mbox

[bug#46183,0/1] Update gcrypt [URGENT SECURITY ISSUE]

Message ID 20210130042045.16727-1-rprior@protonmail.com
Headers show

Message

kasper.andersson--- via Guix-patches" via Jan. 30, 2021, 4:20 a.m. UTC
Hi Guix! Please review ASAP. This update fixes an exploitable heap overflow.

 ## Info

https://dev.gnupg.org/T5275

https://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000455.html

Ryan Prior (1):
  gnu: libgcrypt: Update to 1.9.1.

 gnu/packages/gnupg.scm | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

Comments

lordyuuma@gmail.com Jan. 30, 2021, 7:56 a.m. UTC | #1
Hi Ryan,

Am Samstag, den 30.01.2021, 04:20 +0000 schrieb Ryan Prior:
> Hi Guix! Please review ASAP. This update fixes an exploitable heap
> overflow.
> 
> https://dev.gnupg.org/T5275
> 
> https://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000455.html

I have some good news and some bad news.  The good news is, that
according to your sources this affects only version 1.9.0, so master is
currently safe.  The bad news is, that libgcrypt has more than 10000
dependants, so an update for it should go to core-updates.

Regards,
Leo