr+nowMll4fB94Y833MPTZph5owHJUg8ZUvOgI
 8oUYRC2SqUz6lBY8M0tIuhZJk7QtF94lKFSbv5VFbbbiol/omXBUfNHTdXCdyuxhhV
 tZ+F1Tz9lAT4Adhl8f3Uh5J2vN4AQeWWfjuRJks8jmKG5rWZkRHNM1B9s9gjXPmU1C
 q+kS2QG2wKvrU4hUymKZ8/lOJP0BcCFRuxnlV2VFmZjFtzg4wT2XrMQ79LwVojes6D
 ckfoEYo417/Tw==
X-Spam-Score: -0.7 (/)
X-Debbugs-Envelope-To: 47259-done
Cc: 47259-done@debbugs.gnu.org
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -1.7 (-)
[Message part 1 (text/plain, inline)]
Maxim Cournoyer schreef op di 22-03-2022 om 22:57 [-0400]:
> Léo Le Bouter <lle-bout@zaclys.net> writes:
> 
> > Hello!
> > 
> > pillow-simd is a fork of pillow (
> > https://github.com/uploadcare/pillow-simd), it's currently still at
> > version 7.x and it does not seem like it backports security patches
> > from pillow.
> 
> Thanks for the heads-up; our package is currently at 9.0.0, and I've
> just updated it to 9.0.0.post1.

Something went wrong
<https://git.savannah.gnu.org/cgit/guix.git/commit/?id=4a828263791ebb8ed8f8104e015a8f467008fc76>:
the version in the version field contains a "v" prefix which is dropped
in Guix.
Additionally, the package name is missing from the commit message,
though that cannot be corrected retroactively.

WDYT of removing the "v", and changing the "commit" field to

  (commit (string-append "v" version))

?

Greetings,
Maxime.

[signature.asc (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sun Dec 22 02:05:36 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.