[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Chicken security bugs [was Re: address@hidden: Irregex packages shou
From: |
Kei Kebreau |
Subject: |
Re: Chicken security bugs [was Re: address@hidden: Irregex packages should be updated to 0.9.6]] |
Date: |
Thu, 22 Dec 2016 14:20:37 -0500 |
User-agent: |
Gnus/5.13 (Gnus v5.13) Emacs/25.1 (gnu/linux) |
Leo Famulari <address@hidden> writes:
> On Fri, Dec 16, 2016 at 02:33:19PM -0500, Leo Famulari wrote:
>> We fixed this bug in our guile-irregex package in commit fb73f07a0fe,
>> but our chez-irregex and chicken packages are still vulnerable.
>
> Also note that (I believe) our chicken package is vulnerable to
> CVE-2016-{6830,6831}:
>
> http://lists.nongnu.org/archive/html/chicken-announce/2016-08/msg00002.html
The attached patch is currently being tested on my computer, but I
suspect it will work.
See https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=834845.
0001-gnu-chicken-Fix-CVE-2016-6830-6831.patch
Description: Text document
signature.asc
Description: PGP signature
- address@hidden: Irregex packages should be updated to 0.9.6], Leo Famulari, 2016/12/16
- Chicken security bugs [was Re: address@hidden: Irregex packages should be updated to 0.9.6]], Leo Famulari, 2016/12/16
- Re: Chicken security bugs [was Re: address@hidden: Irregex packages should be updated to 0.9.6]],
Kei Kebreau <=
- Re: Chicken security bugs [was Re: address@hidden: Irregex packages should be updated to 0.9.6]], Leo Famulari, 2016/12/24
- Re: Chicken security bugs [was Re: address@hidden: Irregex packages should be updated to 0.9.6]], Kei Kebreau, 2016/12/24
- Re: Chicken security bugs [was Re: address@hidden: Irregex packages should be updated to 0.9.6]], Leo Famulari, 2016/12/24
- Re: Chicken security bugs [was Re: address@hidden: Irregex packages should be updated to 0.9.6]], Kei Kebreau, 2016/12/24
- Re: Chicken security bugs [was Re: address@hidden: Irregex packages should be updated to 0.9.6]], Kei Kebreau, 2016/12/25
- Re: Chicken security bugs [was Re: address@hidden: Irregex packages should be updated to 0.9.6]], Kei Kebreau, 2016/12/28