This is the mail archive of the
cygwin-apps
mailing list for the Cygwin project.
[SECURITY] nettle
- From: Yaakov Selkowitz <yselkowitz at cygwin dot com>
- To: cygwin-apps at cygwin dot com
- Date: Wed, 2 Mar 2016 20:28:57 -0600
- Subject: [SECURITY] nettle
- Authentication-results: sourceware.org; auth=none
Dr. Volker,
Three CVEs have been announced for nettle. The upstream 3.2 release
includes the fixes, but that involves an ABI version bump -- and hence
an immediate rebuild of the six packages which depend on nettle. In the
meantime, could you also provide a 2.7.1 with the following patch:
http://pkgs.fedoraproject.org/cgit/rpms/nettle.git/plain/nettle-2.7.1-ecc-cve.patch?h=f22
TIA,
--
Yaakov