<feed xmlns='http://www.w3.org/2005/Atom'>
<title>guix.git/gnu/packages/patches/optipng-CVE-2017-1000229.patch, branch master</title>
<subtitle>Personal branch of https://git.savannah.gnu.org/cgit/guix.git/ for implementing 'guix deploy'.
</subtitle>
<id>https://git.jakob.space/guix.git/atom?h=master</id>
<link rel='self' href='https://git.jakob.space/guix.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/'/>
<updated>2018-02-23T15:00:04Z</updated>
<entry>
<title>gnu: optipng: Update to 0.7.7 [security fixes].</title>
<updated>2018-02-23T15:00:04Z</updated>
<author>
<name>Tobias Geerinckx-Rice</name>
</author>
<published>2018-02-23T13:24:42Z</published>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/commit/?id=bbf8832f160120d4f78b563653db49ab715e7c6c'/>
<id>urn:sha1:bbf8832f160120d4f78b563653db49ab715e7c6c</id>
<content type='text'>
This release claims to fix 2 vulnerabilities:
- ‘an integer overflow vulnerability in the TIFF decoder’
  (CVE-2017-1000229, previously patched in Guix), and
- ‘a buffer overflow vulnerability in the GIF decoder’.

* gnu/packages/image.scm (optipng): Update to 0.7.7.
[source]: Remove patch.
[arguments]: Substitute INVOKE for SYSTEM* and end phase with #t.
* gnu/packages/patches/optipng-CVE-2017-1000229.patch: Delete file.
* gnu/local.mk (dist_patch_DATA): Remove it.
</content>
</entry>
<entry>
<title>gnu: optipng: Fix CVE-2017-1000229.</title>
<updated>2017-11-29T11:53:08Z</updated>
<author>
<name>Marius Bakke</name>
</author>
<published>2017-11-28T16:41:33Z</published>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/commit/?id=0e7fb0cd9b91e873b5f9d04c49472b06aff6911f'/>
<id>urn:sha1:0e7fb0cd9b91e873b5f9d04c49472b06aff6911f</id>
<content type='text'>
* gnu/packages/image.scm (optipng)[source](patches): New field.
* gnu/packages/patches/optipng-CVE-2017-1000229.patch: New file.
* gnu/local.mk (dist_patch_DATA): Register it.
</content>
</entry>
</feed>
