diff options
author | Peiran Hong <peiran.hong@windriver.com> | 2019-10-07 09:43:40 -0400 |
---|---|---|
committer | Armin Kuster <akuster808@gmail.com> | 2019-10-19 08:23:16 -0700 |
commit | fea53271d1fcd482ed1003e40f2cf5573cdb37a3 (patch) | |
tree | 86522abfaf62d1904ffdc222badbc05be7a08415 /meta-networking/recipes-support/tcpdump/tcpdump/avoid-absolute-path-when-searching-for-libdlpi.patch | |
parent | b71e3bb1db813bf4bfdf45492ed5f69b643d9587 (diff) | |
download | meta-openembedded-fea53271d1fcd482ed1003e40f2cf5573cdb37a3.tar.gz |
tcpdump: upgrade 4.9.2 -> 4.9.3
This upgrade adds some new features and fixes numerous bugs including
the following CVEs:
CVE: CVE-2017-16808 (AoE)
CVE: CVE-2018-14468 (FrameRelay)
CVE: CVE-2018-14469 (IKEv1)
CVE: CVE-2018-14470 (BABEL)
CVE: CVE-2018-14466 (AFS/RX)
CVE: CVE-2018-14461 (LDP)
CVE: CVE-2018-14462 (ICMP)
CVE: CVE-2018-14465 (RSVP)
CVE: CVE-2018-14881 (BGP)
CVE: CVE-2018-14464 (LMP)
CVE: CVE-2018-14463 (VRRP)
CVE: CVE-2018-14467 (BGP)
CVE: CVE-2018-10103 (SMB - partially fixed, but SMB printing disabled)
CVE: CVE-2018-10105 (SMB - too unreliably reproduced,
SMB printing disabled)
CVE: CVE-2018-14880 (OSPF6)
CVE: CVE-2018-16451 (SMB)
CVE: CVE-2018-14882 (RPL)
CVE: CVE-2018-16227 (802.11)
CVE: CVE-2018-16229 (DCCP)
CVE: CVE-2018-16301 (was fixed in libpcap)
CVE: CVE-2018-16230 (BGP)
CVE: CVE-2018-16452 (SMB)
CVE: CVE-2018-16300 (BGP)
CVE: CVE-2018-16228 (HNCP)
CVE: CVE-2019-15166 (LMP)
CVE: CVE-2019-15167 (VRRP)
CVE: CVE-2018-14879 (tcpdump -V)
Deleted patch "0001-CVE-2017-16808-AoE-Add-a-missing-bounds-check.patch"
since the fix is included in the upgrade.
Modified patches "avoid-absolute-path-when-searching-for-libdlpi.patch",
"unnecessary-to-check-libpcap.patch", and "add-ptest.path" since
the upgrade renamed configure.in to configure.ac and made changes
to the file.
Added PACKAGECONFIG for smb. It is disabled by default in
the upgraded version in both the package's configure script and this
bitbake recipe since it is insecure.
Modified the parsing of ptest result to align with the new output
format.
With core-image-minimal on qemux86-64/kvm:
Recipe | Passed | Failed | Skipped | Time(s)
Before | 408 | 0 | 2 | 4
After | 431 | 11 | 2 | 10
11 test failed after the upgrade since libpcap is not upgraded
alongside with tcpdump.
Signed-off-by: Peiran Hong <peiran.hong@windriver.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit 71535e2f0ea76d39d2911e022905ec8ee9843872)
[Upgrade is a resonable path do to the # of patches needed to address
all this issues]
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Diffstat (limited to 'meta-networking/recipes-support/tcpdump/tcpdump/avoid-absolute-path-when-searching-for-libdlpi.patch')
-rw-r--r-- | meta-networking/recipes-support/tcpdump/tcpdump/avoid-absolute-path-when-searching-for-libdlpi.patch | 19 |
1 files changed, 10 insertions, 9 deletions
diff --git a/meta-networking/recipes-support/tcpdump/tcpdump/avoid-absolute-path-when-searching-for-libdlpi.patch b/meta-networking/recipes-support/tcpdump/tcpdump/avoid-absolute-path-when-searching-for-libdlpi.patch index d82c16053..977ab95b7 100644 --- a/meta-networking/recipes-support/tcpdump/tcpdump/avoid-absolute-path-when-searching-for-libdlpi.patch +++ b/meta-networking/recipes-support/tcpdump/tcpdump/avoid-absolute-path-when-searching-for-libdlpi.patch | |||
@@ -1,6 +1,6 @@ | |||
1 | From a2bfd28034d9aa48d8ff109c1314e53bc9779752 Mon Sep 17 00:00:00 2001 | 1 | From 02085028cdaf075943c27ebc02bb6de0289ec1d3 Mon Sep 17 00:00:00 2001 |
2 | From: Andre McCurdy <armccurdy@gmail.com> | 2 | From: Andre McCurdy <armccurdy@gmail.com> |
3 | Date: Wed, 24 Oct 2018 22:26:08 -0700 | 3 | Date: Wed, 2 Oct 2019 16:43:48 -0400 |
4 | Subject: [PATCH] avoid absolute path when searching for libdlpi | 4 | Subject: [PATCH] avoid absolute path when searching for libdlpi |
5 | 5 | ||
6 | Let the build environment control library search paths. | 6 | Let the build environment control library search paths. |
@@ -8,15 +8,16 @@ Let the build environment control library search paths. | |||
8 | Upstream-Status: Inappropriate [OE specific] | 8 | Upstream-Status: Inappropriate [OE specific] |
9 | 9 | ||
10 | Signed-off-by: Andre McCurdy <armccurdy@gmail.com> | 10 | Signed-off-by: Andre McCurdy <armccurdy@gmail.com> |
11 | Signed-off-by: Peiran Hong <peiran.hong@windriver.com> | ||
11 | --- | 12 | --- |
12 | configure.in | 2 +- | 13 | configure.ac | 2 +- |
13 | 1 file changed, 1 insertion(+), 1 deletion(-) | 14 | 1 file changed, 1 insertion(+), 1 deletion(-) |
14 | 15 | ||
15 | diff --git a/configure.in b/configure.in | 16 | diff --git a/configure.ac b/configure.ac |
16 | index c882909..52aefd6 100644 | 17 | index 3401a7a3..6a52485a 100644 |
17 | --- a/configure.in | 18 | --- a/configure.ac |
18 | +++ b/configure.in | 19 | +++ b/configure.ac |
19 | @@ -542,7 +542,7 @@ don't.]) | 20 | @@ -528,7 +528,7 @@ don't.]) |
20 | fi | 21 | fi |
21 | 22 | ||
22 | # libdlpi is needed for Solaris 11 and later. | 23 | # libdlpi is needed for Solaris 11 and later. |
@@ -26,5 +27,5 @@ index c882909..52aefd6 100644 | |||
26 | dnl | 27 | dnl |
27 | dnl Check for "pcap_list_datalinks()", "pcap_set_datalink()", | 28 | dnl Check for "pcap_list_datalinks()", "pcap_set_datalink()", |
28 | -- | 29 | -- |
29 | 1.9.1 | 30 | 2.17.1 |
30 | 31 | ||