diff options
author | Patrick J Volkerding <volkerdi@slackware.com> | 2019-07-05 20:08:13 +0000 |
---|---|---|
committer | Eric Hameleers <alien@slackware.com> | 2019-07-06 08:59:49 +0200 |
commit | a4d0dd1f5db5958cdad3256093994939333afec2 (patch) | |
tree | 8f5b051558b83bcc4c0403438659028340de43f6 /source/a/grub/0001-Fix-CVE-2015-8370-Grub2-user-pass-vulnerability.patch | |
parent | 3a97b5c90345b5a4a0ee4e9df0a88a9b57dfb3f5 (diff) | |
download | current-a4d0dd1f5db5958cdad3256093994939333afec2.tar.gz current-a4d0dd1f5db5958cdad3256093994939333afec2.tar.xz |
Fri Jul 5 20:08:13 UTC 201920190705200813
a/grub-2.04-x86_64-1.txz: Upgraded.
ap/mariadb-10.4.6-x86_64-2.txz: Rebuilt.
Patched mysql_install_db to comment out PAM related setup.
Thanks to Labinnah.
l/argon2-20190702-x86_64-2.txz: Rebuilt.
Fixed library install path. Thanks to phenixia2003.
l/imagemagick-6.9.10_52-x86_64-1.txz: Upgraded.
n/ModemManager-1.10.4-x86_64-1.txz: Upgraded.
x/libdrm-2.4.99-x86_64-1.txz: Upgraded.
x/libinput-1.13.4-x86_64-1.txz: Upgraded.
isolinux/efiboot.img: Rebuilt.
Diffstat (limited to 'source/a/grub/0001-Fix-CVE-2015-8370-Grub2-user-pass-vulnerability.patch')
-rw-r--r-- | source/a/grub/0001-Fix-CVE-2015-8370-Grub2-user-pass-vulnerability.patch | 45 |
1 files changed, 0 insertions, 45 deletions
diff --git a/source/a/grub/0001-Fix-CVE-2015-8370-Grub2-user-pass-vulnerability.patch b/source/a/grub/0001-Fix-CVE-2015-8370-Grub2-user-pass-vulnerability.patch deleted file mode 100644 index 5701b5475..000000000 --- a/source/a/grub/0001-Fix-CVE-2015-8370-Grub2-user-pass-vulnerability.patch +++ /dev/null @@ -1,45 +0,0 @@ -From 88c9657960a6c5d3673a25c266781e876c181add Mon Sep 17 00:00:00 2001 -From: Hector Marco-Gisbert <hecmargi@upv.es> -Date: Fri, 13 Nov 2015 16:21:09 +0100 -Subject: [PATCH] Fix security issue when reading username and password - - This patch fixes two integer underflows at: - * grub-core/lib/crypto.c - * grub-core/normal/auth.c - -Signed-off-by: Hector Marco-Gisbert <hecmargi@upv.es> -Signed-off-by: Ismael Ripoll-Ripoll <iripoll@disca.upv.es> ---- - grub-core/lib/crypto.c | 2 +- - grub-core/normal/auth.c | 2 +- - 2 files changed, 2 insertions(+), 2 deletions(-) - -diff --git a/grub-core/lib/crypto.c b/grub-core/lib/crypto.c -index 010e550..524a3d8 100644 ---- a/grub-core/lib/crypto.c -+++ b/grub-core/lib/crypto.c -@@ -468,7 +468,7 @@ grub_password_get (char buf[], unsigned buf_size) - break; - } - -- if (key == '\b') -+ if (key == '\b' && cur_len) - { - cur_len--; - continue; -diff --git a/grub-core/normal/auth.c b/grub-core/normal/auth.c -index c6bd96e..5782ec5 100644 ---- a/grub-core/normal/auth.c -+++ b/grub-core/normal/auth.c -@@ -172,7 +172,7 @@ grub_username_get (char buf[], unsigned buf_size) - break; - } - -- if (key == '\b') -+ if (key == '\b' && cur_len) - { - cur_len--; - grub_printf ("\b"); --- -1.9.1 - |