GNU bug report logs

#49817 [PATCH] gnu: libsndfile: Update to 1.1.0beta1 [fixes CVE-2021-3246].

PackageSource(s)Maintainer(s)
guix-patches PTS Buildd Popcon
Full log

Message #25 received at 49817@debbugs.gnu.org (full text, mbox, reply):

Received: (at 49817) by debbugs.gnu.org; 5 Apr 2023 16:20:26 +0000
From debbugs-submit-bounces@debbugs.gnu.org Wed Apr 05 12:20:26 2023
Received: from localhost ([127.0.0.1]:52501 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1pk5s2-0000Z5-IN
	for submit@debbugs.gnu.org; Wed, 05 Apr 2023 12:20:26 -0400
Received: from sail-ipv4.us-core.com ([208.82.101.137]:45218)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <felix.lechner@lease-up.com>) id 1pk5s0-0000Yv-NT
 for 49817@debbugs.gnu.org; Wed, 05 Apr 2023 12:20:25 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; s=2017; bh=HO8qaSQiXidXFqS
 Jrl/Yuagx3d9Tfnuv5FsjjsPWIj8=;
 h=cc:to:subject:date:from:in-reply-to:
 references; d=lease-up.com; b=Wv+wDicP0R3WH7eb7wKKMobXl4abElCqYeOt8k5D
 ZW8o7Q/pK8i3BKPVudnJWHCEjBGjpoLovMOlxFzsGGYePGXHD0/4u0iDK4XdDQjeIE/BWc
 4+37N5tPX7oX6zdA+eDWfVS5NuW26E+1SvXO/UsGsZKa9iotYcMSSvZQUvAz4=
Received: by sail-ipv4.us-core.com (OpenSMTPD) with ESMTPSA id 004abfe8
 (TLSv1.3:TLS_CHACHA20_POLY1305_SHA256:256:NO)
 for <49817@debbugs.gnu.org>; Wed, 5 Apr 2023 16:20:22 +0000 (UTC)
Received: by mail-lj1-f182.google.com with SMTP id y7so5426537ljp.2
 for <49817@debbugs.gnu.org>; Wed, 05 Apr 2023 09:20:22 -0700 (PDT)
X-Gm-Message-State: AAQBX9cCuwVIu2U1GzICo51S42U5B5fktrIx52fFXItSEsyB32px4FcU
 i8cWEVuvzGTXaczt50oaj6/PzKNupM9YiiMw5FQ=
X-Google-Smtp-Source: AKy350bUedzn4L0LBbpwFXXZR5/ATG4L+QlgOEhz4dbDmWcZddWBdOG9rEQoLCVAN2u6kXvI9+EFsCfuOTSbxcehiTc=
X-Received: by 2002:a2e:a30b:0:b0:298:a7be:4a8d with SMTP id
 l11-20020a2ea30b000000b00298a7be4a8dmr2353189lje.8.1680711620168; Wed, 05 Apr
 2023 09:20:20 -0700 (PDT)
MIME-Version: 1.0
References: <ZCzhmHZw/KUuHZ4M@jasmine.lan>
 <CAFHYt54bMuO58B7jHLDP-w+=JkgvkGN3e914dHvC3F9OO_zOmw@mail.gmail.com>
 <ZC01TQBgDyWGOCLA@jurong>
In-Reply-To: <ZC01TQBgDyWGOCLA@jurong>
From: Felix Lechner <felix.lechner@lease-up.com>
Date: Wed, 5 Apr 2023 09:19:43 -0700
X-Gmail-Original-Message-ID: <CAFHYt546Ezx8VBw77Hh2SKw6v7X4bDkTibMu9QZOnU_Vkx-XNQ@mail.gmail.com>
Message-ID: <CAFHYt546Ezx8VBw77Hh2SKw6v7X4bDkTibMu9QZOnU_Vkx-XNQ@mail.gmail.com>
Subject: Re: [core-updates] It would be nice to fix libsndfile CVE-2021-3246
 (arbitrary code execution via crafted WAV file)
To: Andreas Enge <andreas@enge.fr>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Spam-Score: 0.0 (/)
X-Debbugs-Envelope-To: 49817
Cc: guix-devel@gnu.org, 49817@debbugs.gnu.org, Leo Famulari <leo@famulari.name>
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -1.0 (-)
Hi everyone,

On Wed, Apr 5, 2023 at 1:46 AM Andreas Enge <andreas@enge.fr> wrote:
>
> I would suggest to keep the bug
> open until it is merged to master.

Do we have a hook that closes such bugs automatically via instructions
in commit messages?

If not, I'd be happy to look into writing such a thing. It would also
help to tie commits to bug reports, which can be good for research
after the fact.

Kind regards,
Felix




Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sun Dec 22 03:08:17 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.