From patchwork Sun May 30 08:44:57 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Korsgaard X-Patchwork-Id: 1485444 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=busybox.net (client-ip=140.211.166.137; helo=smtp4.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=XHw1s8Zx; dkim-atps=neutral Received: from smtp4.osuosl.org (smtp4.osuosl.org [140.211.166.137]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4FtBns6thmz9sSs for ; Sun, 30 May 2021 18:45:21 +1000 (AEST) Received: from localhost (localhost [127.0.0.1]) by smtp4.osuosl.org (Postfix) with ESMTP id EADA74030F; Sun, 30 May 2021 08:45:18 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from smtp4.osuosl.org ([127.0.0.1]) by localhost (smtp4.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id T62hz6_TIGpw; Sun, 30 May 2021 08:45:17 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by smtp4.osuosl.org (Postfix) with ESMTP id EB7B240315; Sun, 30 May 2021 08:45:16 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from smtp3.osuosl.org (smtp3.osuosl.org [140.211.166.136]) by ash.osuosl.org (Postfix) with ESMTP id 669F01BF599 for ; Sun, 30 May 2021 08:45:15 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by smtp3.osuosl.org (Postfix) with ESMTP id 5592660611 for ; Sun, 30 May 2021 08:45:15 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Authentication-Results: smtp3.osuosl.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com Received: from smtp3.osuosl.org ([127.0.0.1]) by localhost (smtp3.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0Tg_17RhLVWw for ; Sun, 30 May 2021 08:45:14 +0000 (UTC) X-Greylist: whitelisted by SQLgrey-1.8.0 Received: from mail-ej1-x630.google.com (mail-ej1-x630.google.com [IPv6:2a00:1450:4864:20::630]) by smtp3.osuosl.org (Postfix) with ESMTPS id E5F1E60610 for ; Sun, 30 May 2021 08:45:13 +0000 (UTC) Received: by mail-ej1-x630.google.com with SMTP id qq22so3640729ejb.9 for ; Sun, 30 May 2021 01:45:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=2Q3vN0ST9wbpUvbA0rzxh966pUPmAZ3EUuBvtaUdGKg=; b=XHw1s8Zxl7s2vOipNuD/8WCnoTXeF+wu7d+LoqLHbowFNnyQj6tVNf3pQYb7gFBQvf 4Hr3hKvaZFzCkGIsHoa7NvYP8Id4Xt9NGDzG7MdfsV2sgUTe16vPYyiHgfFJrzyT4oQl mL7NJaU2LEHaJFePMXLis4bp17uKYwgxS1/aCZQoLmmpM8b1xVfru6aAYvNecwdl5VC+ SmmwpW577JKPhLf2oUi4Cnnqu9w6OOv4y8HcB9xq5ZEzeXiBmESgKRseQH2adcvRlfX4 Q6+VyKsp2P2b0SLni4ZA6n348lfTGEcjeAbdaoFM1AukuF9U8BYF2VQKQkoms923Me43 WyCg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :mime-version:content-transfer-encoding; bh=2Q3vN0ST9wbpUvbA0rzxh966pUPmAZ3EUuBvtaUdGKg=; b=P5FP6r8ckB12eEIYjk+zDDMF+AOzvih8uUlOlTAbdjPUsVSKiS3MU+O3uFFq8ETDVf wde48Y3QoUgQMuQTKBIKCTZmes5+Bp7xTH0k+Bm0CCIkulTuS+YyJiuRUJImwmOvFJmn HIZgsS9RSJ8R2BWhC+mEdASc+mrm038lx9ynI/JV12U/AfBZbWnNP2vVvIMJqro6iPeU udawn8678fiLFQl+3JdcIMcfm68gkrAbjadym6cRpMxH0UFNvUoDzLipSjrPnX0Ogs5e 4Tq9193Poa4J5TT8bm7+wGyNoSgHOckQWf2TzptguvePx5LshgmPDyBXq8AjVpXb0355 uO6A== X-Gm-Message-State: AOAM5321w4gEelVgqzF7dRzEz07y9afYAcY02dHt4KtHxudV/Kl+TVFU 0C5KxTupfFyPfJnYlNi2Qm2LTNvS4ak= X-Google-Smtp-Source: ABdhPJz+s/ISwuUXB/7IZXGLW+vDaQKqgbDyR13YYOE59ai+Pm7NAy0ZAkyAC+7YuxdmFuIOedwBRg== X-Received: by 2002:a17:906:abcc:: with SMTP id kq12mr17985598ejb.97.1622364311983; Sun, 30 May 2021 01:45:11 -0700 (PDT) Received: from dell.be.48ers.dk (d51A5BC31.access.telenet.be. [81.165.188.49]) by smtp.gmail.com with ESMTPSA id p11sm5246083edt.22.2021.05.30.01.45.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 30 May 2021 01:45:11 -0700 (PDT) Received: from peko by dell.be.48ers.dk with local (Exim 4.92) (envelope-from ) id 1lnH4I-0006NW-6g; Sun, 30 May 2021 10:45:10 +0200 From: Peter Korsgaard To: buildroot@buildroot.org Date: Sun, 30 May 2021 10:44:57 +0200 Message-Id: <20210530084457.24417-1-peter@korsgaard.com> X-Mailer: git-send-email 2.20.1 MIME-Version: 1.0 Subject: [Buildroot] [PATCH] package/dhcp: security bump to version 4.4.2-P1 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" Fixes the following security issue: - CVE-2021-25217: A buffer overrun in lease file parsing code can be used to exploit a common vulnerability shared by dhcpd and dhclient For details, see the advisory: https://kb.isc.org/docs/cve-2021-25217 Update the LICENSE hash for a change of copyright years. Signed-off-by: Peter Korsgaard --- package/dhcp/dhcp.hash | 6 +++--- package/dhcp/dhcp.mk | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/package/dhcp/dhcp.hash b/package/dhcp/dhcp.hash index 92ecdfec58..ec7c4fe58d 100644 --- a/package/dhcp/dhcp.hash +++ b/package/dhcp/dhcp.hash @@ -1,4 +1,4 @@ -# Verified from https://ftp.isc.org/isc/dhcp/4.4.2/dhcp-4.4.2.tar.gz.sha256.asc -sha256 1a7ccd64a16e5e68f7b5e0f527fd07240a2892ea53fe245620f4f5f607004521 dhcp-4.4.2.tar.gz +# Verified from https://ftp.isc.org/isc/dhcp/4.4.2-P1/dhcp-4.4.2-P1.tar.gz.sha256.asc +sha256 b05e04337539545a8faa0d6ac518defc61a07e5aec66a857f455e7f218c85a1a dhcp-4.4.2-P1.tar.gz # Locally calculated -sha256 89e7b0661134cc118bdcdeb87ff0493d544bc5723c9ca6616fa05f03539738af LICENSE +sha256 9961fce0d83a6229b9084cdadedfa723a53274c63af610c9adb61b607e0f5a76 LICENSE diff --git a/package/dhcp/dhcp.mk b/package/dhcp/dhcp.mk index db58870f88..1edb3c5e99 100644 --- a/package/dhcp/dhcp.mk +++ b/package/dhcp/dhcp.mk @@ -4,7 +4,7 @@ # ################################################################################ -DHCP_VERSION = 4.4.2 +DHCP_VERSION = 4.4.2-P1 DHCP_SITE = http://ftp.isc.org/isc/dhcp/$(DHCP_VERSION) DHCP_INSTALL_STAGING = YES DHCP_LICENSE = MPL-2.0