Github messages for voidlinux
 help / color / mirror / Atom feed
From: Sigmw <Sigmw@users.noreply.github.com>
To: ml@inbox.vuxu.org
Subject: Re: [PR PATCH] [Closed]:  busybox: add patches for CVE-2022-28391
Date: Wed, 17 Aug 2022 01:24:28 +0200	[thread overview]
Message-ID: <20220816232428.YIOD3MsHZFOXJvor_oZ4iE79Faci_LYoWf08KkH2bhU@z> (raw)
In-Reply-To: <gh-mailinglist-notifications-41a7ca26-5023-4802-975b-f1789d68868e-void-packages-38722@inbox.vuxu.org>

[-- Attachment #1: Type: text/plain, Size: 1571 bytes --]

There's a closed pull request on the void-packages repository

 busybox: add patches for CVE-2022-28391
https://github.com/void-linux/void-packages/pull/38722

Description:
<!-- Uncomment relevant sections and delete options which are not applicable -->

#### Testing the changes
- I tested the changes in this PR: **YES**
- This two patches are not upstream, made by Alpine Linux Team, but they are reported in https://bugs.busybox.net/show_bug.cgi?id=14811
- Source: https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch
- Source:  https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch
- Check CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28391
<!--
#### New package
- This new package conforms to the [package requirements](https://github.com/void-linux/void-packages/blob/master/CONTRIBUTING.md#package-requirements): **YES**|**NO**
-->

<!-- Note: If the build is likely to take more than 2 hours, please add ci skip tag as described in
https://github.com/void-linux/void-packages/blob/master/CONTRIBUTING.md#continuous-integration
and test at least one native build and, if supported, at least one cross build.
Ignore this section if this PR is not skipping CI.
-->
<!--
#### Local build testing
- I built this PR locally for my native architecture, (ARCH-LIBC)
- I built this PR locally for these architectures (if supported. mark crossbuilds):
  - aarch64-musl
  - armv7l
  - armv6l-musl
-->


  parent reply	other threads:[~2022-08-16 23:24 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-08-16 18:58 [PR PATCH] busybox: applied CVE-2022-28391 fix patches Sigmw
2022-08-16 19:09 ` [PR PATCH] [Updated] " Sigmw
2022-08-16 19:10 ` [PR PATCH] [Updated] busybox: revbump and added patches for CVE-2022-28391 Sigmw
2022-08-16 19:47 ` Sigmw
2022-08-16 20:38 ` CameronNemo
2022-08-16 20:38 ` [PR REVIEW] " CameronNemo
2022-08-16 20:40 ` Sigmw
2022-08-16 20:40 ` Sigmw
2022-08-16 21:06 ` [PR REVIEW] " CameronNemo
2022-08-16 21:07 ` CameronNemo
2022-08-16 22:28 ` [PR PATCH] [Updated] " Sigmw
2022-08-16 22:28 ` Sigmw
2022-08-16 22:29 ` [PR REVIEW] " Sigmw
2022-08-16 22:29 ` Sigmw
2022-08-16 22:49 ` busybox: add " CameronNemo
2022-08-16 23:24 ` Sigmw
2022-08-16 23:24 ` Sigmw [this message]
2022-08-16 23:25 ` Sigmw
2022-08-17  0:45 ` CameronNemo
2022-08-18  3:27 ` [PR PATCH] [Merged]: " classabbyamp

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20220816232428.YIOD3MsHZFOXJvor_oZ4iE79Faci_LYoWf08KkH2bhU@z \
    --to=sigmw@users.noreply.github.com \
    --cc=ml@inbox.vuxu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).