Report forwarded
to bug-guix@gnu.org: bug#47510; Package guix.
(Wed, 31 Mar 2021 01:51:01 GMT) (full text, mbox, link).
Acknowledgement sent
to Léo Le Bouter <lle-bout@zaclys.net>:
New bug report received and forwarded. Copy sent to bug-guix@gnu.org.
(Wed, 31 Mar 2021 01:51:01 GMT) (full text, mbox, link).
I asked the maintainer to fix the issues because they were unfixed
since a while, they have done so recently:
https://git.savannah.gnu.org/cgit/cflow.git/commit/?id=b9a7cd5e9d4efb54141dd0d11c319bb97a4600c6
They have not made a recently, also it seems they fixed other issues
that could be security relevant in their commit log, not sure if we
apply/backport patches or wait for release.
Added tag(s) security.
Request was from Léo Le Bouter <lle-bout@zaclys.net>
to control@debbugs.gnu.org.
(Wed, 31 Mar 2021 01:52:01 GMT) (full text, mbox, link).
Reply sent
to Maxim Cournoyer <maxim.cournoyer@gmail.com>:
You have taken responsibility.
(Fri, 18 Mar 2022 02:36:02 GMT) (full text, mbox, link).
Notification sent
to Léo Le Bouter <lle-bout@zaclys.net>:
bug acknowledged by developer.
(Fri, 18 Mar 2022 02:36:02 GMT) (full text, mbox, link).
Subject: Re: bug#47510: cflow is vulnerable to CVE-2019-16165 and
CVE-2019-16166
Date: Thu, 17 Mar 2022 22:35:12 -0400
Hello!
Léo Le Bouter <lle-bout@zaclys.net> writes:
> I asked the maintainer to fix the issues because they were unfixed
> since a while, they have done so recently:
>
> https://git.savannah.gnu.org/cgit/cflow.git/commit/?id=b9a7cd5e9d4efb54141dd0d11c319bb97a4600c6
>
> They have not made a recently, also it seems they fixed other issues
> that could be security relevant in their commit log, not sure if we
> apply/backport patches or wait for release.
Our cflow package is now at 1.7, which includes the above commit and CVE
fixes.
Thank you,
Maxim
bug archived.
Request was from Debbugs Internal Request <help-debbugs@gnu.org>
to internal_control@debbugs.gnu.org.
(Fri, 15 Apr 2022 11:24:04 GMT) (full text, mbox, link).
Debbugs is free software and licensed under the terms of the
GNU Public License version 2. The current version can be
obtained from https://bugs.debian.org/debbugs-source/.