bug-guix
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

bug#32026: [PATCH 10/10] gnu: icecat: Unbundle nss and nspr.


From: Mark H Weaver
Subject: bug#32026: [PATCH 10/10] gnu: icecat: Unbundle nss and nspr.
Date: Thu, 16 Feb 2023 17:14:33 -0500

Hi Maxim,

Maxim Cournoyer <maxim.cournoyer@gmail.com> writes:

> * gnu/packages/gnuzilla.scm (icecat-minimal) [inputs]: Add nspr-next and
> nss-next.
> [configure-flags]: Re-instate the "--with-system-nspr" and "--with-system-nss"
> configure flags.
> [phases] {remove-bundled-libraries}: Update comment.

This is really great, thank you!

There's just one transient issue that makes me want to hold off on this:
As I recently reported to guix-security, a Mozilla security advisory
<https://www.mozilla.org/en-US/security/advisories/mfsa2023-06/>
published on Tuesday mentions "CVE-2023-0767: Arbitrary memory write via
PKCS 12 in NSS".  I'd like someone to confirm that this issue has been
fixed in 'nss-next' before applying this commit.  I don't have time to
check it myself right now.

       Thanks,
         Mark





reply via email to

[Prev in Thread] Current Thread [Next in Thread]