Armin Kuster
f696ff1050
wireshark: Update to 2.2.11
...
changed --with-ssh to --with-libssh=DIR
includes:
wnpa-sec-2017-47 : CVE-2017-17084
The IWARP_MPA dissector could crash. (Bug 14236)
wnpa-sec-2017-48 : CVE-2017-17083
The NetBIOS dissector could crash. (Bug 14249)
wnpa-sec-2017-49 : CVE-2017-17085
The CIP Safety dissector could crash. (Bug 14250)
release notes:
https://www.wireshark.org/docs/relnotes/wireshark-2.2.11.html
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Armin Kuster <akuster808@gmail.com >
Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com >
2018-01-08 12:05:49 -05:00
Armin Kuster
c083405d2a
wireshark: update to 2.2.6
...
The following vulnerabilities have been fixed:
* [1]wnpa-sec-2017-12
IMAP dissector crash ([2]Bug 13466) [3]CVE-2017-7703
* [4]wnpa-sec-2017-13
WBMXL dissector infinite loop ([5]Bug 13477) [6]CVE-2017-7702
* [7]wnpa-sec-2017-14
NetScaler file parser infinite loop ([8]Bug 13478) [9]CVE-2017-7700
* [10]wnpa-sec-2017-15
RPCoRDMA dissector infinite loop ([11]Bug 13558) [12]CVE-2017-7705
* [13]wnpa-sec-2017-16
BGP dissector infinite loop ([14]Bug 13557) [15]CVE-2017-7701
* [16]wnpa-sec-2017-17
DOF dissector infinite loop ([17]Bug 13453) [18]CVE-2017-7704
* [19]wnpa-sec-2017-18
PacketBB dissector crash ([20]Bug 13559)
* [21]wnpa-sec-2017-19
SLSK dissector long loop ([22]Bug 13576)
* [23]wnpa-sec-2017-20
SIGCOMP dissector infinite loop ([24]Bug 13578)
* [25]wnpa-sec-2017-21
WSP dissector infinite loop ([26]Bug 13581)
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com >
2017-04-25 15:55:38 -04:00
Armin Kuster
01511d4cde
ntp: update to 4.2.8.p10
...
LICENSE_FILE md5 changed do to copyright date change.
NTF's NTP Project is releasing ntp-4.2.8p10, which addresses:
6 MEDIUM severity vulnerabilities (1 is about the Windows PPSAPI DLL)
5 LOW severity vulnerabilities (2 are in the Windows Installer)
4 Informational-level vulnerabilities
15 other non-security fixes and improvements
All of the security issues in this release are listed in VU#633849.
ntp-4.2.8p10 was released on 21 March 2017.
Sec 3389 / CVE-2017-6464 / VU#325339: NTP-01-016 NTP: Denial of Service via Malformed Config (Pentest report 01.2017)
Sec 3388 / CVE-2017-6462 / VU#325339: NTP-01-014 NTP: Buffer Overflow in DPTS Clock (Pentest report 01.2017)
Sec 3387 / CVE-2017-6463 / VU#325339: NTP-01-012 NTP: Authenticated DoS via Malicious Config Option (Pentest report 01.2017)
Sec 3386: NTP-01-011 NTP: ntpq_stripquotes() returns incorrect Value (Pentest report 01.2017)
Sec 3385: NTP-01-010 NTP: ereallocarray()/eallocarray() underused (Pentest report 01.2017)
Sec 3384 / CVE-2017-6455 / VU#325339: NTP-01-009 NTP: Windows: Privileged execution of User Library code (Pentest report 01.2017)
Sec 3383 / CVE-2017-6452 / VU#325339: NTP-01-008 NTP: Windows Installer: Stack Buffer Overflow from Command Line (Pentest report 01.2017)
Sec 3382 / CVE-2017-6459 / VU#325339: NTP-01-007 NTP: Windows Installer: Data Structure terminated insufficiently (Pentest report 01.2017)
Sec 3381: NTP-01-006 NTP: Copious amounts of Unused Code (Pentest report 01.2017)
Sec 3380: NTP-01-005 NTP: Off-by-one in Oncore GPS Receiver (Pentest report 01.2017)
Sec 3379 / CVE-2017-6458 / VU#325339: NTP-01-004 NTP: Potential Overflows in ctl_put() functions (Pentest report 01.2017)
Sec 3378 / CVE-2017-6451 / VU#325339: NTP-01-003 Improper use of snprintf() in mx4200_send() (Pentest report 01.2017)
Sec 3377 / CVE-2017-6460 / VU#325339: NTP-01-002 Buffer Overflow in ntpq when fetching reslist (Pentest report 01.2017)
Sec 3376: NTP-01-001 Makefile does not enforce Security Flags (Pentest report 01.2017)
Sec 3361 / CVE-2016-9042 / VU#325339: 0rigin
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com >
2017-04-25 10:24:47 -04:00
Armin Kuster
d940c11e66
tcpdump: update to 4.9.0 for security fixes
...
CVE included in this release:
CVE-2016-7922 CVE-2016-7923 CVE-2016-7924 CVE-2016-7925
CVE-2016-7926 CVE-2016-7927 CVE-2016-7928 CVE-2016-7929
CVE-2016-7930 CVE-2016-7931 CVE-2016-7932 CVE-2016-7933
CVE-2016-7934 CVE-2016-7935 CVE-2016-7936 CVE-2016-7937
CVE-2016-7938 CVE-2016-7939 CVE-2016-7940 CVE-2016-7973
CVE-2016-7974 CVE-2016-7975 CVE-2016-7983 CVE-2016-7984
CVE-2016-7985 CVE-2016-7986 CVE-2016-7992 CVE-2016-7993
CVE-2016-8574 CVE-2016-8575 CVE-2017-5202 CVE-2017-5203
CVE-2017-5204 CVE-2017-5205 CVE-2017-5341 CVE-2017-5342
CVE-2017-5482 CVE-2017-5483 CVE-2017-5484 CVE-2017-5485
CVE-2017-5486
updated add-ptest patch to apply to Makefile.in
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com >
2017-02-22 08:31:59 -05:00
Armin Kuster
b813911696
cpuset: add new python package
...
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2016-07-29 10:59:41 +02:00
Armin Kuster
207e97112b
python-cryptography: fix compile issue with openssl 1.0.2h
...
this fixes:
error: 'SSLv2_method' redeclared as different kind of symbol
| SSL_METHOD* (*SSLv2_method)(void) = NULL;
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2016-05-19 12:02:41 +02:00
Armin Kuster
8cd5bc5346
ntp: Security fixes via update to 4.2.8p7
...
CVE-2016-1551
CVE-2016-2516
CVE-2016-2517
CVE-2016-2518
CVE-2016-2519
CVE-2016-1547
CVE-2015-7704
CVE-2015-8138
CVE-2016-1550
for more info see:
http://support.ntp.org/bin/view/Main/SecurityNotice#April_2016_NTP_4_2_8p7_Security
Signed-off-by: Armin Kuster <akuster@mvista.com >
Acked-by: Joe MacDonald <joe_macdonald@mentor.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com >
2016-05-05 11:41:28 -04:00
Armin Kuster
44f0e74954
python-crytograph: fix build issue do to openssl 1.0.1g upgrade
...
this fixes
build/temp.linux-x86_64-2.7/_openssl.c:697:6: error: conflicting types for 'BIO_new_mem_buf'
BIO *BIO_new_mem_buf(void *, int);
^
In file included from /home/jenkins/oe/world/shr-core/tmp-glibc/sysroots/qemuarm/usr/include/openssl/asn1.h:65:0,
from build/temp.linux-x86_64-2.7/_openssl.c:413:
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2016-03-25 11:27:33 +01:00
Armin Kuster
1692d5c302
netmap: add new package
...
this adds netmap, the fast packet I/O framework
http://info.iet.unipi.it/~luigi/netmap/
- updated to latest version to get kernel 4.1 support
- fixed printf type issue
- Fixed manual config options
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com >
2015-09-15 10:49:30 -04:00
Armin Kuster
7ceb57db0b
ipmiutil: add new package
...
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2015-08-24 13:59:44 +02:00
Armin Kuster
2750941c1e
nbd: Add new package
...
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com >
2015-07-15 15:44:09 -04:00
Armin Kuster
f143211de3
wireshark: update to 12.4
...
The following vulnerabilities have been fixed.
* [1]wnpa-sec-2015-06
The ATN-CPDLC dissector could crash. ([2]Bug 9952) [3]CVE-2015-2187
* [4]wnpa-sec-2015-07
The WCP dissector could crash. ([5]Bug 10844) [6]CVE-2015-2188
* [7]wnpa-sec-2015-08
The pcapng file parser could crash. ([8]Bug 10895) [9]CVE-2015-2189
* [10]wnpa-sec-2015-09
The LLDP dissector could crash. ([11]Bug 10983) [12]CVE-2015-2190
* [13]wnpa-sec-2015-10
The TNEF dissector could go into an infinite loop. Discovered by
Vlad Tsyrklevich. ([14]Bug 11023) [15]CVE-2015-2191
* [16]wnpa-sec-2015-11
The SCSI OSD dissector could go into an infinite loop. Discovered
by Vlad Tsyrklevich. ([17]Bug 11024) [18]CVE-2015-2192
For more information see
https://www.wireshark.org/docs/relnotes/wireshark-1.12.4.html
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com >
2015-03-10 18:23:56 -04:00
Armin Kuster
bcfbe19f4a
mcelog: update to latest
...
remove unused md5sum check since using git.
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2015-03-03 08:37:27 +01:00
Armin Kuster
ebda04b2c0
edac-utils: Add new package
...
Userspace helper for kernel EDAC drivers (Error Detection and Correction)
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2015-03-03 08:37:27 +01:00
Armin Kuster
8912083e23
wireshark: fix rdepends issue
...
Added a few more PACKAGECONF options
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com >
2015-01-26 10:27:55 -05:00
Armin Kuster
d6afd2bdb6
strongswan: update package to 5.2.1
...
see https://wiki.strongswan.org/projects/strongswan/wiki/Changelog52
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2014-12-09 11:34:42 +01:00
Armin Kuster
967f16750a
wireshark: fix build depends
...
This should address issues found in test-dependencies 2014-07-25
wireshark/wireshark/latest lost dependency on libcap libnl libnl-genl libnl-nf libnl-route portaudio-v19 sbc
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2014-08-01 14:23:45 +02:00
Armin Kuster
6d92fd5d68
wireshark: fix build for arm
...
* Backported Arm build fix
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2014-08-01 14:23:45 +02:00
Armin Kuster
9bfdcec408
wireshark: Add recipe 1.12.0-rc2
...
* Inital wireshark support on gtk+, gtk3
* README with additional info
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2014-08-01 14:23:44 +02:00
Armin Kuster
ee37bcbbae
libnet: fix build issue with package upgrade
...
The main issue was the endianess detection. The ac override did not work.
The current version has updated automake and autoconf files that address better endianess detection and it plays well with YP autotools.
Build tested on all qemus arches.
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2014-06-21 10:32:30 +02:00
Armin Kuster
8316933b40
libol: compile issue files missing in B and packaging issue
...
needed to copy over a file from S to B.
remove packaging requirement for /usr/bin/scsh. Not needed (see link)
https://lists.balabit.hu/pipermail/syslog-ng/2000-August/000795.html
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2014-06-13 13:38:12 +02:00
Armin Kuster
a97e06713e
postgresql: B!=S fix
...
This fixes a configure issue do to incorrect directory reference.
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2014-06-10 12:29:00 +02:00
Armin Kuster
a3142cd44b
tipcutils: B!=S fix
...
The do_install_append was trying to install from src location and not the build.
Signed-off-by: Armin Kuster <akuster@mvista.com >
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com >
2014-06-10 12:29:00 +02:00