Date: Sun, 10 Oct 2010 21:17:26 +0700 (NOVST) From: Eugene Grosbein <eugen@eg.sd.rdtc.ru> To: FreeBSD-gnats-submit@FreeBSD.org Subject: ports/151364: update archivers/bzip2 to 1.0.6 to fix CVE-2010-0405 Message-ID: <201010101417.o9AEHQY8070788@eg.sd.rdtc.ru> Resent-Message-ID: <201010101440.o9AEe29d025450@freefall.freebsd.org>
next in thread | raw e-mail | index | archive | help
>Number: 151364 >Category: ports >Synopsis: update archivers/bzip2 to 1.0.6 to fix CVE-2010-0405 >Confidential: no >Severity: non-critical >Priority: low >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: update >Submitter-Id: current-users >Arrival-Date: Sun Oct 10 14:40:01 UTC 2010 >Closed-Date: >Last-Modified: >Originator: Eugene Grosbein >Release: FreeBSD 8.1-STABLE i386 >Organization: RDTC JSC >Environment: System: FreeBSD eg.sd.rdtc.ru 8.1-STABLE FreeBSD 8.1-STABLE #17: Mon Aug 23 13:55:22 NOVST 2010 root@eg.sd.rdtc.ru:/usr/local/obj/usr/local/src/sys/EG i386 >Description: The port archivers/bzip2 still installs version 1.0.5 that's vulnerable to CVE-2010-0405. Let's move to 1.0.6 containing fix. >How-To-Repeat: I still have some remote installations of FreeBSD 4.11-STABLE that run rock-stable. Some software (e.g. clamav antivirus) that link with libbz2 contain configure script that demonstrate segfaults if linked with version before 1.0.6 >Fix: diff -urN bzip2.orig/Makefile bzip2/Makefile --- bzip2.orig/Makefile 2008-03-21 05:44:53.000000000 +0600 +++ bzip2/Makefile 2010-10-10 21:03:55.000000000 +0700 @@ -7,7 +7,7 @@ # PORTNAME= bzip2 -PORTVERSION= 1.0.5 +PORTVERSION= 1.0.6 CATEGORIES= archivers MASTER_SITES= http://www.bzip.org/${PORTVERSION}/ diff -urN bzip2.orig/distinfo bzip2/distinfo --- bzip2.orig/distinfo 2008-03-21 05:44:53.000000000 +0600 +++ bzip2/distinfo 2010-10-10 21:04:44.000000000 +0700 @@ -1,3 +1,3 @@ -MD5 (bzip2-1.0.5.tar.gz) = 3c15a0c8d1d3ee1c46a1634d00617b1a -SHA256 (bzip2-1.0.5.tar.gz) = f7bf5368309d76e5daf3a89d4d1bea688dac7780742e7a0ae1af19be9316fe22 -SIZE (bzip2-1.0.5.tar.gz) = 841402 +MD5 (bzip2-1.0.6.tar.gz) = 00b516f4704d4a7cb50a1d97e6e8e15b +SHA256 (bzip2-1.0.6.tar.gz) = a2848f34fcd5d6cf47def00461fcb528a0484d8edef8208d6d2e2909dc61d9cd +SIZE (bzip2-1.0.6.tar.gz) = 782025 >Release-Note: >Audit-Trail: >Unformatted:
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201010101417.o9AEHQY8070788>