[Pkg-erlang-devel] Wheezy update of erlang?

Raphael Hertzog hertzog at debian.org
Tue Dec 12 14:21:30 UTC 2017


Hello Sergei,

On Sun, 10 Dec 2017, Sergei Golovan wrote:
> On Sun, Dec 10, 2017 at 9:52 PM, Thorsten Alteholz <debian at alteholz.de> wrote:
> > Hi Sergei,
> >
> > The Debian LTS team would like to fix the security issues which are
> > currently open in the Wheezy version of erlang:
> > https://security-tracker.debian.org/tracker/source-package/erlang
> >
> > Would you like to take care of this yourself?
> 
> I would love to, but there's a problem. The existing fixes can't be applied to
> the version in wheezy because it's fairly old, and the ssl application codebase
> has been changed considerably. So, basically, I'd have to recreate the
> fix myself. And I'm not sure I have time for this till next week.
> 
> Though I can test an existing patch if any.

I tried to backport the patch from version 18 for the version that we have
in wheezy. The resulting patch is attached. I'm not quite sure that the
patch is correct.

Can you review it and test it?

The package builds fine with this patch (my debdiff is also attached)
but I did not do any other test.

The binary packages for amd64 are here:
$ dget https://people.debian.org/~hertzog/packages/erlang_15.b.1-dfsg-4+deb7u2_amd64.changes

Cheers,
-- 
Raphaël Hertzog ◈ Debian Developer

Support Debian LTS: https://www.freexian.com/services/debian-lts.html
Learn to master Debian: https://debian-handbook.info/get/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: CVE-2017-1000385.patch
Type: text/x-diff
Size: 2595 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-erlang-devel/attachments/20171212/9346cd5b/attachment.patch>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: debdiff.patch
Type: text/x-diff
Size: 3671 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-erlang-devel/attachments/20171212/9346cd5b/attachment-0001.patch>


More information about the Pkg-erlang-devel mailing list