From owner-freebsd-ports-bugs@FreeBSD.ORG Sun Oct 10 14:40:02 2010 Return-Path: Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 57FAE1065670 for ; Sun, 10 Oct 2010 14:40:02 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 33FDB8FC19 for ; Sun, 10 Oct 2010 14:40:02 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.4/8.14.4) with ESMTP id o9AEe22q025451 for ; Sun, 10 Oct 2010 14:40:02 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.4/8.14.4/Submit) id o9AEe29d025450; Sun, 10 Oct 2010 14:40:02 GMT (envelope-from gnats) Resent-Date: Sun, 10 Oct 2010 14:40:02 GMT Resent-Message-Id: <201010101440.o9AEe29d025450@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-ports-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Eugene Grosbein Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E041F106564A for ; Sun, 10 Oct 2010 14:32:50 +0000 (UTC) (envelope-from eugen@eg.sd.rdtc.ru) Received: from eg.sd.rdtc.ru (eg.sd.rdtc.ru [62.231.161.221]) by mx1.freebsd.org (Postfix) with ESMTP id 3077C8FC12 for ; Sun, 10 Oct 2010 14:32:49 +0000 (UTC) Received: from eg.sd.rdtc.ru (localhost [127.0.0.1]) by eg.sd.rdtc.ru (8.14.4/8.14.4) with ESMTP id o9AEHQ7r070789 for ; Sun, 10 Oct 2010 21:17:26 +0700 (NOVST) (envelope-from eugen@eg.sd.rdtc.ru) Received: (from eugen@localhost) by eg.sd.rdtc.ru (8.14.4/8.14.4/Submit) id o9AEHQY8070788; Sun, 10 Oct 2010 21:17:26 +0700 (NOVST) (envelope-from eugen) Message-Id: <201010101417.o9AEHQY8070788@eg.sd.rdtc.ru> Date: Sun, 10 Oct 2010 21:17:26 +0700 (NOVST) From: Eugene Grosbein To: FreeBSD-gnats-submit@FreeBSD.org X-Send-Pr-Version: 3.113 Cc: Subject: ports/151364: update archivers/bzip2 to 1.0.6 to fix CVE-2010-0405 X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Eugene Grosbein List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 10 Oct 2010 14:40:02 -0000 >Number: 151364 >Category: ports >Synopsis: update archivers/bzip2 to 1.0.6 to fix CVE-2010-0405 >Confidential: no >Severity: non-critical >Priority: low >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: update >Submitter-Id: current-users >Arrival-Date: Sun Oct 10 14:40:01 UTC 2010 >Closed-Date: >Last-Modified: >Originator: Eugene Grosbein >Release: FreeBSD 8.1-STABLE i386 >Organization: RDTC JSC >Environment: System: FreeBSD eg.sd.rdtc.ru 8.1-STABLE FreeBSD 8.1-STABLE #17: Mon Aug 23 13:55:22 NOVST 2010 root@eg.sd.rdtc.ru:/usr/local/obj/usr/local/src/sys/EG i386 >Description: The port archivers/bzip2 still installs version 1.0.5 that's vulnerable to CVE-2010-0405. Let's move to 1.0.6 containing fix. >How-To-Repeat: I still have some remote installations of FreeBSD 4.11-STABLE that run rock-stable. Some software (e.g. clamav antivirus) that link with libbz2 contain configure script that demonstrate segfaults if linked with version before 1.0.6 >Fix: diff -urN bzip2.orig/Makefile bzip2/Makefile --- bzip2.orig/Makefile 2008-03-21 05:44:53.000000000 +0600 +++ bzip2/Makefile 2010-10-10 21:03:55.000000000 +0700 @@ -7,7 +7,7 @@ # PORTNAME= bzip2 -PORTVERSION= 1.0.5 +PORTVERSION= 1.0.6 CATEGORIES= archivers MASTER_SITES= http://www.bzip.org/${PORTVERSION}/ diff -urN bzip2.orig/distinfo bzip2/distinfo --- bzip2.orig/distinfo 2008-03-21 05:44:53.000000000 +0600 +++ bzip2/distinfo 2010-10-10 21:04:44.000000000 +0700 @@ -1,3 +1,3 @@ -MD5 (bzip2-1.0.5.tar.gz) = 3c15a0c8d1d3ee1c46a1634d00617b1a -SHA256 (bzip2-1.0.5.tar.gz) = f7bf5368309d76e5daf3a89d4d1bea688dac7780742e7a0ae1af19be9316fe22 -SIZE (bzip2-1.0.5.tar.gz) = 841402 +MD5 (bzip2-1.0.6.tar.gz) = 00b516f4704d4a7cb50a1d97e6e8e15b +SHA256 (bzip2-1.0.6.tar.gz) = a2848f34fcd5d6cf47def00461fcb528a0484d8edef8208d6d2e2909dc61d9cd +SIZE (bzip2-1.0.6.tar.gz) = 782025 >Release-Note: >Audit-Trail: >Unformatted: