[Buildroot] [PATCH 6/8] package/rpm: security bump to 4.14.2.1

Fabrice Fontaine fontaine.fabrice at gmail.com
Fri Mar 29 07:40:24 UTC 2019


Hello Thomas,

Le ven. 29 mars 2019 à 08:34, Thomas Petazzoni
<thomas.petazzoni at bootlin.com> a écrit :
>
> On Thu, 28 Mar 2019 21:28:52 +0100
> Fabrice Fontaine <fontaine.fabrice at gmail.com> wrote:
>
> > - Remove first and second patches (already in version)
> > - Remove third and fourth patches (not needed since:
> >   https://github.com/rpm-software-management/rpm/commit/245b5a3b4b6d616adf47361137987e90f8dab22c)
> > - Add hash for license file
> > - Drop autoreconf (as configure.ac is not patched anymore)
> > - Use new --with-crypto option
> > - Restrict symlink following on installation (CVE-2017-7500,
> >   CVE-2017-7501)
> >
> > Signed-off-by: Fabrice Fontaine <fontaine.fabrice at gmail.com>
>
> Can this be applied as PATCH 1/8 ? Indeed, we will want this security
> bump in the LTS release, but not all the patches before it.
>
> Ideally, this patch should be first in the series.
OK, I'll send a v2 with this patch as 1/8. I'll also tune 7/8 to add a
configuration option for the crypto library.
>
> Thomas
> --
> Thomas Petazzoni, CTO, Bootlin
> Embedded Linux and Kernel engineering
> https://bootlin.com
Best Regards,

Fabrice



More information about the buildroot mailing list