![]() |
Samba 4
|
Samba has just been updated to 4.1.11 according to the latest ChangeLog and security advisories.
|
OpenSSL has been updated to 1.0.1i and 0.9.8zb. They build fine under -current.
https://www.openssl.org/news/secadv_20140806.txt |
OpenSSL packages updated according to the latest ChangeLog.
|
Update 20140906
--mancha |
Quote:
Mats |
2.20 has just been tagged in git, so I wouldn't bother rebuilding 2.19 for current. Decision is with Pat of course, but I expect 2.20 will turn up in current before too long.
If you don't want to wait though, the fix for 0475 appears to have been applied to release/2.19/master 2 days ago: https://sourceware.org/git/?p=glibc....0bd971de4aa163 Personally, if I were going to rebuild, I'd be inclined to just pull release/2.19/master and get all the other (non-security) fixes as well. |
when you upgrade subversion 1.7.18, you might need to upgrade neon as well to latest 0.30.0 however I think there is typo in ./src/ne_openssl.c
for people disabled sslv2 Code:
--- ./src/ne_openssl.c.orig 2013-07-26 12:15:19.000000000 -0400 |
Quote:
cleanly because it only patches long-standing code). However, my patches have source attribution in their headers and in the case of glibc patches I list the upstream commits I used to construct them. By the way, glibc 2.20 (sig), which includes those fixes, was released today. Quote:
you need to update neon or rebuild Slackware 14.1's neon 0.29.6 after applying neon-0.29_disable-SSLv2.diff. --mancha |
Quote:
Mats |
Update 20140909
|
Update 20140910
--mancha |
Mancha, I went to try your two proof of concepts from here. I run them both, the one for CVE-2012-4412 gives me a segmentation fault and the second one works (in a few seconds I get an overflow).
|
And I am not being able to rebuild glibc. I got messages like this a few times:
Code:
patching file posix/tst-spawn.c This is my glibc.SlackBuild http://paste.debian.net/120456/ |
Quote:
Code:
# CVE-2014-4043 Once you re-build and install glibc, if those PoCs run for at least 5 minutes with no errors you're no longer vulnerable. --mancha |
All times are GMT -5. The time now is 10:58 PM. |