Re: Flex security update: RCE in generated code (CVE-2016-6354)

2016-08-28 Thread Efraim Flashner
On Sat, Aug 27, 2016 at 08:54:34PM -0400, Leo Famulari wrote: > On Sat, Aug 27, 2016 at 11:48:10PM +0200, Ludovic Courtès wrote: > > Hello! > > > > Leo Famulari skribis: > > > > > On Fri, Aug 26, 2016 at 06:14:26PM -0400, Leo Famulari wrote: > > >> Subject: [PATCH] gnu: flex: Fix CVE-2016-6354.

Re: Flex security update: RCE in generated code (CVE-2016-6354)

2016-08-27 Thread Leo Famulari
On Sat, Aug 27, 2016 at 11:48:10PM +0200, Ludovic Courtès wrote: > Hello! > > Leo Famulari skribis: > > > On Fri, Aug 26, 2016 at 06:14:26PM -0400, Leo Famulari wrote: > >> Subject: [PATCH] gnu: flex: Fix CVE-2016-6354. > >> > >> * gnu/packages/flex.scm (flex)[replacement]: New field. > >> (fle

Re: Flex security update: RCE in generated code (CVE-2016-6354)

2016-08-27 Thread Ludovic Courtès
Hello! Leo Famulari skribis: > On Fri, Aug 26, 2016 at 06:14:26PM -0400, Leo Famulari wrote: >> Subject: [PATCH] gnu: flex: Fix CVE-2016-6354. >> >> * gnu/packages/flex.scm (flex)[replacement]: New field. >> (flex/fixed): New variable. >> * gnu/packages/patches/flex-CVE-2016-6354.patch: New fil

Re: Flex security update: RCE in generated code (CVE-2016-6354)

2016-08-26 Thread Leo Famulari
On Fri, Aug 26, 2016 at 06:14:26PM -0400, Leo Famulari wrote: > Subject: [PATCH] gnu: flex: Fix CVE-2016-6354. > > * gnu/packages/flex.scm (flex)[replacement]: New field. > (flex/fixed): New variable. > * gnu/packages/patches/flex-CVE-2016-6354.patch: New file. > * gnu/local.mk (dist_patch_DATA):