Bug 138415 - [MAINTAINER] dns/dnsmasq: SECURITY update to 2.50
Summary: [MAINTAINER] dns/dnsmasq: SECURITY update to 2.50
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Martin Wilke
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2009-08-31 20:00 UTC by Matthias Andree
Modified: 2009-09-02 17:14 UTC (History)
0 users

See Also:


Attachments
dnsmasq-2.50.patch (1.12 KB, patch)
2009-08-31 20:00 UTC, Matthias Andree
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Matthias Andree 2009-08-31 20:00:13 UTC
- Update to 2.50, complete changelog:
            Fix security problem which allowed any host permitted to
            do TFTP to possibly compromise dnsmasq by remote buffer
            overflow when TFTP enabled. Thanks to Core Security
            Technologies and Iván Arce, Pablo Hernán Jorge, Alejandro
            Pablo Rodriguez, Martín Coco, Alberto Soliño Testa and
            Pablo Annetta. This problem has Bugtraq id: 36121
            and CVE: 2009-2957
 
            Fix a problem which allowed a malicious TFTP client to
            crash dnsmasq. Thanks to Steve Grubb at Red Hat for
            spotting this. This problem has Bugtraq id: 36120 and
            CVE: 2009-2958

Generated with FreeBSD Port Tools 0.77
Comment 1 Martin Wilke freebsd_committer freebsd_triage 2009-08-31 20:20:17 UTC
Responsible Changed
From-To: freebsd-ports-bugs->miwi

I'll take it.
Comment 2 dfilter service freebsd_committer freebsd_triage 2009-09-02 13:18:24 UTC
miwi        2009-09-02 12:18:10 UTC

  FreeBSD ports repository

  Modified files:
    dns/dnsmasq          Makefile distinfo 
  Log:
  - Update to 2.50
  
  PR:             138415
  Submitted by:   Matthias Andree <matthias.andree@gmx.de> (maintainer)
  Security:       http://www.freebsd.org/ports/portaudit/80aa98e0-97b4-11de-b946-0030843d3802.html
  
  Revision  Changes    Path
  1.56      +1 -2      ports/dns/dnsmasq/Makefile
  1.40      +3 -3      ports/dns/dnsmasq/distinfo
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 3 Martin Wilke freebsd_committer freebsd_triage 2009-09-02 17:14:52 UTC
State Changed
From-To: open->closed

Committed. Thanks!