New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Erlang CVE-2017-1000385 erlangR{18,19,20} #32443
Conversation
Sgtm to drop R16 and R17. R16-basho is most likely a dependency of Riak, so
should stay if that’s the case
…On Fri, 8 Dec 2017 at 10:46, Andreas Rammhold ***@***.***> wrote:
Motivation for this change
Closing CVE-2017-1000385 in erlangR{18,19,20}.
We are also carrying versions of R16, R16-basho & R17 around that are no
longer receiving any kinds of updates as far as I can tell.
It should be considered to remove those or at least mark them as
unsupported (meta.broken = true, …).
CC maintainers: @the-kenny <https://github.com/the-kenny> @sjmackenzie
<https://github.com/sjmackenzie> @couchemar <https://github.com/couchemar>
@gleber <https://github.com/gleber>
Things done
- Tested using sandboxing (nix.useSandbox
<http://nixos.org/nixos/manual/options.html#opt-nix.useSandbox> on
NixOS, or option build-use-sandbox in nix.conf
<http://nixos.org/nix/manual/#sec-conf-file> on non-NixOS)
- Built on platform(s)
- NixOS
- macOS
- other Linux distributions
- Tested via one or more NixOS test(s) if existing and applicable for
the change (look inside nixos/tests
<https://github.com/NixOS/nixpkgs/blob/master/nixos/tests>)
- Tested compilation of all pkgs that depend on this change using nix-shell
-p nox --run "nox-review wip"
- Tested execution of all binary files (usually in ./result/bin/)
- Fits CONTRIBUTING.md
<https://github.com/NixOS/nixpkgs/blob/master/.github/CONTRIBUTING.md>.
------------------------------
------------------------------
You can view, comment on, or merge this pull request online at:
#32443
Commit Summary
- erlangR20: 20.1 -> 20.1.7 (fixes CVE-2017-1000385)
- erlangR19: 19.3 -> 19.3.6.4 (fixes CVE-2017-1000385)
- erlangR18: 18.3.4.4 -> 18.3.4.7 (fixes CVE-2017-1000385)
File Changes
- *M* pkgs/development/interpreters/erlang/R18.nix
<https://github.com/NixOS/nixpkgs/pull/32443/files#diff-0> (4)
- *M* pkgs/development/interpreters/erlang/R19.nix
<https://github.com/NixOS/nixpkgs/pull/32443/files#diff-1> (4)
- *M* pkgs/development/interpreters/erlang/R20.nix
<https://github.com/NixOS/nixpkgs/pull/32443/files#diff-2> (4)
Patch Links:
- https://github.com/NixOS/nixpkgs/pull/32443.patch
- https://github.com/NixOS/nixpkgs/pull/32443.diff
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
<#32443>, or mute the thread
<https://github.com/notifications/unsubscribe-auth/AACBoV4-TfoXJNpBvwhdeVbeyfoOrVdOks5s-QWJgaJpZM4Q62Cd>
.
|
Packages can be marked as insecure. Are R16 and R17 still used by other stuff? |
erlangR16 doesn't receive any upstream updates anymore and none of our packages depend on it.
There wasn't any package depending on erlangR17 or R16 so I added two commits removing those versions. |
@GrahamcOfBorg eval |
oh, that one is obvious... |
So apparently I could probably just bump that as well... It seems to move out of scope for this PR tho.. |
Can you drop the R17 commit, then we should be able to merge it. |
4566a07
to
2b72043
Compare
done |
Backported to 17.09 in 414c57b etc. |
(cherry picked from commit b8b4d7e)
Motivation for this change
Closing CVE-2017-1000385 in erlangR{18,19,20}.
We are also carrying versions of R16, R16-basho & R17 around that are no longer receiving any kinds of updates as far as I can tell.
It should be considered to remove those or at least mark them as unsupported (
meta.broken = true
, …).CC maintainers: @the-kenny @sjmackenzie @couchemar @gleber
Things done
build-use-sandbox
innix.conf
on non-NixOS)nix-shell -p nox --run "nox-review wip"
./result/bin/
)