GNU bug report logs - #27429
Stack clash (CVE-2017-1000366 etc)

Previous Next

Package: guix;

Reported by: Leo Famulari <leo <at> famulari.name>

Date: Mon, 19 Jun 2017 22:27:01 UTC

Severity: serious

Done: Leo Famulari <leo <at> famulari.name>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: ludo <at> gnu.org (Ludovic Courtès)
To: Mark H Weaver <mhw <at> netris.org>
Cc: 27429 <at> debbugs.gnu.org, Efraim Flashner <efraim <at> flashner.co.il>, Leo Famulari <leo <at> famulari.name>
Subject: bug#27429: Stack clash (CVE-2017-1000366 etc)
Date: Tue, 27 Jun 2017 15:57:33 +0200
Mark H Weaver <mhw <at> netris.org> skribis:

> Yes, I ran "guix pull" for user mhw on Hydra, and then asked it to build
> a grafted 'hello' for all three hydra-supported platforms.  This
> entailed building a grafted 'glibc-final' as well as 'perl' and 'expat'.
> I then ran:
>
>   guix challenge --substitute-urls=https://hydra.gnu.org /gnu/store/...
>
> to generate narinfo requests for the relevant outputs, on the theory
> that this would cause guix-publish to build NARs.  (Am I right?)

You are, that’s a good strategy.  :-)

Thanks,
Ludo’.




This bug report was last modified 7 years and 309 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.