Navigation Menu

Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ppp: 2.4.7 -> 2.4.8 & CVE-2020-8597 fix #81931

Merged
merged 2 commits into from Mar 10, 2020
Merged

ppp: 2.4.7 -> 2.4.8 & CVE-2020-8597 fix #81931

merged 2 commits into from Mar 10, 2020

Conversation

andir
Copy link
Member

@andir andir commented Mar 6, 2020

Motivation for this change

This bumps to the latest upstream version, uses upstream versions of some patches and finally applies a new patch for CVE-2020-8597.

Things done
  • Tested using sandboxing (nix.useSandbox on NixOS, or option sandbox in nix.conf on non-NixOS linux)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Determined the impact on package closure size (by running nix path-info -S before and after)
  • Ensured that relevant documentation is up to date
  • Fits CONTRIBUTING.md.

This fixes a potential buffer overflow in the eap_{request,response}
functions.
@andir
Copy link
Member Author

andir commented Mar 6, 2020

@GrahamcOfBorg test pppd

@andir andir added the 9.needs: port to stable A PR needs a backport to the stable release. label Mar 6, 2020
@jtojnar jtojnar mentioned this pull request Mar 9, 2020
@fooker
Copy link
Contributor

fooker commented Mar 10, 2020

👍 Seems to work fine on a german DSL line.

@jtojnar jtojnar merged commit 9d22d1d into NixOS:master Mar 10, 2020
@jtojnar
Copy link
Contributor

jtojnar commented Mar 10, 2020

Cherry-picked as:

[release-20.03 f3fc8ac9258] ppp: 2.4.7 -> 2.4.8
 Author: Andreas Rammhold <andreas@rammhold.de>
 Date: Fri Mar 6 23:33:06 2020 +0100
 3 files changed, 21 insertions(+), 27 deletions(-)
[release-20.03 ed5fef01177] ppp: apply patch for CVE-2020-8597
 Author: Andreas Rammhold <andreas@rammhold.de>
 Date: Fri Mar 6 23:35:18 2020 +0100
 1 file changed, 5 insertions(+)

@jtojnar jtojnar removed the 9.needs: port to stable A PR needs a backport to the stable release. label Mar 10, 2020
@andir andir deleted the ppp branch March 10, 2020 20:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants