Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 8 Nov 2024 17:51:39 GMT
From:      Dirk Meyer <dinoex@FreeBSD.org>
To:        ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-branches@FreeBSD.org
Subject:   git: e86680e50289 - 2024Q4 - comms/lrzsz: patch CVE-2018-10195
Message-ID:  <202411081751.4A8HpdcM094020@gitrepo.freebsd.org>

next in thread | raw e-mail | index | archive | help
The branch 2024Q4 has been updated by dinoex:

URL: https://cgit.FreeBSD.org/ports/commit/?id=e86680e50289016b45ccadfb854b1af204b1088a

commit e86680e50289016b45ccadfb854b1af204b1088a
Author:     Dirk Meyer <dinoex@FreeBSD.org>
AuthorDate: 2024-11-08 17:45:36 +0000
Commit:     Dirk Meyer <dinoex@FreeBSD.org>
CommitDate: 2024-11-08 17:51:30 +0000

    comms/lrzsz: patch CVE-2018-10195
    
    Security: CVE-2018-10195
    MFC: 2024Q4
    (cherry picked from commit a2e118fa2128c7cb7f1bf961c62ac4f4ce809a0c)
---
 comms/lrzsz/Makefile         |  2 +-
 comms/lrzsz/files/patch-zm.c | 19 +++++++++++++++++++
 2 files changed, 20 insertions(+), 1 deletion(-)

diff --git a/comms/lrzsz/Makefile b/comms/lrzsz/Makefile
index 6a4ef5a42333..c271e30d3bbd 100644
--- a/comms/lrzsz/Makefile
+++ b/comms/lrzsz/Makefile
@@ -1,6 +1,6 @@
 PORTNAME=	lrzsz
 PORTVERSION=	0.12.20
-PORTREVISION=	6
+PORTREVISION=	7
 CATEGORIES=	comms
 MASTER_SITES=	http://ohse.de/uwe/releases/
 
diff --git a/comms/lrzsz/files/patch-zm.c b/comms/lrzsz/files/patch-zm.c
new file mode 100644
index 000000000000..fdf38e31aad2
--- /dev/null
+++ b/comms/lrzsz/files/patch-zm.c
@@ -0,0 +1,19 @@
+--- src/zm.c.orig	1998-12-29 16:48:38 UTC
++++ src/zm.c
+@@ -431,10 +431,12 @@ zsdata(const char *buf, size_t length, int frameend)
+ 	VPRINTF(3,("zsdata: %lu %s", (unsigned long) length, 
+ 		Zendnames[(frameend-ZCRCE)&3]));
+ 	crc = 0;
+-	do {
+-		zsendline(*buf); crc = updcrc((0377 & *buf), crc);
+-		buf++;
+-	} while (--length>0);
++
++	for( ; length; length--) {
++	  zsendline(*buf); crc = updcrc((0377 & *buf), crc);
++	  buf++;
++	}
++
+ 	xsendline(ZDLE); xsendline(frameend);
+ 	crc = updcrc(frameend, crc);
+ 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202411081751.4A8HpdcM094020>