From: bugzilla at busybox.net <bugzilla@busybox.net>
To: buildroot@busybox.net
Subject: [Buildroot] [Bug 145] New: Bump bind package to 9.5.1-P1 (security)
Date: Thu, 5 Mar 2009 11:52:16 +0000 (UTC) [thread overview]
Message-ID: <bug-145-163@https.bugs.busybox.net/> (raw)
https://bugs.busybox.net/show_bug.cgi?id=145
Host: i686-linux
Target: arm-softfloat-linux-uclibcgnueabi
Summary: Bump bind package to 9.5.1-P1 (security)
Product: buildroot
Version: unspecified
Platform: PC
OS/Version: Linux
Status: NEW
Severity: major
Priority: P5
Component: Outdated package
AssignedTo: unassigned at buildroot.uclibc.org
ReportedBy: gustavo at zacarias.com.ar
CC: buildroot at uclibc.org
Estimated Hours: 0.0
Created an attachment (id=105)
--> (https://bugs.busybox.net/attachment.cgi?id=105)
Bump bind package to 9.5.1-P1 and migrate to Makefile.autotools.in
Current bind package is version 9.3.2 which is from the 9.3 branch and is
EOLed.
It has many security bugs probably fixed in 9.3.6-P1 but since it won't be
supported for long it's probably metter to move on to a supported branch.
CVE-2009-0025, CVE-2008-1447, CVE-2008-0122, CVE-2007-2926 and probably more.
While at it migrate to Makefile.autotools.in too.
Also introduced an option for/not to install userland tools (dig, host,
nslookup, nsupdate).
Some initscripts (like the one used by bind) aren't too nice or people may want
to use their own initscripts, is it worth considering introducing an option in
buildroot so that packages don't install their initscripts?
--
Configure bugmail: https://bugs.busybox.net/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
next reply other threads:[~2009-03-05 11:52 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-03-05 11:52 bugzilla at busybox.net [this message]
2009-03-05 11:55 ` [Buildroot] [Bug 145] Bump bind package to 9.5.1-P1 (security) bugzilla at busybox.net
2009-03-05 12:13 ` bugzilla at busybox.net
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=bug-145-163@https.bugs.busybox.net/ \
--to=bugzilla@busybox.net \
--cc=buildroot@busybox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox