Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 10 Oct 2010 21:17:26 +0700 (NOVST)
From:      Eugene Grosbein <eugen@eg.sd.rdtc.ru>
To:        FreeBSD-gnats-submit@FreeBSD.org
Subject:   ports/151364: update archivers/bzip2 to 1.0.6 to fix CVE-2010-0405
Message-ID:  <201010101417.o9AEHQY8070788@eg.sd.rdtc.ru>
Resent-Message-ID: <201010101440.o9AEe29d025450@freefall.freebsd.org>

next in thread | raw e-mail | index | archive | help

>Number:         151364
>Category:       ports
>Synopsis:       update archivers/bzip2 to 1.0.6 to fix CVE-2010-0405
>Confidential:   no
>Severity:       non-critical
>Priority:       low
>Responsible:    freebsd-ports-bugs
>State:          open
>Quarter:        
>Keywords:       
>Date-Required:
>Class:          update
>Submitter-Id:   current-users
>Arrival-Date:   Sun Oct 10 14:40:01 UTC 2010
>Closed-Date:
>Last-Modified:
>Originator:     Eugene Grosbein
>Release:        FreeBSD 8.1-STABLE i386
>Organization:
RDTC JSC
>Environment:
System: FreeBSD eg.sd.rdtc.ru 8.1-STABLE FreeBSD 8.1-STABLE #17: Mon Aug 23 13:55:22 NOVST 2010 root@eg.sd.rdtc.ru:/usr/local/obj/usr/local/src/sys/EG i386

>Description:
	The port archivers/bzip2 still installs version 1.0.5
	that's vulnerable to CVE-2010-0405. Let's move to 1.0.6 containing fix.

>How-To-Repeat:
	I still have some remote installations of FreeBSD 4.11-STABLE
	that run rock-stable. Some software (e.g. clamav antivirus) that
	link with libbz2 contain configure script that demonstrate
	segfaults if linked with version before 1.0.6

>Fix:

diff -urN bzip2.orig/Makefile bzip2/Makefile
--- bzip2.orig/Makefile	2008-03-21 05:44:53.000000000 +0600
+++ bzip2/Makefile	2010-10-10 21:03:55.000000000 +0700
@@ -7,7 +7,7 @@
 #
 
 PORTNAME=	bzip2
-PORTVERSION=	1.0.5
+PORTVERSION=	1.0.6
 CATEGORIES=	archivers
 MASTER_SITES=	http://www.bzip.org/${PORTVERSION}/
 
diff -urN bzip2.orig/distinfo bzip2/distinfo
--- bzip2.orig/distinfo	2008-03-21 05:44:53.000000000 +0600
+++ bzip2/distinfo	2010-10-10 21:04:44.000000000 +0700
@@ -1,3 +1,3 @@
-MD5 (bzip2-1.0.5.tar.gz) = 3c15a0c8d1d3ee1c46a1634d00617b1a
-SHA256 (bzip2-1.0.5.tar.gz) = f7bf5368309d76e5daf3a89d4d1bea688dac7780742e7a0ae1af19be9316fe22
-SIZE (bzip2-1.0.5.tar.gz) = 841402
+MD5 (bzip2-1.0.6.tar.gz) = 00b516f4704d4a7cb50a1d97e6e8e15b
+SHA256 (bzip2-1.0.6.tar.gz) = a2848f34fcd5d6cf47def00461fcb528a0484d8edef8208d6d2e2909dc61d9cd
+SIZE (bzip2-1.0.6.tar.gz) = 782025


>Release-Note:
>Audit-Trail:
>Unformatted:



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201010101417.o9AEHQY8070788>