GNU bug report logs

#49817 [PATCH] gnu: libsndfile: Update to 1.1.0beta1 [fixes CVE-2021-3246].

PackageSource(s)Maintainer(s)
guix-patches PTS Buildd Popcon
Full log

Message #22 received at 49817@debbugs.gnu.org (full text, mbox, reply):

Received: (at 49817) by debbugs.gnu.org; 5 Apr 2023 15:54:22 +0000
From debbugs-submit-bounces@debbugs.gnu.org Wed Apr 05 11:54:22 2023
Received: from localhost ([127.0.0.1]:52486 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1pk5Sn-0007zV-S1
	for submit@debbugs.gnu.org; Wed, 05 Apr 2023 11:54:22 -0400
Received: from out5-smtp.messagingengine.com ([66.111.4.29]:48013)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <leo@famulari.name>) id 1pk5Sm-0007z7-VB
 for 49817@debbugs.gnu.org; Wed, 05 Apr 2023 11:54:21 -0400
Received: from compute3.internal (compute3.nyi.internal [10.202.2.43])
 by mailout.nyi.internal (Postfix) with ESMTP id D6D9D5C020F;
 Wed,  5 Apr 2023 11:54:15 -0400 (EDT)
Received: from mailfrontend1 ([10.202.2.162])
 by compute3.internal (MEProxy); Wed, 05 Apr 2023 11:54:15 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name;
 h=cc:cc:content-type:content-type:date:date:from:from
 :in-reply-to:in-reply-to:message-id:mime-version:references
 :reply-to:sender:subject:subject:to:to; s=mesmtp; t=1680710055;
 x=1680796455; bh=CuAGOUbcDDrvOuwkdWBU+3dKnVAjwi3lGwtI1RLts+w=; b=
 i9sP2VKfP53e6bkn5LHnjreRKt5kFD/f+8XYmiT5feg2oWhdonvvDCsXlQIILLPS
 NTEzp4hPxWHIhOPP6HxetuFu0ddXkCdGkfiF8UBB34FwYBOdPoW1IcArSHPvi5v3
 ez5uLfnMQMJooG5v3hv8AYRHWtLM9Eq6ApU9kfPVpiY=
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
 messagingengine.com; h=cc:cc:content-type:content-type:date:date
 :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to
 :message-id:mime-version:references:reply-to:sender:subject
 :subject:to:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender
 :x-sasl-enc; s=fm2; t=1680710055; x=1680796455; bh=CuAGOUbcDDrvO
 uwkdWBU+3dKnVAjwi3lGwtI1RLts+w=; b=F5LCXmg/me6s8oxGu5tgUj/Btj6/t
 wTNxIjFzZyE5NoRbBQXkv4LOhf3mCYKeoC2TXVeXryotRe1/Ujp04epi1DK/GObI
 GieAdXXhRLVxMLYsQUwLYK8vAkArDfFi6gvzofpBRJzTsxaQbZIcPt3x7FMEXHmc
 8H//kLHMgregG1d4sHyylr0+y3/uBbGkiiSGbzsrZ7Nk1MRnREgA03/NfjCf9t2R
 n86K9iHGkfhVsZ8euJrcJ9nOl1Apl1aqcKTsJN49gvMKeP49Mpvf5rmVBa+Onl34
 0BSdiJYy6pgxbbtvqywxuR2wScLgBWQDuPoX9bvqj0s2d0TD5NNfFPO0g==
X-ME-Sender: <xms:p5ktZHXKiRaAzgk1N80_qGW-Nbo70sv8vTnMrMcGkaZJfu7Nkb1pBw>
 <xme:p5ktZPltYsZYrBA9Fngq6JX85KJyBVpAqpXhvijGvskqW6FEqYkbqZdvnYhwlmWOh
 QbR_LuhH5zeD6JisQ>
X-ME-Received: <xmr:p5ktZDbhoi1W1MjDwH8t-_bSZZ9CgQNqp1h9cvLYBWa29pSclMu4oA4ZP5UO9gqZ_-AUarHKljggI7VteZEQFR0P>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvhedrvdejuddgleehucetufdoteggodetrfdotf
 fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen
 uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne
 cujfgurhepfffhvfevuffkfhggtggujgesthdtredttddtvdenucfhrhhomhepnfgvohcu
 hfgrmhhulhgrrhhiuceolhgvohesfhgrmhhulhgrrhhirdhnrghmvgeqnecuggftrfgrth
 htvghrnhepieetudehfeekueefleegudfhjefgleehfeeluefhfeffgfeuudelhedvjeel
 ieetnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomheplh
 gvohesfhgrmhhulhgrrhhirdhnrghmvg
X-ME-Proxy: <xmx:p5ktZCXUW3u4SwIr1t58xznniJeERBz7ReCrKVVu7ieA3nzbvTN_RA>
 <xmx:p5ktZBlWEusgU6qpTzB7Tb3xHo3DwvVjHtUD1AZZuqHdZBSwTlmuGg>
 <xmx:p5ktZPe6Gx51NUp81BV-gJIbpZFR02YOuth84vVgUPXcGwj_twmkdA>
 <xmx:p5ktZGytPmau803eglRIT76QSXvmJek7W0wQAIZapq_Pz_CT4dxkkw>
Feedback-ID: i819c4023:Fastmail
Received: by mail.messagingengine.com (Postfix) with ESMTPA; Wed,
 5 Apr 2023 11:54:15 -0400 (EDT)
Date: Wed, 5 Apr 2023 11:54:13 -0400
From: Leo Famulari <leo@famulari.name>
To: Andreas Enge <andreas@enge.fr>
Subject: Re: [core-updates] It would be nice to fix libsndfile CVE-2021-3246
 (arbitrary code execution via crafted WAV file)
Message-ID: <ZC2ZpfVjumeRviQ4@jasmine.lan>
References: <ZCzhmHZw/KUuHZ4M@jasmine.lan>
 <CAFHYt54bMuO58B7jHLDP-w+=JkgvkGN3e914dHvC3F9OO_zOmw@mail.gmail.com>
 <ZC01TQBgDyWGOCLA@jurong>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <ZC01TQBgDyWGOCLA@jurong>
X-Spam-Score: -0.7 (/)
X-Debbugs-Envelope-To: 49817
Cc: guix-devel@gnu.org, 49817@debbugs.gnu.org,
 Felix Lechner <felix.lechner@lease-up.com>
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -1.7 (-)
On Wed, Apr 05, 2023 at 10:46:05AM +0200, Andreas Enge wrote:
> Well, an update causes a lot of rebuilds anyway. The NEWS of 1.2.0 look
> like it is in fact only a bugfix release, so I took the risk to update to
> this latest version. pulseaudio still compiles, and pavucontrol still works
> on my machine.
> 
> The update is pushed to core-updates, but I would suggest to keep the bug
> open until it is merged to master.

Thank you Andreas!




Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sun Dec 22 03:33:21 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.