emacs-bug-tracker
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[debbugs-tracker] bug#27769: closed ([PATCH] gnu: pcre: Update replaceme


From: GNU bug Tracking System
Subject: [debbugs-tracker] bug#27769: closed ([PATCH] gnu: pcre: Update replacement to 8.41 [fixes CVE-2017-{7244, 7245, 7246}].)
Date: Thu, 20 Jul 2017 12:36:02 +0000

Your message dated Thu, 20 Jul 2017 08:34:23 -0400
with message-id <address@hidden>
and subject line Re: [bug#27769] [PATCH] gnu: pcre: Update replacement to 8.41 
[fixes CVE-2017-{7244, 7245, 7246}].
has caused the debbugs.gnu.org bug report #27769,
regarding [PATCH] gnu: pcre: Update replacement to 8.41 [fixes CVE-2017-{7244, 
7245, 7246}].
to be marked as done.

(If you believe you have received this mail in error, please contact
address@hidden)


-- 
27769: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=27769
GNU Bug Tracking System
Contact address@hidden with problems
--- Begin Message --- Subject: [PATCH] gnu: pcre: Update replacement to 8.41 [fixes CVE-2017-{7244, 7245, 7246}]. Date: Wed, 19 Jul 2017 22:22:28 -0400
* gnu/packages/pcre.scm (pcre)[replacement]: Update to pcre-8.41.
(pcre/fixed): Replace with ...
(pcre-8.41): ... new variable.
---
 gnu/packages/pcre.scm | 16 ++++++++++++----
 1 file changed, 12 insertions(+), 4 deletions(-)

diff --git a/gnu/packages/pcre.scm b/gnu/packages/pcre.scm
index 67a8db1c7..8dd509931 100644
--- a/gnu/packages/pcre.scm
+++ b/gnu/packages/pcre.scm
@@ -34,7 +34,7 @@
   (package
    (name "pcre")
    (version "8.40")
-   (replacement pcre/fixed)
+   (replacement pcre-8.41)
    (source (origin
             (method url-fetch)
             (uri (list
@@ -72,12 +72,20 @@ POSIX regular expression API.")
    (license license:bsd-3)
    (home-page "http://www.pcre.org/";)))
 
-(define pcre/fixed
+(define pcre-8.41
   (package
     (inherit pcre)
+    (version "8.41")
     (source (origin
-              (inherit (package-source pcre))
-              (patches (search-patches "pcre-CVE-2017-7186.patch"))))))
+              (method url-fetch)
+              (uri (list (string-append "mirror://sourceforge/pcre/pcre/"
+                                        version "/pcre-" version ".tar.bz2")
+                         (string-append "ftp://ftp.csx.cam.ac.uk";
+                                        "/pub/software/programming/pcre/"
+                                        "pcre-" version ".tar.bz2")))
+              (sha256
+               (base32
+                "0c5m469p5pd7jip621ipq6hbgh7128lzh7xndllfgh77ban7wb76"))))))
 
 (define-public pcre2
   (package
-- 
2.13.3




--- End Message ---
--- Begin Message --- Subject: Re: [bug#27769] [PATCH] gnu: pcre: Update replacement to 8.41 [fixes CVE-2017-{7244, 7245, 7246}]. Date: Thu, 20 Jul 2017 08:34:23 -0400 User-agent: Mutt/1.8.3 (2017-05-23)
On Thu, Jul 20, 2017 at 10:35:28AM +0200, Ludovic Courtès wrote:
> > -              (patches (search-patches "pcre-CVE-2017-7186.patch"))))))
> 
> Should we remove this patch as well?

Yes! I was rushing to finish this at the end of the night and I sent a
preliminary version of this change by mistake :/

> For ‘core-updates’, I suggest we keep 8.41 it as a graft.  WDYT?

Agreed, I think we should not make any more big changes on that branch
unless we have to.

Pushed as 426b0b898f70a58133d80779980f163a5761686e.

Attachment: signature.asc
Description: PGP signature


--- End Message ---

reply via email to

[Prev in Thread] Current Thread [Next in Thread]