Report forwarded
to bug-guix@gnu.org: bug#47418; Package guix.
(Fri, 26 Mar 2021 19:53:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Léo Le Bouter <lle-bout@zaclys.net>:
New bug report received and forwarded. Copy sent to bug-guix@gnu.org.
(Fri, 26 Mar 2021 19:53:02 GMT) (full text, mbox, link).
Added tag(s) security.
Request was from Léo Le Bouter <lle-bout@zaclys.net>
to control@debbugs.gnu.org.
(Fri, 26 Mar 2021 20:56:02 GMT) (full text, mbox, link).
Information forwarded
to bug-guix@gnu.org: bug#47418; Package guix.
(Fri, 26 Mar 2021 23:13:02 GMT) (full text, mbox, link).
Léo Le Bouter via Bug reports for GNU Guix <bug-guix@gnu.org> writes:
> * gnu/packages/patches/imagemagick-CVE-2020-27829.patch: New patch.
> * gnu/local.mk (dist_patch_DATA): Register it.
> * gnu/packages/imagemagick.scm (imagemagick/fixed): Apply patch to existing
> graft.
> ---
> gnu/local.mk | 1 +
> gnu/packages/imagemagick.scm | 3 ++-
> .../patches/imagemagick-CVE-2020-27829.patch | 23 +++++++++++++++++++
> 3 files changed, 26 insertions(+), 1 deletion(-)
> create mode 100644 gnu/packages/patches/imagemagick-CVE-2020-27829.patch
Your patch looks good to me, but I've just posted an alternative patch
set to 'guix-devel' which should enable us to keep ImageMagick
up-to-date without grafting, and which fixes this security flaw and
more.
https://lists.gnu.org/archive/html/guix-devel/2021-03/msg00538.html
It's not a big deal, but if you push your patch now, I would need to
rebase the patch set on top of it.
Mark
Information forwarded
to bug-guix@gnu.org: bug#47418; Package guix.
(Sat, 27 Mar 2021 13:32:02 GMT) (full text, mbox, link).
On Sat, 2021-03-27 at 09:27 -0400, Mark H Weaver wrote:
> Your patch looks good to me, but I've just posted an alternative
> patch
> set to 'guix-devel' which should enable us to keep ImageMagick
> up-to-date without grafting, and which fixes this security flaw and
> more.
>
> https://lists.gnu.org/archive/html/guix-devel/2021-03/msg00538.html
>
> It's not a big deal, but if you push your patch now, I would need to
> rebase the patch set on top of it.
>
> Mark
Thank you, let's get your better patch in then close this.
Léo Le Bouter <lle-bout@zaclys.net> writes:
> Thank you, let's get your better patch in then close this.
I've now pushed those patches to 'master'. CVE-2020-27829 is fixed in
commit bfc69d5e7c45eac865e231643b58396580afb231, so I'm closing this bug
now.
Thanks!
Mark
bug archived.
Request was from Debbugs Internal Request <help-debbugs@gnu.org>
to internal_control@debbugs.gnu.org.
(Sun, 25 Apr 2021 11:24:04 GMT) (full text, mbox, link).
Debbugs is free software and licensed under the terms of the
GNU Public License version 2. The current version can be
obtained from https://bugs.debian.org/debbugs-source/.