Re: Expat 2.2.7 with security fixes has been released / CVE-2018-20843

2019-07-13 Thread Sebastian Pipping
Hi Jack and Marius, glad to hear that GUIX saying "no" to 2.2.7 in general was a misunderstanding on my side. Thanks for the clarification! Best Sebastian

Re: Expat 2.2.7 with security fixes has been released / CVE-2018-20843

2019-07-12 Thread Marius Bakke
Sebastian, Thank you very much for reaching out downstream! Sebastian Pipping writes: > Hi Jack, > > > On 12.07.19 01:17, Jack Hill wrote: >> I'm pleased to let you know that we've applied the fix for >> CVE-2018-20843 in GNU Guix as of >> 5a836ce38c9c29e9c2bd306007347486b90c5064 [0]. We electe

Re: Expat 2.2.7 with security fixes has been released / CVE-2018-20843

2019-07-12 Thread Jack Hill
Hi Sebastian, On Fri, 12 Jul 2019, Sebastian Pipping wrote: On 12.07.19 01:17, Jack Hill wrote: We elected to backport the patch that fixed the problem instead of upgrading due to a change in the expat abi with 2.2.7 [1]. [1] https://issues.guix.gnu.org/issue/36424#2 thanks for the update

Re: Expat 2.2.7 with security fixes has been released / CVE-2018-20843

2019-07-12 Thread Sebastian Pipping
Hi Jack, On 12.07.19 01:17, Jack Hill wrote: > I'm pleased to let you know that we've applied the fix for > CVE-2018-20843 in GNU Guix as of > 5a836ce38c9c29e9c2bd306007347486b90c5064 [0]. We elected to backport the > patch that fixed the problem instead of upgrading due to a change in the > expa

Re: Expat 2.2.7 with security fixes has been released / CVE-2018-20843

2019-07-11 Thread Jack Hill
On Fri, 28 Jun 2019, Sebastian Pipping wrote: Hello everyone! Sorry for the noise if you heard about the release of 2.2.7 about a week ago through some other channel and maybe even took action, already! To be quick, there is one DoS fix — for CVE-2018-20843 [1] — and misc build system fixes.

Expat 2.2.7 with security fixes has been released / CVE-2018-20843

2019-06-27 Thread Sebastian Pipping
Hello everyone! Sorry for the noise if you heard about the release of 2.2.7 about a week ago through some other channel and maybe even took action, already! To be quick, there is one DoS fix — for CVE-2018-20843 [1] — and misc build system fixes. The change log with details is up at [2]. If yo