Page MenuHomeFreeBSD

net/libutp: pull Transmission's fix for CVE-2012-6129
AbandonedPublic

Authored by jbeich on Jan 22 2015, 4:48 AM.
Tags
None
Referenced Files
Unknown Object (File)
Wed, Apr 3, 8:32 PM
Unknown Object (File)
Wed, Apr 3, 8:31 PM
Unknown Object (File)
Mar 15 2024, 4:07 AM
Unknown Object (File)
Mar 2 2024, 4:37 PM
Unknown Object (File)
Feb 19 2024, 10:07 PM
Unknown Object (File)
Jan 2 2024, 1:06 AM
Unknown Object (File)
Dec 23 2023, 9:23 AM
Unknown Object (File)
Dec 9 2023, 7:59 AM
Subscribers
None

Details

Reviewers
bapt
Summary

Pull Transmisson's fix for stack-based buffer overflow in libutp

Also fixed upstream but due to breaking API changes net/libutp update
is delayed until consumers adapt, or at least net-p2p/transmission-*.

PR: 196351
Obtained from: https://trac.transmissionbt.com/changeset/13646/
Approved by: bapt (mentor)
Approved by: mi (maintainer)
MFH: 2014Q4
MFH: 2015Q1
Security: CVE-2012-6129
Security: 0523fb7e-8444-4e86-812d-8de05f6f0dce

/branches/2014Q4 and /branches/2015Q1 want the fix becasue
Transmission there uses system libutp, see rP369657.

Test Plan

Run Transmission for a while with uTP enabled.

Diff Detail

Repository
rP FreeBSD ports repository
Lint
No Lint Coverage
Unit
No Test Coverage

Event Timeline

jbeich retitled this revision from to net/libutp: pull Transmission's fix for CVE-2012-6129.
jbeich updated this object.
jbeich edited the test plan for this revision. (Show Details)
jbeich added a reviewer: bapt.
bapt requested changes to this revision.Jan 22 2015, 12:55 PM
bapt edited edge metadata.

You will need to bump port revision as well

This revision now requires changes to proceed.Jan 22 2015, 12:55 PM

Closed by commit rP377674 (authored by @mi).