buildroot/package/busybox
Quentin Schulz cb419c8b3c package/busybox: fix CVE-2022-28391
The patches have been used by Alpine for 5 months now and they were
posted on the Busybox mailing list mid-July with no review or comment.

According to Ariadne Conill[1] - though NVD CVSS 3.x Base Score seems to
disagree - this has a low security impact so we could probably just wait
for upstream to merge the patches or implement it the way they want.

Considering those patches have been public for 5 months and upstream
hasn't acted until now, let's take the patches from the mailing list
anyway as there's no indication the CVEs will be fixed upstream soon.

[1] https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661

Cc: Quentin Schulz <foss+buildroot@0leil.net>
Signed-off-by: Quentin Schulz <quentin.schulz@theobroma-systems.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
(cherry picked from commit 4a03d17172)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2022-09-29 22:06:40 +02:00
..
0001-networking-libiproute-use-linux-if_packet.h-instead-.patch package/busybox: bump version to 1.34.0 2021-09-22 23:03:53 +02:00
0002-Makefile.flags-strip-non-l-arguments-returned-by-pkg.patch package/busybox: bump version to 1.34.0 2021-09-22 23:03:53 +02:00
0003-awk-fix-use-after-free-CVE-2022-30065.patch package/busybox: fix CVE-2022-30065 2022-09-29 17:29:08 +02:00
0004-libbb-sockaddr2str-ensure-only-printable-characters-.patch package/busybox: fix CVE-2022-28391 2022-09-29 22:06:40 +02:00
0005-nslookup-sanitize-all-printed-strings-with-printable.patch package/busybox: fix CVE-2022-28391 2022-09-29 22:06:40 +02:00
Config.in
S01syslogd
S02klogd
S02sysctl
S10mdev
S15watchdog
S50telnet
busybox-minimal.config package/busybox: fix udhcpc options in minimal config 2022-03-31 08:25:36 +02:00
busybox.config package/busybox: bump version to 1.35.0 2022-02-12 15:24:55 +01:00
busybox.hash package/busybox: bump version to 1.35.0 2022-02-12 15:24:55 +01:00
busybox.mk package/busybox: fix CVE-2022-28391 2022-09-29 22:06:40 +02:00
inittab skeleton + init: prepare /run/lock and adjust compat symlinks 2022-01-09 11:28:56 +01:00
mdev.conf
telnetd.service
udhcpc.script