Bug 201893 - sysutils/logstash: Update to 1.5.3
Summary: sysutils/logstash: Update to 1.5.3
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Many People
Assignee: Mark Felder
URL:
Keywords:
: 201874 (view as bug list)
Depends on:
Blocks:
 
Reported: 2015-07-26 17:11 UTC by Enrico M. Crisostomo
Modified: 2015-08-04 14:29 UTC (History)
3 users (show)

See Also:


Attachments
logstash 1.5.3: svn patch (564.39 KB, patch)
2015-07-26 17:11 UTC, Enrico M. Crisostomo
no flags Details | Diff
logstash 1.5.3: poudriere testport output (19.43 KB, text/plain)
2015-07-26 17:12 UTC, Enrico M. Crisostomo
no flags Details
security/vuxml for CVE-2015-5378 in logstash < 1.5.3 (1.55 KB, patch)
2015-07-27 01:39 UTC, Jason Unovitch
junovitch: maintainer-approval? (ports-secteam)
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Enrico M. Crisostomo 2015-07-26 17:11:57 UTC
Created attachment 159247 [details]
logstash 1.5.3: svn patch

This patch updates sysutils/logstash to 1.5.3 and solves:

    Bug 201874 - sysutils/logstash: SSL/TLS vulnerability with Lumberjack input (CVE-2015-5378)
Comment 1 Enrico M. Crisostomo 2015-07-26 17:12:28 UTC
Created attachment 159248 [details]
logstash 1.5.3: poudriere testport output
Comment 2 Jason Unovitch freebsd_committer freebsd_triage 2015-07-27 01:39:52 UTC
Created attachment 159290 [details]
security/vuxml for CVE-2015-5378 in logstash < 1.5.3

Enrico,
Thanks for the quick update!  Here's security/vuxml to go along with the update.

Log:

Document logstash SSL/TLS security vulnerability (FREAK attack)

PR:		201893
Security:	CVE-2015-5378
Security:	c470bcc7-33fe-11e5-a4a5-002590263bf5

Validation:

> make validate
/bin/sh /usr/ports/security/vuxml/files/tidy.sh "/usr/ports/security/vuxml/files/tidy.xsl" "/usr/ports/security/vuxml/vuln.xml" > "/usr/ports/security/vuxml/vuln.xml.tidy"
>>> Validating...
/usr/local/bin/xmllint --valid --noout /usr/ports/security/vuxml/vuln.xml
>>> Successful.
Checking if tidy differs...
... seems okay
Checking for space/tab...
... seems okay
/usr/local/bin/python2.7 /usr/ports/security/vuxml/files/extra-validation.py /usr/ports/security/vuxml/vuln.xml

> env PKG_DBDIR=/usr/ports/security/vuxml pkg audit logstash-1.5.1
logstash-1.5.1 is vulnerable:
logstash -- SSL/TLS vulnerability with Lumberjack input
CVE: CVE-2015-5378
WWW: https://vuxml.FreeBSD.org/freebsd/c470bcc7-33fe-11e5-a4a5-002590263bf5.html

1 problem(s) in the installed packages found.

> env PKG_DBDIR=/usr/ports/security/vuxml pkg audit logstash-1.5.3
0 problem(s) in the installed packages found.
Comment 3 Jason Unovitch freebsd_committer freebsd_triage 2015-07-27 01:41:26 UTC
*** Bug 201874 has been marked as a duplicate of this bug. ***
Comment 4 Enrico M. Crisostomo 2015-07-27 10:27:32 UTC
You're welcome Jason.

(In reply to Jason Unovitch from comment #2)
Comment 5 Jason Unovitch freebsd_committer freebsd_triage 2015-07-27 10:49:39 UTC
(In reply to Enrico M. Crisostomo from comment #1)

Supplementing this testport, I also tested in Poudriere and the patch builds on the following:
8.4-RELEASE-p31      amd64
8.4-RELEASE-p31      i386
9.3-RELEASE-p17      amd64
9.3-RELEASE-p17      i386
10.1-RELEASE-p14     amd64
10.1-RELEASE-p14     i386
10.2-BETA2           amd64
10.2-BETA2           i386
11.0-CURRENT r284725 amd64
11.0-CURRENT r284725 i386
Comment 6 commit-hook freebsd_committer freebsd_triage 2015-07-27 13:06:52 UTC
A commit references this bug:

Author: feld
Date: Mon Jul 27 13:06:50 UTC 2015
New revision: 392978
URL: https://svnweb.freebsd.org/changeset/ports/392978

Log:
  Document logstash SSL/TLS security vulnerability (FREAK attack)

  PR:		201893
  Security:	CVE-2015-5378
  Security:	c470bcc7-33fe-11e5-a4a5-002590263bf5

Changes:
  head/security/vuxml/vuln.xml
Comment 7 Jason Unovitch freebsd_committer freebsd_triage 2015-08-04 02:16:47 UTC
Mark,
Do you need any assistance?
Comment 8 Enrico M. Crisostomo 2015-08-04 09:36:46 UTC
Hi Jason,

I'm afraid I need your assistance indeed.  When I saw the last line of your comment #2 I thought the CVE-2015-5378 issues was fixed.  Could you point me at some documentation about what am I supposed to do now?

Thank you very much,
-- 
Enrico
 
(In reply to Jason Unovitch from comment #7)
Comment 9 Jason Unovitch freebsd_committer freebsd_triage 2015-08-04 10:59:00 UTC
Mark, do you want me to go ahead and commit this one?
Comment 10 Enrico M. Crisostomo 2015-08-04 11:04:03 UTC
Doh, sorry Jason, I didn't notice the "Mark" line in the mail notification.  Sorry for the noise.
 
(In reply to Enrico M. Crisostomo from comment #8)
Comment 11 Mark Felder freebsd_committer freebsd_triage 2015-08-04 14:20:39 UTC
I had tested and then was distracted. Thanks for prompting me.
Comment 12 commit-hook freebsd_committer freebsd_triage 2015-08-04 14:27:30 UTC
A commit references this bug:

Author: feld
Date: Tue Aug  4 14:26:40 UTC 2015
New revision: 393522
URL: https://svnweb.freebsd.org/changeset/ports/393522

Log:
  sysutils/logstash: update to 1.5.3

  PR:		201893
  Security:	CVE-2015-5378
  Security:	c470bcc7-33fe-11e5-a4a5-002590263bf5

  MFH:		2015Q3

Changes:
  head/sysutils/logstash/Makefile
  head/sysutils/logstash/distinfo
  head/sysutils/logstash/pkg-plist
Comment 13 commit-hook freebsd_committer freebsd_triage 2015-08-04 14:28:33 UTC
A commit references this bug:

Author: feld
Date: Tue Aug  4 14:27:44 UTC 2015
New revision: 393524
URL: https://svnweb.freebsd.org/changeset/ports/393524

Log:
  MFH: r393522

  sysutils/logstash: update to 1.5.3

  PR:		201893
  Security:	CVE-2015-5378
  Security:	c470bcc7-33fe-11e5-a4a5-002590263bf5
  Approved by:	ports-secteam (with hat)

Changes:
_U  branches/2015Q3/
  branches/2015Q3/sysutils/logstash/Makefile
  branches/2015Q3/sysutils/logstash/distinfo
  branches/2015Q3/sysutils/logstash/pkg-plist
Comment 14 Mark Felder freebsd_committer freebsd_triage 2015-08-04 14:28:45 UTC
The rc script could use some work, but it's more important we get this security fix out.