Skip to content

openocd: patch security issue#8089

Merged
neheb merged 1 commit intoopenwrt:masterfrom
ja-pa:openocd-security-fix
Apr 1, 2019
Merged

openocd: patch security issue#8089
neheb merged 1 commit intoopenwrt:masterfrom
ja-pa:openocd-security-fix

Conversation

@ja-pa
Copy link
Copy Markdown
Contributor

@ja-pa ja-pa commented Jan 31, 2019

Maintainer: @paulfertser
Compile tested: Turris Omnia (TOS4), OpenWrt 18.06.1
Run tested: Turris Omnia (TOS4), OpenWrt 18.06.1

Description:
This PR contains security patches from Debian which restrict some cross-protocol scripting attacks.
CVE info https://nvd.nist.gov/vuln/detail/CVE-2018-5704

Signed-off-by: Jan Pavlinec jan.pavlinec@nic.cz

@paulfertser
Copy link
Copy Markdown
Contributor

Thank you for the attention.

In my opinion it's worth upgrading to the current git HEAD version instead as 0.10.0 is really old now. Do you think those using OpenOCD on OpenWrt would be unhappy with that?

@neheb
Copy link
Copy Markdown
Contributor

neheb commented Apr 1, 2019

@paulfertser it's not as bad as the libimobiledevice people. Last releases were from 2014 with a still active git repository.

As far as updating to git, up to you. I do not use openocd. Please open a separate pull request if you wish to go that route.

@neheb
Copy link
Copy Markdown
Contributor

neheb commented Apr 1, 2019

@ja-pa can you add PKG_CPE_ID so uscan can track this properly?

@ja-pa
Copy link
Copy Markdown
Contributor Author

ja-pa commented Apr 1, 2019

@neheb Fixed. I updated PR with CPE id openocd:open_on-chip_debugger

@neheb
Copy link
Copy Markdown
Contributor

neheb commented Apr 1, 2019

Great.

@neheb neheb merged commit 044f27c into openwrt:master Apr 1, 2019
@ja-pa ja-pa deleted the openocd-security-fix branch May 5, 2019 07:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants