Summary: | dns/powerdns: Upgrade to recent version (v4.0.2) - current(4.0.1) has critical vulnerabilities | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | Ports & Packages | Reporter: | Dani I. <i.dani> | ||||||
Component: | Individual Port(s) | Assignee: | Jason Unovitch <junovitch> | ||||||
Status: | Closed FIXED | ||||||||
Severity: | Affects Many People | CC: | ghostonthewire, junovitch, ports-secteam, tremere | ||||||
Priority: | --- | Keywords: | patch, patch-ready, security | ||||||
Version: | Latest | Flags: | tremere:
maintainer-feedback+
junovitch: merge-quarterly+ |
||||||
Hardware: | Any | ||||||||
OS: | Any | ||||||||
Attachments: |
|
Description
Dani I.
2017-01-16 10:22:27 UTC
Created attachment 178967 [details] dns/powerdns: Update to version 4.0.2 dns/powerdns: Update to version 4.0.2 - Bump version to 4.0.2 - patch-libressl is no longer needed [^1] Has been built successfully on following versions with all possible port options set: 10.2-RELEASE-p28/amd64 10.2-RELEASE-p28/i386 10.3-RELEASE-p15/amd64 10.3-RELEASE-p15/i386 11.0-RELEASE-p6/amd64 11.0-RELEASE-p6/i386 Full poudriere logs - https://gist.github.com/3afc69cb8985c71ab3d76fd503ed8984 [^1]: https://github.com/PowerDNS/pdns/commit/115f658 Looks good to me. Can be committed Created attachment 178991 [details]
Update to 4.0.3
This patch replaces the previous one.
Also replaced CXXFLAGS and LDFLAGS with USES=localbase:ldflags
A commit references this bug: Author: junovitch Date: Wed Jan 18 11:22:48 UTC 2017 New revision: 431785 URL: https://svnweb.freebsd.org/changeset/ports/431785 Log: Document mulitiple PowerDNS vulnerabilities PR: 216135 PR: 216136 Reported by: Dani <i.dani@outlook.com> Security: CVE-2016-2120 Security: CVE-2016-7068 Security: CVE-2016-7072 Security: CVE-2016-7073 Security: CVE-2016-7074 Security: https://vuxml.FreeBSD.org/freebsd/e3200958-dd6c-11e6-ae1b-002590263bf5.html Changes: head/security/vuxml/vuln.xml A commit references this bug: Author: junovitch Date: Wed Jan 18 11:23:11 UTC 2017 New revision: 431786 URL: https://svnweb.freebsd.org/changeset/ports/431786 Log: dns/powerdns: update 4.0.1 -> 4.0.3 - Switch to USES=localbase while here - Remove LibreSSL patch (see https://github.com/PowerDNS/pdns/pull/4310) Changes: https://doc.powerdns.com/md/changelog/#powerdns-authoritative-server-402 https://doc.powerdns.com/md/changelog/#powerdns-authoritative-server-403 PR: 216136 Reported by: Dani <i.dani@outlook.com> Submitted by: ghostonthewire@gmail.com (original 4.0.2 patch) Approved by: Ralf van der Enden <tremere@cainites.net> (maintainer) Security: CVE-2016-2120 Security: CVE-2016-7068 Security: CVE-2016-7072 Security: CVE-2016-7073 Security: CVE-2016-7074 Security: https://vuxml.FreeBSD.org/freebsd/e3200958-dd6c-11e6-ae1b-002590263bf5.html MFH: 2017Q1 Changes: head/dns/powerdns/Makefile head/dns/powerdns/distinfo head/dns/powerdns/files/patch-libressl A commit references this bug: Author: junovitch Date: Wed Jan 18 11:23:59 UTC 2017 New revision: 431787 URL: https://svnweb.freebsd.org/changeset/ports/431787 Log: MFH: r431786 dns/powerdns: update 4.0.1 -> 4.0.3 - Switch to USES=localbase while here - Remove LibreSSL patch (see https://github.com/PowerDNS/pdns/pull/4310) Changes: https://doc.powerdns.com/md/changelog/#powerdns-authoritative-server-402 https://doc.powerdns.com/md/changelog/#powerdns-authoritative-server-403 PR: 216136 Reported by: Dani <i.dani@outlook.com> Submitted by: ghostonthewire@gmail.com (original 4.0.2 patch) Approved by: Ralf van der Enden <tremere@cainites.net> (maintainer) Approved by: ports-secteam (with hat) Security: CVE-2016-2120 Security: CVE-2016-7068 Security: CVE-2016-7072 Security: CVE-2016-7073 Security: CVE-2016-7074 Security: https://vuxml.FreeBSD.org/freebsd/e3200958-dd6c-11e6-ae1b-002590263bf5.html Changes: _U branches/2017Q1/ branches/2017Q1/dns/powerdns/Makefile branches/2017Q1/dns/powerdns/distinfo branches/2017Q1/dns/powerdns/files/patch-libressl To all involved for the initial report, the patch, and the maintainer approval; thanks! |