GNU bug report logs - #27263
Perl CVE-2017-6512

Previous Next

Package: guix-patches;

Reported by: Leo Famulari <leo <at> famulari.name>

Date: Tue, 6 Jun 2017 03:03:01 UTC

Severity: normal

Done: Leo Famulari <leo <at> famulari.name>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: help-debbugs <at> gnu.org (GNU bug Tracking System)
To: Leo Famulari <leo <at> famulari.name>
Cc: tracker <at> debbugs.gnu.org
Subject: bug#27263: closed (Perl CVE-2017-6512)
Date: Wed, 07 Jun 2017 16:18:01 +0000
[Message part 1 (text/plain, inline)]
Your message dated Wed, 7 Jun 2017 12:17:53 -0400
with message-id <20170607161752.GA5750 <at> jasmine>
and subject line Re: bug#27263: [PATCH 2/2] gnu: perl: Fix CVE-2017-6512 in File::Path.
has caused the debbugs.gnu.org bug report #27263,
regarding Perl CVE-2017-6512
to be marked as done.

(If you believe you have received this mail in error, please contact
help-debbugs <at> gnu.org.)


-- 
27263: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=27263
GNU Bug Tracking System
Contact help-debbugs <at> gnu.org with problems
[Message part 2 (message/rfc822, inline)]
From: Leo Famulari <leo <at> famulari.name>
To: guix-patches <at> gnu.org
Subject: Perl CVE-2017-6512
Date: Mon, 5 Jun 2017 23:01:08 -0400
[Message part 3 (text/plain, inline)]
These patches fix CVE-2017-6512 in perl-file-path and the copy of
File::Path in perl itself.
[signature.asc (application/pgp-signature, inline)]
[Message part 5 (message/rfc822, inline)]
From: Leo Famulari <leo <at> famulari.name>
To: Ludovic Courtès <ludo <at> gnu.org>
Cc: 27263-done <at> debbugs.gnu.org
Subject: Re: bug#27263: [PATCH 2/2] gnu: perl: Fix CVE-2017-6512 in File::Path.
Date: Wed, 7 Jun 2017 12:17:53 -0400
[Message part 6 (text/plain, inline)]
On Wed, Jun 07, 2017 at 01:18:09AM +0200, Ludovic Courtès wrote:
> Leo Famulari <leo <at> famulari.name> skribis:
> 
> > * gnu/packages/perl.scm (perl)[replacement]: New field.
> > (perl/fixed): New variable.
> > * gnu/packages/patches/perl-file-path-CVE-2017-6512.patch: New file.
> > * gnu/local.mk (dist_patch_DATA): Add it.
> 
> OK too.
> 
> I suppose we’ll have to apply it in core-updates too, right?

And, done as c67d587f94173fd42d65097165afc5c512935646.

I tested that this packaging of Perl 5.26.0 builds on master, then I
"ported" the package to core-updates. I don't have the resources to
build the Perl package on core-updates in a timely manner.
[signature.asc (application/pgp-signature, inline)]

This bug report was last modified 8 years and 69 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.