Message #16 received at submit@debbugs.gnu.org (full text, mbox, reply):
Received: (at submit) by debbugs.gnu.org; 9 Apr 2021 00:01:42 +0000 From debbugs-submit-bounces@debbugs.gnu.org Thu Apr 08 20:01:42 2021 Received: from localhost ([127.0.0.1]:48593 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from <debbugs-submit-bounces@debbugs.gnu.org>) id 1lUeae-0006ah-DM for submit@debbugs.gnu.org; Thu, 08 Apr 2021 20:01:42 -0400 Received: from lists.gnu.org ([209.51.188.17]:41442) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from <leo@famulari.name>) id 1lUeab-0006aS-RO for submit@debbugs.gnu.org; Thu, 08 Apr 2021 20:01:35 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:41648) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <leo@famulari.name>) id 1lUeab-0000iQ-Jp for bug-guix@gnu.org; Thu, 08 Apr 2021 20:01:33 -0400 Received: from wout3-smtp.messagingengine.com ([64.147.123.19]:56915) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <leo@famulari.name>) id 1lUeaZ-0004Ll-3J for bug-guix@gnu.org; Thu, 08 Apr 2021 20:01:33 -0400 Received: from compute2.internal (compute2.nyi.internal [10.202.2.42]) by mailout.west.internal (Postfix) with ESMTP id F0FF8161D; Thu, 8 Apr 2021 20:01:28 -0400 (EDT) Received: from mailfrontend1 ([10.202.2.162]) by compute2.internal (MEProxy); Thu, 08 Apr 2021 20:01:29 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name; h=date:from:to:cc:subject:message-id:references:mime-version :content-type:in-reply-to; s=mesmtp; bh=ymg66VmiJ1PRuau5sHytN5LF 5xxt9BqO4tm1seltMdo=; b=DDx4vdvQ+oiYL2WPR1XMGkgZ2CLZuYdmOlRpnyiJ lzOsfkaAaX0uEZVSKWx1pNfoG2dXchg+wjtYLHsERBxjuYNeZKTyvT5w1dXS8kh8 UgKGfY/T3vE/+GvdebZkkvm+QXcWGWYG2zzbYIVyEj+MhxXFgJ5n6CHYVKAGXOSF fH4= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; bh=ymg66V miJ1PRuau5sHytN5LF5xxt9BqO4tm1seltMdo=; b=Yoe598bmNlCGBZg4xOaKEg 1wcFFr2vw87cmeWCgfTBlWHvg21VlyCUMXeTUMuwRspZZLFMNerz1hn+GMXZXge+ 1r3+VdzV6mCsA7vFRvHnmlNZcFZ3jqxsMPPKDic9cm/0RPZxUWcJPc+q2FFB5+Pg qScqLq2aFd6o402dOTL39/t5R4RgcXArGZIoHU2cqjtXXee2BEpvxin32KoKX4pW yW9pm4hO/ZOdTF9RfaHcnD8CXvZywu4UJpoUcc+qn8pW0u+pNU0jbs0ezzggmfFg 8avu3nJXqP5dz5vfeX40lFRWB4+QZvxRAXymzlqD2uGYnNx0GUmj+Ulo/BjMI4wA == X-ME-Sender: <xms:WJlvYCpd4xXClD8Ajukd21DMtFie5e0y6HabVysdUsuaZPC7NemyDg> <xme:WJlvYNFLqBjoZ2ntFN3SBkjRCIbWjUvxSQ8f9vl_NIeXGJ4PpKrB7T5lLpJlkTL21 CKJuz9tdHPxeR_BKw> X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrudektddgvdejucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepfffhvffukfhfgggtuggjsehgtderredttddvnecuhfhrohhmpefnvghoucfh rghmuhhlrghrihcuoehlvghosehfrghmuhhlrghrihdrnhgrmhgvqeenucggtffrrghtth gvrhhnpedukeevgeetkeeltefgiedtjefgjeekffduteehvdfhueekudelieekjeefheff teenucfkphepuddttddruddurdduieelrdduudeknecuvehluhhsthgvrhfuihiivgeptd enucfrrghrrghmpehmrghilhhfrhhomheplhgvohesfhgrmhhulhgrrhhirdhnrghmvg X-ME-Proxy: <xmx:WJlvYGHT0rk4zD5icHQd-9W2W04k082GCZFMMK1Rl8T1jGXGTB34ig> <xmx:WJlvYIAyYWmlB01h3JqYIv-ii6l2oSbmL8GXN-fl09bD4xB3RQxykg> <xmx:WJlvYLPnuO6hIlXGPrt2EMiXpZYJdD8tV1J8Yq55Fh6d0-MLfe8QNw> <xmx:WJlvYCddF59DSCB3ndFz5oyGcvazUTdDISUc1PUBoFgrFmc-Pal2cQ> Received: from localhost (pool-100-11-169-118.phlapa.fios.verizon.net [100.11.169.118]) by mail.messagingengine.com (Postfix) with ESMTPA id 0FA6A240057; Thu, 8 Apr 2021 20:01:28 -0400 (EDT) Date: Thu, 8 Apr 2021 20:01:26 -0400 From: Leo Famulari <leo@famulari.name> To: Léo Le Bouter via Bug reports for GNU Guix <bug-guix@gnu.org> Subject: Re: bug#47627: syncthing package is vulnerable to CVE-2021-21404 Message-ID: <YG+ZVl0SMWko4LOJ@jasmine.lan> References: <38a8a1cb8749b422642dfa6d5374c242ddb80b42.camel@zaclys.net> <YGzmAwp2zOS9lTD6@jasmine.lan> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="hJNysbSMk7R5YAXi" Content-Disposition: inline In-Reply-To: <YGzmAwp2zOS9lTD6@jasmine.lan> Received-SPF: pass client-ip=64.147.123.19; envelope-from=leo@famulari.name; helo=wout3-smtp.messagingengine.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.4 (-) X-Debbugs-Envelope-To: submit Cc: 47627@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: <debbugs-submit.debbugs.gnu.org> List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe> List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/> List-Post: <mailto:debbugs-submit@debbugs.gnu.org> List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help> List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe> Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org> X-Spam-Score: -0.1 (/)
[Message part 1 (text/plain, inline)]
[0001-gnu-Syncthing-Update-to-1.15.1-fixes-CVE-2021-21404.patch (text/plain, attachment)]
[signature.asc (application/pgp-signature, inline)]
Send a report that this bug log contains spam.
Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.