zeromq: security bump to version 4.0.5
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Tue, 11 Nov 2014 20:29:15 +0000 (17:29 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 11 Nov 2014 21:25:28 +0000 (22:25 +0100)
Fixes:
CVE-2014-7202 - stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5
before 4.0.5 allows man-in-the-middle attackers to conduct downgrade
attacks via a crafted connection request.
CVE-2014-7203 - libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not
ensure that nonces are unique, which allows man-in-the-middle attackers
to conduct replay attacks via unspecified vectors.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/zeromq/0001-tests-disable-test_fork-if-fork-is-not-available.patch [new file with mode: 0644]
package/zeromq/zeromq-0001-tests-disable-test_fork-if-fork-is-not-available.patch [deleted file]
package/zeromq/zeromq.hash [new file with mode: 0644]
package/zeromq/zeromq.mk

diff --git a/package/zeromq/0001-tests-disable-test_fork-if-fork-is-not-available.patch b/package/zeromq/0001-tests-disable-test_fork-if-fork-is-not-available.patch
new file mode 100644 (file)
index 0000000..1eefdc3
--- /dev/null
@@ -0,0 +1,52 @@
+From b50912f2eecec1ea7accc155f8132116f8702075 Mon Sep 17 00:00:00 2001
+From: Samuel Martin <s.martin49@gmail.com>
+Date: Sat, 3 May 2014 12:22:38 +0200
+Subject: [PATCH] tests: disable test_fork if fork() is not available
+
+Signed-off-by: Samuel Martin <s.martin49@gmail.com>
+---
+ configure.ac      | 1 +
+ tests/Makefile.am | 8 ++++++--
+ tests/Makefile.in | 8 ++++----
+ 3 files changed, 11 insertions(+), 6 deletions(-)
+
+diff --git a/configure.ac b/configure.ac
+index 0c41604..8f8521c 100644
+--- a/configure.ac
++++ b/configure.ac
+@@ -431,6 +431,7 @@ AM_CONDITIONAL(BUILD_PGM, test "x$libzmq_pgm_ext" = "xyes")
+ AM_CONDITIONAL(ON_MINGW, test "x$libzmq_on_mingw32" = "xyes")
+ AM_CONDITIONAL(ON_ANDROID, test "x$libzmq_on_android" = "xyes")
+ AM_CONDITIONAL(ON_LINUX, test "x$libzmq_on_linux" = "xyes")
++AM_CONDITIONAL(HAVE_FORK, test "x$ac_cv_func_fork" = "xyes")
+ # Checks for library functions.
+ AC_TYPE_SIGNAL
+diff --git a/tests/Makefile.am b/tests/Makefile.am
+index 0cfe4e8..2a1e257 100644
+--- a/tests/Makefile.am
++++ b/tests/Makefile.am
+@@ -46,8 +46,10 @@ if !ON_MINGW
+ noinst_PROGRAMS += test_shutdown_stress \
+                    test_pair_ipc \
+                    test_reqrep_ipc \
+-                   test_timeo \
+-                   test_fork
++                   test_timeo
++if HAVE_FORK
++noinst_PROGRAMS += test_fork
++endif
+ endif
+ test_system_SOURCES = test_system.cpp
+@@ -93,8 +95,10 @@ test_shutdown_stress_SOURCES = test_shutdown_stress.cpp
+ test_pair_ipc_SOURCES = test_pair_ipc.cpp testutil.hpp
+ test_reqrep_ipc_SOURCES = test_reqrep_ipc.cpp testutil.hpp
+ test_timeo_SOURCES = test_timeo.cpp
++if HAVE_FORK
+ test_fork_SOURCES = test_fork.cpp
+ endif
++endif
+ #  Run the test cases
+ TESTS = $(noinst_PROGRAMS)
diff --git a/package/zeromq/zeromq-0001-tests-disable-test_fork-if-fork-is-not-available.patch b/package/zeromq/zeromq-0001-tests-disable-test_fork-if-fork-is-not-available.patch
deleted file mode 100644 (file)
index 1eefdc3..0000000
+++ /dev/null
@@ -1,52 +0,0 @@
-From b50912f2eecec1ea7accc155f8132116f8702075 Mon Sep 17 00:00:00 2001
-From: Samuel Martin <s.martin49@gmail.com>
-Date: Sat, 3 May 2014 12:22:38 +0200
-Subject: [PATCH] tests: disable test_fork if fork() is not available
-
-Signed-off-by: Samuel Martin <s.martin49@gmail.com>
----
- configure.ac      | 1 +
- tests/Makefile.am | 8 ++++++--
- tests/Makefile.in | 8 ++++----
- 3 files changed, 11 insertions(+), 6 deletions(-)
-
-diff --git a/configure.ac b/configure.ac
-index 0c41604..8f8521c 100644
---- a/configure.ac
-+++ b/configure.ac
-@@ -431,6 +431,7 @@ AM_CONDITIONAL(BUILD_PGM, test "x$libzmq_pgm_ext" = "xyes")
- AM_CONDITIONAL(ON_MINGW, test "x$libzmq_on_mingw32" = "xyes")
- AM_CONDITIONAL(ON_ANDROID, test "x$libzmq_on_android" = "xyes")
- AM_CONDITIONAL(ON_LINUX, test "x$libzmq_on_linux" = "xyes")
-+AM_CONDITIONAL(HAVE_FORK, test "x$ac_cv_func_fork" = "xyes")
- # Checks for library functions.
- AC_TYPE_SIGNAL
-diff --git a/tests/Makefile.am b/tests/Makefile.am
-index 0cfe4e8..2a1e257 100644
---- a/tests/Makefile.am
-+++ b/tests/Makefile.am
-@@ -46,8 +46,10 @@ if !ON_MINGW
- noinst_PROGRAMS += test_shutdown_stress \
-                    test_pair_ipc \
-                    test_reqrep_ipc \
--                   test_timeo \
--                   test_fork
-+                   test_timeo
-+if HAVE_FORK
-+noinst_PROGRAMS += test_fork
-+endif
- endif
- test_system_SOURCES = test_system.cpp
-@@ -93,8 +95,10 @@ test_shutdown_stress_SOURCES = test_shutdown_stress.cpp
- test_pair_ipc_SOURCES = test_pair_ipc.cpp testutil.hpp
- test_reqrep_ipc_SOURCES = test_reqrep_ipc.cpp testutil.hpp
- test_timeo_SOURCES = test_timeo.cpp
-+if HAVE_FORK
- test_fork_SOURCES = test_fork.cpp
- endif
-+endif
- #  Run the test cases
- TESTS = $(noinst_PROGRAMS)
diff --git a/package/zeromq/zeromq.hash b/package/zeromq/zeromq.hash
new file mode 100644 (file)
index 0000000..729e7ea
--- /dev/null
@@ -0,0 +1,2 @@
+# Locally calculated from download (no sig, hash)
+sha256 3bc93c5f67370341428364ce007d448f4bb58a0eaabd0a60697d8086bc43342b        zeromq-4.0.5.tar.gz
index 59d276e89c75bf958356860bffbed81595faea63..987c65be35f470dad828550105eee7dd0f4ad94a 100644 (file)
@@ -4,12 +4,13 @@
 #
 ################################################################################
 
-ZEROMQ_VERSION = 4.0.4
+ZEROMQ_VERSION = 4.0.5
 ZEROMQ_SITE = http://download.zeromq.org
 ZEROMQ_INSTALL_STAGING = YES
 ZEROMQ_DEPENDENCIES = util-linux
 ZEROMQ_LICENSE = LGPLv3+ with exceptions
 ZEROMQ_LICENSE_FILES = COPYING COPYING.LESSER
+# For 0001-tests-disable-test_fork-if-fork-is-not-available.patch
 ZEROMQ_AUTORECONF = YES
 
 # Only tools/curve_keygen.c needs this, but it doesn't hurt to pass it