From patchwork Thu Feb 11 14:18:37 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Korsgaard X-Patchwork-Id: 1439521 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=busybox.net (client-ip=140.211.166.133; helo=hemlock.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=F/qsIcZj; dkim-atps=neutral Received: from hemlock.osuosl.org (smtp2.osuosl.org [140.211.166.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4DbzJS0SM8z9sBy for ; Fri, 12 Feb 2021 01:18:47 +1100 (AEDT) Received: from localhost (localhost [127.0.0.1]) by hemlock.osuosl.org (Postfix) with ESMTP id E86568758D; Thu, 11 Feb 2021 14:18:45 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from hemlock.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jHuVa+bwtAAD; Thu, 11 Feb 2021 14:18:44 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by hemlock.osuosl.org (Postfix) with ESMTP id 4E124874E6; Thu, 11 Feb 2021 14:18:44 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from whitealder.osuosl.org (smtp1.osuosl.org [140.211.166.138]) by ash.osuosl.org (Postfix) with ESMTP id 1F5471BF2F3 for ; Thu, 11 Feb 2021 14:18:43 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by whitealder.osuosl.org (Postfix) with ESMTP id 1B87384906 for ; Thu, 11 Feb 2021 14:18:43 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from whitealder.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GFu4751A5uFS for ; Thu, 11 Feb 2021 14:18:41 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from mail-ed1-f46.google.com (mail-ed1-f46.google.com [209.85.208.46]) by whitealder.osuosl.org (Postfix) with ESMTPS id 870F9873B7 for ; Thu, 11 Feb 2021 14:18:41 +0000 (UTC) Received: by mail-ed1-f46.google.com with SMTP id s5so7084350edw.8 for ; Thu, 11 Feb 2021 06:18:41 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=F9G9qmda83oBXx4+Fi38srPNnDNa+1c40pSnS6vc9KM=; b=F/qsIcZj+iulgmInGSr0gBZbXzHdaIQb02j2cr129amCXiVvLSY5IDi8kdoDbbpDqz QAriUlHHoDkdgdh5wxGU9hVeyBc5GVj9V8gwsNNLYzyi96A8ejmbW3NH8IuVMRp7i2hd gvCYIJjOK64//NlBog4D49XyFwHiFEbJwIllQxvKQQbpTbcYl0t+wBHOctpO5rX0bQCO FlB8tltuR+stVAaumA7qqg1jLhY8uE2wZJrIkXUczhvUp1FVoP3tHrqvs8QVx44kAgbN w7vpgFLquTggyBERWS56hTz7SP5TEx/4zNV5sm4jR8MXQssDaqlgAncyleTK5ema6U5d XaRg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :mime-version:content-transfer-encoding; bh=F9G9qmda83oBXx4+Fi38srPNnDNa+1c40pSnS6vc9KM=; b=i7hnPCBOn2yNvu3UcfkWtLWv5ZPn4hdBbuVC7kONQ16lwwVwp7+VnD4PwmHk6zk3pz puYgYZpr7aC91m+0yEDZJhGXAs4RFBTYQDhDtb+4RrzK0AfiacXMzaWyFgAGaBMh+NlD 21ZC8dgl6AbS0n2f+RX9hkFEIlnIvQGjEYxGLwKIA1iP4uk347hjOw3rMY6CxP7xsRnP eseRty60DzazvBmsYpvNyw9qCwN7LCrGpxk0vJh+zPgbAgo5Sy1KQcYanJc83buYK82P fAu9mnfD/nd4gZYtDSPzL6HAOWVRAfDOClZLO82IjrWDx+0EB7dOYjvECZU/D1+3yc6V Q+xw== X-Gm-Message-State: AOAM532AkNN7ALh6ZYyHZwTwpU2v4xmPPmMv3y0w5QckXkRybX2dd5eo Cx2TA26Lbzi7koMTqXT5alqzQUNImEE= X-Google-Smtp-Source: ABdhPJwAGnXfxJfklyoE0VwdsyIx+87I8QdE88h1cchOZzvg6G6kiU5fs5TSBfLMv/eixxEyVZzSNg== X-Received: by 2002:aa7:c407:: with SMTP id j7mr8494969edq.28.1613053120084; Thu, 11 Feb 2021 06:18:40 -0800 (PST) Received: from dell.be.48ers.dk (d51A5BC31.access.telenet.be. [81.165.188.49]) by smtp.gmail.com with ESMTPSA id w8sm3785045edd.39.2021.02.11.06.18.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 11 Feb 2021 06:18:39 -0800 (PST) Received: from peko by dell.be.48ers.dk with local (Exim 4.92) (envelope-from ) id 1lACnn-00049U-04; Thu, 11 Feb 2021 15:18:39 +0100 From: Peter Korsgaard To: buildroot@buildroot.org Date: Thu, 11 Feb 2021 15:18:37 +0100 Message-Id: <20210211141838.15911-1-peter@korsgaard.com> X-Mailer: git-send-email 2.20.1 MIME-Version: 1.0 Subject: [Buildroot] [PATCH] package/subversion: security bump to version 1.14.1 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" Fixes the following security issue: CVE-2020-17525: Remote unauthenticated denial-of-service in Subversion mod_authz_svn Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. For more details, see the advisory: https://subversion.apache.org/security/CVE-2020-17525-advisory.txt Signed-off-by: Peter Korsgaard --- package/subversion/subversion.hash | 4 ++-- package/subversion/subversion.mk | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/package/subversion/subversion.hash b/package/subversion/subversion.hash index da0fe91184..534d596514 100644 --- a/package/subversion/subversion.hash +++ b/package/subversion/subversion.hash @@ -1,5 +1,5 @@ -# From https://www.apache.org/dist/subversion/subversion-1.14.0.tar.bz2.sha512 -sha512 af6b706fdc91f7ab292fce9d9de582da306fd11e92767dc852687e71a6a8b65bb867fa70d5afd7f76a46005acb1b3c2d3193e690def48cd26875b3a7851cd13b subversion-1.14.0.tar.bz2 +# From https://www.apache.org/dist/subversion/subversion-1.14.1.tar.bz2.sha512 +sha512 0a70c7152b77cdbcb810a029263e4b3240b6ef41d1c19714e793594088d3cca758d40dfbc05622a806b06463becb73207df249393924ce591026b749b875fcdd subversion-1.14.1.tar.bz2 # Locally calculated sha256 484aff0cfbb81155a10f903ed756e27e9fc65578c245a295bae295c4bb51eaad LICENSE diff --git a/package/subversion/subversion.mk b/package/subversion/subversion.mk index 34ae7bc5e1..d4cc717536 100644 --- a/package/subversion/subversion.mk +++ b/package/subversion/subversion.mk @@ -4,7 +4,7 @@ # ################################################################################ -SUBVERSION_VERSION = 1.14.0 +SUBVERSION_VERSION = 1.14.1 SUBVERSION_SOURCE = subversion-$(SUBVERSION_VERSION).tar.bz2 SUBVERSION_SITE = https://downloads.apache.org/subversion SUBVERSION_LICENSE = Apache-2.0