From owner-svn-src-all@freebsd.org Thu Sep 29 08:34:02 2016 Return-Path: Delivered-To: svn-src-all@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 28F22C02A25 for ; Thu, 29 Sep 2016 08:34:02 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: from mail-yw0-x230.google.com (mail-yw0-x230.google.com [IPv6:2607:f8b0:4002:c05::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id D60A2B0 for ; Thu, 29 Sep 2016 08:34:01 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: by mail-yw0-x230.google.com with SMTP id g192so44406607ywh.1 for ; Thu, 29 Sep 2016 01:34:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardenedbsd-org.20150623.gappssmtp.com; s=20150623; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=yhLNLCDmifND9hvXBvF+gvVRtxwB3ju7G89O3Wt63do=; b=dvQCWdVKkbACxgtFciEm9SNUwzQJ+wmjrGEWnlJwgGIh0pCBP3iJ7clmqoYEYmGaHm CdYMbDp+H5tTE/QFMI56G4MctjGvTN+T9aOa+2dm9nSEnkUIyWs7R3HyqZw9DG+/dqSF JDVdzOBCez3ZfWkzttMyvauK5iAyapQqMGhNMf1AUI9QQotT3mYGxSMdvdQS1TKL518L 1Av8YlqgDFy2wU6oIWta9/HnFzSxXqR5xl3eOSrWaugpgsTOYqoI/jl7S93LAS5EfNoJ YdAViHLKjQnMd/f+Sqt1HlUcK8wywHHBcnlh5jrXB0+TDlaSChNCz89xwBC5jBc+e1iI R/iw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=yhLNLCDmifND9hvXBvF+gvVRtxwB3ju7G89O3Wt63do=; b=RWgx9PLrhrghDSS0uedwqyzVgRZj0Nv2HArWdpc18VdQrmF/ydfDi+CNv7x3rSsZS5 n1RyNmI3Ov4AQF9N8MOoGmaSQfspYcvd+h/s/Gnrk/viqRku7zt7aWWNfPFmtV5GRSCH A2ODhzFDqx3klorcDPFuU+0s3f3ZYeb6BXe1SwWxv4f9vNIDhnZY7LRCcq0L7H8yBD4T 0/IrADPwa3PEnqAowYzuEfs94TmaaGYiKMbrHfb1LTYZmMwsYiycgNbXNkJhEjFfUi+z B6e8p2PsZbPrRIWKjZuHcMN7FaKl8qyOlxew7mEfxxJKyh+tNwBdsuABEaF/UwF6v6eB et5Q== X-Gm-Message-State: AA6/9RmL3W3SPGW8zpf9yTkexS+RJyHq+VQ83bSgy0azwz0WgBzNqOumAhCCXXOgyJFgq7Xw X-Received: by 10.13.229.69 with SMTP id o66mr120341ywe.286.1475138041131; Thu, 29 Sep 2016 01:34:01 -0700 (PDT) Received: from mutt-hardenedbsd (pool-100-16-217-83.bltmmd.fios.verizon.net. [100.16.217.83]) by smtp.gmail.com with ESMTPSA id g123sm4845060ywd.30.2016.09.29.01.33.59 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Thu, 29 Sep 2016 01:34:00 -0700 (PDT) Date: Thu, 29 Sep 2016 04:33:57 -0400 From: Shawn Webb To: Ed Maste Cc: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-head@freebsd.org Subject: Re: svn commit: r305486 - head/usr.bin/bsdiff/bspatch Message-ID: <20160929083357.GC45358@mutt-hardenedbsd> References: <201609061900.u86J0bd4076628@repo.freebsd.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="KN5l+BnMqAQyZLvT" Content-Disposition: inline In-Reply-To: <201609061900.u86J0bd4076628@repo.freebsd.org> X-Operating-System: FreeBSD mutt-hardenedbsd 12.0-CURRENT-HBSD FreeBSD 12.0-CURRENT-HBSD X-PGP-Key: http://pgp.mit.edu/pks/lookup?op=vindex&search=0x6A84658F52456EEE User-Agent: Mutt/1.6.1 (2016-04-27) X-BeenThere: svn-src-all@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "SVN commit messages for the entire src tree \(except for " user" and " projects" \)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 29 Sep 2016 08:34:02 -0000 --KN5l+BnMqAQyZLvT Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Sep 06, 2016 at 07:00:37PM +0000, Ed Maste wrote: > Author: emaste > Date: Tue Sep 6 19:00:37 2016 > New Revision: 305486 > URL: https://svnweb.freebsd.org/changeset/base/305486 >=20 > Log: > bspatch: add sanity checks on sizes to avoid integer overflow > =20 > Note that this introduces an explicit 2GB limit, but this was already > implicit in variable and function argument types. > =20 > This is based on the "non-cryptanalytic attacks against freebsd > update components" anonymous gist. Further refinement is planned. > =20 > Reviewed by: allanjude, cem, kib > Obtained from: anonymous gist > MFC after: 3 days > Sponsored by: The FreeBSD Foundation > Differential Revision: https://reviews.freebsd.org/D7619 Hey Ed, Any plans to release a security announcement? Thanks, --=20 Shawn Webb Cofounder and Security Engineer HardenedBSD GPG Key ID: 0x6A84658F52456EEE GPG Key Fingerprint: 2ABA B6BD EF6A F486 BE89 3D9E 6A84 658F 5245 6EEE --KN5l+BnMqAQyZLvT Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJX7NH1AAoJEGqEZY9SRW7urpYP/A4gXIr9fqa0TwRaJ1n2deI5 Uhu/0Q98eyx0kF8gWNgBgBFE+oCoNrLe9G2vBA++x8r7vGpAVahlLaIm9x2JZHXB DrV5c5SumYwr17nW83ce4H8NItTam6mRqC5xuA3yBF5SWTOgf/lWtfhdXW73VBT0 aVz3dwXojWn4cDMtOlDGh7zMZ0Utc3bvORFHXRZkePDsRtSRB3OaDaK+ruDJsbsP 3HOugXJ4hNb+cOReU3kpDxIzqk0Tr0k8xStruzqx2fWVqNAmJDhVwzmZcYG7mX79 CjzLjjnXRpKZuX/4uDpXQHXyhVFKLtozbMIlNbwN8Eiy1g9mW9Hb06t3AcSQPaO+ yoldG+kRhzkQnnE5GpJTjKUzVPmEyBmCJHTIURMjQpEfipkQZVPjo5Bl/Lkm9Zkl 06NRMjm0r9LuD7aG24wtFlLI1TeFtcHZrXao3Iun6WEIzgvpL6+NAzDuyCLklZHv DjfeBJp5wSiZGRsDj8hz0d95Zo9KJ/e9w1cSTMIeH3fjDCGex7ho509Y/2GxcZBs m784cUXwMuWQ03D7y1Olena4QMfT23Vyv4WEcNLu4zRcO8od/d4R7lX3WzJnR77L sRRJrUw4Kj1Kq304vMJsQ0vLXYyT7opewySBTl3L2rRSkW1gNDV0+H+IpUQ5g9pT Ekxrl//+R21y86WMtFof =lagG -----END PGP SIGNATURE----- --KN5l+BnMqAQyZLvT--