Bug 156246 - [PATCH] net/isc-dhcp41-server: update to 4.1-ESV-R2 *CVE-2011-0997*
Summary: [PATCH] net/isc-dhcp41-server: update to 4.1-ESV-R2 *CVE-2011-0997*
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Wesley Shields
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-04-07 12:10 UTC by Marcin Cieślak
Modified: 2011-04-10 22:50 UTC (History)
1 user (show)

See Also:


Attachments
isc-dhcp41-server-4.1,2.patch (1.44 KB, patch)
2011-04-07 12:10 UTC, Marcin Cieślak
no flags Details | Diff
isc-dhcp41-server.patch (1.38 KB, patch)
2011-04-08 03:21 UTC, Douglas Thrift
no flags Details | Diff
vuxml.patch (1.48 KB, patch)
2011-04-10 06:00 UTC, Douglas Thrift
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Marcin Cieślak 2011-04-07 12:10:07 UTC
- Quick & dirty update to 4.1-ESV-R2

Not sure about PORTEPOCH bump, but the 4.1 line got somehow rebadged.

                        Changes since 4.1-ESV-R1

! In dhclient check the data for some string options for
  reasonableness before passing it along to the script that
  interfaces with the OS.
  [ISC-Bugs #23722]
  CVE: CVE-2011-0997
                        Changes since 4.1-ESV

! When processing a request in the DHCPv6 server code that specifies
  an address that is tagged as abandoned (meaning we received a
  decline request for it previously) don't attempt to move it from
  the inactive to active pool as doing so can result in the server
  crshing on an assert failure.  Also retag the lease as active
  and reset it's timeout value.
  [ISC-Bugs #21921]
  
(4.1-ESV seems to be re-badged 4.1.2-P1 we have in ports)

Port maintainer (douglas@douglasthrift.net) is cc'd.

Generated with FreeBSD Port Tools 0.99
Comment 1 Edwin Groothuis freebsd_committer freebsd_triage 2011-04-07 12:10:18 UTC
Maintainer of net/isc-dhcp41-server,

Please note that PR ports/156246 has just been submitted.

If it contains a patch for an upgrade, an enhancement or a bug fix
you agree on, reply to this email stating that you approve the patch
and a committer will take care of it.

The full text of the PR can be found at:
    http://www.freebsd.org/cgi/query-pr.cgi?pr=ports/156246

-- 
Edwin Groothuis via the GNATS Auto Assign Tool
edwin@FreeBSD.org
Comment 2 Edwin Groothuis freebsd_committer freebsd_triage 2011-04-07 12:10:20 UTC
State Changed
From-To: open->feedback

Awaiting maintainers feedback (via the GNATS Auto Assign Tool)
Comment 3 Douglas Thrift 2011-04-08 03:21:31 UTC
On 4/7/2011 4:10 AM, Edwin Groothuis wrote:
> Maintainer of net/isc-dhcp41-server,
> 
> Please note that PR ports/156246 has just been submitted.
> 
> If it contains a patch for an upgrade, an enhancement or a bug fix
> you agree on, reply to this email stating that you approve the patch
> and a committer will take care of it.
> 
> The full text of the PR can be found at:
>     http://www.freebsd.org/cgi/query-pr.cgi?pr=ports/156246
> 

Hello,

I was already working on this update and I have attached my patch that
should be applied instead.

Thanks!
-- 
Douglas William Thrift
<douglas@douglasthrift.net>
<http://douglasthrift.net/>
Comment 4 Wesley Shields freebsd_committer freebsd_triage 2011-04-08 14:32:24 UTC
Responsible Changed
From-To: freebsd-ports-bugs->wxs

I'll take it.
Comment 5 Douglas Thrift 2011-04-10 06:00:02 UTC
I've attached a patch for the VuXML port which describes this CVE.
-- 
Douglas William Thrift
<douglas@douglasthrift.net>
<http://douglasthrift.net/>
Comment 6 dfilter service freebsd_committer freebsd_triage 2011-04-10 22:39:46 UTC
wxs         2011-04-10 21:39:37 UTC

  FreeBSD ports repository

  Modified files:
    security/vuxml       vuln.xml 
  Log:
  Document isc-dhcp41-client and isc-dhcp31-client vulnerabilities.
  
  PR:             ports/156246
  Submitted by:   Douglas Thrift <douglas@douglasthrift.net>
  
  Revision  Changes    Path
  1.2340    +35 -1     ports/security/vuxml/vuln.xml
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 7 dfilter service freebsd_committer freebsd_triage 2011-04-10 22:41:03 UTC
wxs         2011-04-10 21:40:52 UTC

  FreeBSD ports repository

  Modified files:
    net/isc-dhcp41-server Makefile distinfo 
  Log:
  Update to the latest ESV release to address security vulnerability.
  
  PR:             ports/156246
  Submitted by:   Douglas Thrift <douglas@douglasthrift.net>
  Security:       7e69f00d-632a-11e0-9f3a-001d092480a4
  
  Revision  Changes    Path
  1.19      +12 -9     ports/net/isc-dhcp41-server/Makefile
  1.6       +2 -2      ports/net/isc-dhcp41-server/distinfo
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 8 Wesley Shields freebsd_committer freebsd_triage 2011-04-10 22:46:16 UTC
State Changed
From-To: feedback->closed

Committed, with minor changes. Thanks!