From nobody Mon Aug 21 19:07:03 2023 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4RV25z6rLsz4rC7Z; Mon, 21 Aug 2023 19:07:03 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4RV25z5skMz4Qq3; Mon, 21 Aug 2023 19:07:03 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1692644823; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=KyC1cTNPlkKCdR8KPuRWz0V8echzztQMUAlD9Ko3C5w=; b=eXW17+GTUfGbfLY8cbmGvJN4h5s50yzPadqsuSB7IZSotAG6YBbJ9tlK8c780EpLnv04O3 c1+iFcz8X6m5zhDHvRpUsZP89FTkIZUzAu83FR8DdOudbBo5zY0l99MW99ytEwV43az88G OxExiLkq8epcar+YbXIriWhx8CTAZkluFWOFpwbUOGgFsPYfjAZMP+shbv3A8lzitgNI7t 9jdzzcUu9nHbwTLKjjLNQ9eozfbcIFXG8iHP+kVo8ExWjLmhqPIbS0Y3bnUuipXh+DlSVA o8+82P2S41/do5+eVFdy61EY5X7k+XM9uopOZFop9qupwu+msyW/rxkSiwTwRA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1692644823; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=KyC1cTNPlkKCdR8KPuRWz0V8echzztQMUAlD9Ko3C5w=; b=G5CH/a6MOos4DMRZLT2UXfmecFX/h5ToagHIQBP/RqGP3Yy0ZmkreVJwa1jocpDdFDTCnk PCQuYGC4YRbUk0dGRJcg7snAUnrDE+K5ETUEQj+AOeGW/ut+h49TYE30eDtYjfn3DJXSP5 6FoXbAAoG+xi23UGftVOD6aPsUVFEtc5VKGiowIz2fOMrNiXMhd0eFidYX0VGBolLwchqi sL+tZAqVACz9pLGTEiKbtjDlh7GaApHaVUxSfD+MRW0jNsAziJz9kM1J2UkPePROC0z8sN vgbMuJfhpPzZd1Nv5mJR95DvLTHBUvne2R14nevv/Of2/SHx+Tm3ujaV8ayKCg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1692644823; a=rsa-sha256; cv=none; b=gDQE1nqfZVoq7VHWFj8Vp2jzm+s9EGXYK6OeEiYT9i1O5Sk2tF/ViidwKcG/xNMmPS5cgz G+AjYMKgY/tKQ520h6C+oFg6lGslLr7alfTPJP962jUtWpwl7Z31puDt0TFTsfwBuMfDB0 BQM+fKVIF4eLwLvQVNl0IO+fBaSVqBuLHI5iHaNPR69bpRSEof8QHsncV1kBAibaJ9vTro 1H9cPKSveA7oLXJHgLvXc3v2rgXmw/T0DY/vMz62Eja4XeQ/sNoRU9KChEnTZ33Ey96eb2 Vgs8CJl7c73Kx41KMH4USFTrfmVL25+Kv0uZC/bEB+52rpafxVgzKBJZSNi9IQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4RV25z4xKSzXvj; Mon, 21 Aug 2023 19:07:03 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 37LJ73FX098016; Mon, 21 Aug 2023 19:07:03 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 37LJ73mI098013; Mon, 21 Aug 2023 19:07:03 GMT (envelope-from git) Date: Mon, 21 Aug 2023 19:07:03 GMT Message-Id: <202308211907.37LJ73mI098013@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Cy Schubert Subject: git: 5d50183d2c7e - main - security/pam_krb5: Revert "security/pam_krb5: IGNORE for CVE-2023-3326" List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: cy X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 5d50183d2c7e9ff0a7f7113702506933a6fce4b8 Auto-Submitted: auto-generated The branch main has been updated by cy: URL: https://cgit.FreeBSD.org/ports/commit/?id=5d50183d2c7e9ff0a7f7113702506933a6fce4b8 commit 5d50183d2c7e9ff0a7f7113702506933a6fce4b8 Author: Cy Schubert AuthorDate: 2023-08-21 18:59:59 +0000 Commit: Cy Schubert CommitDate: 2023-08-21 19:06:59 +0000 security/pam_krb5: Revert "security/pam_krb5: IGNORE for CVE-2023-3326" Discussing with our upstream, he is aware of CVE-2023-3326. Work to add generalized anti-spoofing is planned. In the mean time he recommends using FAST (anon_fast) to mitigate CVE-2023-3326. anon_fast already includes built-in anti-spoofing. More discussion is here: https://github.com/rra/pam-krb5/blob/main/docs/pam_krb5.pod#L53 This reverts commit 41afd03d9c8e76fe42c555b1274fec069f83ecae. --- security/pam_krb5/Makefile | 2 -- 1 file changed, 2 deletions(-) diff --git a/security/pam_krb5/Makefile b/security/pam_krb5/Makefile index 6a898f6aa535..afe524587a76 100644 --- a/security/pam_krb5/Makefile +++ b/security/pam_krb5/Makefile @@ -14,8 +14,6 @@ LICENSE= BSD3CLAUSE GPLv1+ LICENSE_COMB= dual LICENSE_FILE= ${WRKSRC}/LICENSE -IGNORE= CVE-2023-3326, https://github.com/rra/pam-krb5/issues/27 - USES= gmake libtool perl5 USE_PERL5= build