From patchwork Fri May 22 20:10:41 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Fabrice Fontaine X-Patchwork-Id: 1296446 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=busybox.net (client-ip=140.211.166.138; helo=whitealder.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Authentication-Results: ozlabs.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=DCKzhf3Q; dkim-atps=neutral Received: from whitealder.osuosl.org (smtp1.osuosl.org [140.211.166.138]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 49THfJ3dl0z9sPF for ; Sat, 23 May 2020 06:10:16 +1000 (AEST) Received: from localhost (localhost [127.0.0.1]) by whitealder.osuosl.org (Postfix) with ESMTP id 4D34888863; Fri, 22 May 2020 20:10:13 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from whitealder.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JqLKFOdj0wPK; Fri, 22 May 2020 20:10:11 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by whitealder.osuosl.org (Postfix) with ESMTP id B4E858861A; Fri, 22 May 2020 20:10:10 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from fraxinus.osuosl.org (smtp4.osuosl.org [140.211.166.137]) by ash.osuosl.org (Postfix) with ESMTP id 756D41BF2A0 for ; Fri, 22 May 2020 20:10:09 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by fraxinus.osuosl.org (Postfix) with ESMTP id 6ACD287A13 for ; Fri, 22 May 2020 20:09:48 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from fraxinus.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9FB19pm2TQ-q for ; Fri, 22 May 2020 20:09:38 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from mail-wr1-f68.google.com (mail-wr1-f68.google.com [209.85.221.68]) by fraxinus.osuosl.org (Postfix) with ESMTPS id C324A87A02 for ; Fri, 22 May 2020 20:09:31 +0000 (UTC) Received: by mail-wr1-f68.google.com with SMTP id w7so11287589wre.13 for ; Fri, 22 May 2020 13:09:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=ERBztGk0uQ7ZcQbbutd3F1HF34XuPx0fby4EYWyrfW8=; b=DCKzhf3Q3YkTJHo74sIT+tj9FYnUyENdvT0vVWAbWejZVFTOX6UHhX+rtP+sHtBq3P mgHZwc4BMpfRwfuDRwG8S15vaIx+nsKuZaM2U/PTe0kw6dpBC1Wd5u7nkzi3kYWkGVXI hz0EPVRPHvc45FF+0DbW4pKiKoHNKlbXzZjS+FgpU1XbDAveUCIZHqGW/1wmDHKKv6ah 0GUQp14ZFzIHwJcY2LEQx95E5NsOWyMEijNhE+/9FR82YUH3cNHjRr9jpfr1LrsNO2Ij wGM/JZZaLwYMkpEJbES6bCmnwRMy3hdrq8+mHUJSaSkulRJl8n18Lf+t5TYYUVo0XpT/ 3hSg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=ERBztGk0uQ7ZcQbbutd3F1HF34XuPx0fby4EYWyrfW8=; b=QyL85SeoUTAj/McvwgVKEHr1nQIyfRfbyw8s/x+89CrfpXRUAtRC7GT46IIXsafgbC +UYYUchDXfkKn5SszEtnV8TGhU9qeUl1Egz1ndb8Fo+wVE9J3681qK5oblEPFMxyQanD Ey0GB6rUfir8RBMc5adaJImbWwyM39d2B9Xcj/ZE4M3sKW8T3E1zvbMjZ/X/1rrNkkZo 8JG0ybAYzjPKLoyyrTH6O3Fp/RjNBZrBhB9k3c/UReTb5R2SNROu9nRFBLd0jF4f04i1 u5PDRVe5Vc7jvecz5v7xi4i5fT6j0fLXjO5EBhDCRDqkppN5ZqWB1rET+xcfexCnznSe 3HQg== X-Gm-Message-State: AOAM531JNH6WToyrkMkci3ObBWN5U+QtivdEi2HM/PXScNqzyzIFbLk/ zUm3Co3F5GKWb9tc/Gt5CC29o0bT X-Google-Smtp-Source: ABdhPJwCp+EvphOLw5p7Dh68GHwb9gTh7iPXgDkqyMHJtRtwOwGh1r2QU47Q07JOuhFdxNyALrcU5w== X-Received: by 2002:adf:9447:: with SMTP id 65mr4728248wrq.331.1590178169964; Fri, 22 May 2020 13:09:29 -0700 (PDT) Received: from kali.home (lfbn-ren-1-2144-158.w92-167.abo.wanadoo.fr. [92.167.223.158]) by smtp.gmail.com with ESMTPSA id z10sm10368852wmi.2.2020.05.22.13.09.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 22 May 2020 13:09:29 -0700 (PDT) From: Fabrice Fontaine To: buildroot@buildroot.org Date: Fri, 22 May 2020 22:10:41 +0200 Message-Id: <20200522201041.962767-1-fontaine.fabrice@gmail.com> X-Mailer: git-send-email 2.26.2 MIME-Version: 1.0 Subject: [Buildroot] [PATCH 1/1] package/wireshark: security bump to version 3.2.4 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Fabrice Fontaine Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" Fix CVE-2020-13164: In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on a filesystem. Signed-off-by: Fabrice Fontaine --- package/wireshark/wireshark.hash | 6 +++--- package/wireshark/wireshark.mk | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/package/wireshark/wireshark.hash b/package/wireshark/wireshark.hash index d4d0c9e48f..57b496282f 100644 --- a/package/wireshark/wireshark.hash +++ b/package/wireshark/wireshark.hash @@ -1,6 +1,6 @@ -# From https://www.wireshark.org/download/src/all-versions/SIGNATURES-3.2.3.txt -sha1 4656856a40b294f183900ba47651b0fc8e3950fd wireshark-3.2.3.tar.xz -sha256 f007e4b88c86d95e33af03e057ecc03635f54466d02371bc26489eabb274faba wireshark-3.2.3.tar.xz +# From https://www.wireshark.org/download/src/all-versions/SIGNATURES-3.2.4.txt +sha1 bb4157b57c1bcdbac948a1282dafad027d57be9b wireshark-3.2.4.tar.xz +sha256 d17d461e849e2d0b033431c45f71d8ee8ec3c8faa232a6ad63069a47927db8aa wireshark-3.2.4.tar.xz # Locally calculated sha256 7cdbed2b697efaa45576a033f1ac0e73cd045644a91c79bbf41d4a7d81dac7bf COPYING diff --git a/package/wireshark/wireshark.mk b/package/wireshark/wireshark.mk index c262891dcd..0d72f9dd91 100644 --- a/package/wireshark/wireshark.mk +++ b/package/wireshark/wireshark.mk @@ -4,7 +4,7 @@ # ################################################################################ -WIRESHARK_VERSION = 3.2.3 +WIRESHARK_VERSION = 3.2.4 WIRESHARK_SOURCE = wireshark-$(WIRESHARK_VERSION).tar.xz WIRESHARK_SITE = https://www.wireshark.org/download/src/all-versions WIRESHARK_LICENSE = wireshark license