From owner-svn-src-all@freebsd.org Wed Aug 24 12:38:16 2016 Return-Path: Delivered-To: svn-src-all@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 395B8BC3ECE for ; Wed, 24 Aug 2016 12:38:16 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: from mail-qk0-x231.google.com (mail-qk0-x231.google.com [IPv6:2607:f8b0:400d:c09::231]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id E1C431BDC for ; Wed, 24 Aug 2016 12:38:15 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: by mail-qk0-x231.google.com with SMTP id l2so12968828qkf.3 for ; Wed, 24 Aug 2016 05:38:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardenedbsd-org.20150623.gappssmtp.com; s=20150623; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=6yMGNFFzOoVcWLAItFcF09wQFDoCPhdFdxm6UdZDa/o=; b=UBkPg46mlqVCfkRmPe0lXOGcG8I1PqoCNUB467xpVtAEkeAB5MauNwJJlPmvCUOVlH 3PvA2ebd3jjG8dF0eohCoMbEkFkHr1+J1c7UHOSL4McO9YHPhGY4hxIlfTY/fIyJhtsS l+1wq8SU4P54kCNyVO7KhFVa5uGftS2oeMTsqcZm18Qo1/yP6i6CYEGrbzds1FZxyn6H j+NeNjUZ52Ii4pCszZ+Ku9aLuqyeuTV4+yocuV2OBH77se3l8xVmogED+F2a46kmmDCO NyFZZ+v8+mubKNSjpeptysbTFKEWCF1HT+KqiCbPRrDWH4XnInHYxLQSVyoQrNW7BRyw S1pQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=6yMGNFFzOoVcWLAItFcF09wQFDoCPhdFdxm6UdZDa/o=; b=B/dVyNykQofE+r5TgiJJnFPHAJz4rAhEX8CEY17seL7nGh3k0bxqrPTYuL3mg18aRH mVLCctaxsvU5HJ0s0hKGCrX+fn0hL8qwdmC4Tt4GDOCYnoVGscY59W9hu8ErsYTpWJes nvIukZkvTACLd4WIodngieiX/W2l94gb/Q4Yd5yZ/+mRschChbCupTviX5peB5PlQv7M JIpXW0TVhR90if7dox16wmW1XpJTPodwHrkym7wx8ADZb00xrxLPrmgftLgfMh11rONF RvnwW+BDD9UVFSZb9owxayGVtB5uSNYnT6cZT4axCPiqaQF5TH7C2mA3bB6gyqQ5La8C uu0g== X-Gm-Message-State: AE9vXwOg4N3bIT0XTc93yRS+sQ6yVQmCgQAooJ6cTK8d7jcZoJDmRNWqQa5vE9pevn/Z0xFx X-Received: by 10.233.232.195 with SMTP id a186mr3053777qkg.109.1472042294919; Wed, 24 Aug 2016 05:38:14 -0700 (PDT) Received: from mutt-hardenedbsd ([63.88.83.66]) by smtp.gmail.com with ESMTPSA id 55sm4541422qtp.32.2016.08.24.05.38.13 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Wed, 24 Aug 2016 05:38:13 -0700 (PDT) Date: Wed, 24 Aug 2016 08:38:11 -0400 From: Shawn Webb To: Cy Schubert Cc: Cy Schubert , svn-src-head@freebsd.org, svn-src-all@freebsd.org, src-committers@freebsd.org Subject: Re: svn commit: r304747 - in head/contrib/sqlite3: . tea Message-ID: <20160824123811.GB74786@mutt-hardenedbsd> References: <201608241232.u7OCWPsn020853@repo.freebsd.org> <201608241235.u7OCZswp004129@slippy.cwsent.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="qcHopEYAB45HaUaB" Content-Disposition: inline In-Reply-To: <201608241235.u7OCZswp004129@slippy.cwsent.com> X-Operating-System: FreeBSD mutt-hardenedbsd 12.0-CURRENT-HBSD FreeBSD 12.0-CURRENT-HBSD X-PGP-Key: http://pgp.mit.edu/pks/lookup?op=vindex&search=0x6A84658F52456EEE User-Agent: Mutt/1.6.1 (2016-04-27) X-BeenThere: svn-src-all@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "SVN commit messages for the entire src tree \(except for " user" and " projects" \)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 24 Aug 2016 12:38:16 -0000 --qcHopEYAB45HaUaB Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Aug 24, 2016 at 05:35:54AM -0700, Cy Schubert wrote: > In message <201608241232.u7OCWPsn020853@repo.freebsd.org>, Cy Schubert=20 > writes: > > Author: cy > > Date: Wed Aug 24 12:32:24 2016 > > New Revision: 304747 > > URL: https://svnweb.freebsd.org/changeset/base/304747 > >=20 > > Log: > > MFV r304732. > > =20 > > Update from sqlite3-3.12.1 (3120100) to sqlite3-3.14.1 (3140100). > > =20 > > This commit addresses the tmpdir selection vulnerability fixed in > > sqlite3-1.13.0. See VuXML entry 546deeea-3fc6-11e6-a671-60a44ce6887b. > > =20 > > Security: VuXML 546deeea-3fc6-11e6-a671-60a44ce6887b > > Security: CVE-2016-6153 >=20 > This should probably be MFCed in a week unless re@ wants it sooner of=20 > course. Does this also need a FreeBSD errata notice or security announcement? Thanks, --=20 Shawn Webb Cofounder and Security Engineer HardenedBSD GPG Key ID: 0x6A84658F52456EEE GPG Key Fingerprint: 2ABA B6BD EF6A F486 BE89 3D9E 6A84 658F 5245 6EEE --qcHopEYAB45HaUaB Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJXvZUxAAoJEGqEZY9SRW7uze8QAMceVH+G5kwAqAaR3zUZZd0R CJ/hhyFMVuNl6LOOrQYkwwDvOzVtjXzu7DkErXMbsp0/57sjxYcE6Cztu5PzGTTe MAer3s9Wbwy5Lq43w8TtpLNZDEkK3JOqJdvZw0HHgHUsc5ZOoAJY9M/6utKp8mcb HiAAysGaqj80H4JUxdvNaE3eFyu+OGPVgEqg9jlSWBMnfffwAVAiFl+g8ysejAE6 shW4Kef4mZnVwSZib4OeikbxTOLYzyO/c8So7B0I75rQHXu8+0zX/y+AsOcbogOi cMLM3D7tldyu7PwHnZj0Sf9PJohHJDU5arMqtykcPevgY/c/7DCCgDRHah7JU82Y oUByrQ+VQMjK7lpMs2/uqb/kOiYNN14VdAo5vqQ1Bbud+RfDd7V29e8cdrTJxcj0 KJFM744Cu/gFukwd9yvdYZEe0TdVX5CFD+3wiCnD8BoRYJcKYhSKXh4lSvGswUP4 gE9YkZ645aKgk0Jnghibzzj9l9ridUgn2pvVxaheT3luX1JUKWp1GIpoODCShZVG WGm+zyA31Q5aqUh/RYWFIOfw9UGfQqO1VBAi1kUu5bLqPuOOdIX1Sh0E5R1zAbep 0Jfd/EF45o7J1zEe/KE3hmCiP4v6WRXm2ZvTRIGSfscClr55CfLjNvlPBMwmTKeD Uo4OsSeF1Y+T97inOvBY =5jam -----END PGP SIGNATURE----- --qcHopEYAB45HaUaB--