Bug#854923: busybox: "sed -i" bug corrected in version 1.23.0

2017-02-18 Thread Cyril Brulebois
Hi, Cyril Chaboisseau (2017-02-18): > Fine, but busybox will eventually be upgraded to a newer stable version > at some point, or it will suffer from old/buggy version with potential > security holes > if not, it means that on the long run it will be very difficult to > cherry-pick those security

Bug#854923: busybox: "sed -i" bug corrected in version 1.23.0

2017-02-18 Thread Cyril Chaboisseau
Hi Cyril, Fine, but busybox will eventually be upgraded to a newer stable version at some point, or it will suffer from old/buggy version with potential security holes if not, it means that on the long run it will be very difficult to cherry-pick those security patches and the project wil not bene

Bug#854923: busybox: "sed -i" bug corrected in version 1.23.0

2017-02-18 Thread Cyril Brulebois
Hi Cyril, Cyril Chaboisseau (2017-02-16): > this bug https://bugs.busybox.net/show_bug.cgi?id=7484 is corrected in > version 1.23.0 Thanks for the link. Given the patch, we need to be careful about the sed -i call anyway (https://bugs.debian.org/854924), since we would be setting exitcode to EXI

Bug#854923: busybox: "sed -i" bug corrected in version 1.23.0

2017-02-16 Thread Cyril Chaboisseau
Package: busybox Version: 1:1.22.0-19+b1 Followup-For: Bug #854923 this bug https://bugs.busybox.net/show_bug.cgi?id=7484 is corrected in version 1.23.0 busybox should be upgrade to a newer stable version 1.23.2 (or newer : 1.26.2) -- System Information: Debian Release: 9.0 APT prefers unstab