mirror of
https://git.yoctoproject.org/poky
synced 2026-09-29 07:36:20 +02:00
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors. https://nvd.nist.gov/vuln/detail/CVE-2022-28391 Backported from kirkstone 3e17df4cd17c132dc7732ebd3d1c80c81c85bcc4. 2nd patch adjusted to apply on 1.31.1. (From OE-Core rev: 0b9cbcc4ceac3938afd1dd6010ce6d9a3da21598) Signed-off-by: Steve Sakoman <steve@sakoman.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com> Signed-off-by: Steve Sakoman <steve@sakoman.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
65 lines
3.0 KiB
BlitzBasic
65 lines
3.0 KiB
BlitzBasic
require busybox.inc
|
|
|
|
SRC_URI = "https://busybox.net/downloads/busybox-${PV}.tar.bz2;name=tarball \
|
|
file://busybox-udhcpc-no_deconfig.patch \
|
|
file://find-touchscreen.sh \
|
|
file://busybox-cron \
|
|
file://busybox-httpd \
|
|
file://busybox-udhcpd \
|
|
file://default.script \
|
|
file://simple.script \
|
|
file://hwclock.sh \
|
|
file://syslog \
|
|
file://syslog-startup.conf \
|
|
file://syslog.conf \
|
|
file://busybox-syslog.default \
|
|
file://mdev \
|
|
file://mdev.conf \
|
|
file://mdev-mount.sh \
|
|
file://defconfig \
|
|
file://busybox-syslog.service.in \
|
|
file://busybox-klogd.service.in \
|
|
file://fail_on_no_media.patch \
|
|
file://run-ptest \
|
|
file://inetd.conf \
|
|
file://inetd \
|
|
file://login-utilities.cfg \
|
|
file://recognize_connmand.patch \
|
|
file://busybox-cross-menuconfig.patch \
|
|
file://0001-Use-CC-when-linking-instead-of-LD-and-use-CFLAGS-and.patch \
|
|
file://mount-via-label.cfg \
|
|
file://sha1sum.cfg \
|
|
file://sha256sum.cfg \
|
|
file://getopts.cfg \
|
|
file://resize.cfg \
|
|
${@["", "file://init.cfg"][(d.getVar('VIRTUAL-RUNTIME_init_manager') == 'busybox')]} \
|
|
${@["", "file://mdev.cfg"][(d.getVar('VIRTUAL-RUNTIME_dev_manager') == 'busybox-mdev')]} \
|
|
file://syslog.cfg \
|
|
file://unicode.cfg \
|
|
file://rcS \
|
|
file://rcK \
|
|
file://makefile-libbb-race.patch \
|
|
file://0001-testsuite-check-uudecode-before-using-it.patch \
|
|
file://0001-testsuite-use-www.example.org-for-wget-test-cases.patch \
|
|
file://0001-du-l-works-fix-to-use-145-instead-of-144.patch \
|
|
file://0001-date-Use-64-prefix-syscall-if-we-have-to.patch \
|
|
file://0001-time-Use-64-prefix-syscall-if-we-have-to.patch \
|
|
file://0003-runsv-Use-64-prefix-syscall-if-we-have-to.patch \
|
|
file://0001-Remove-syscall-wrappers-around-clock_gettime-closes-.patch \
|
|
file://0001-Remove-stime-function-calls.patch \
|
|
file://0001-sysctl-ignore-EIO-of-stable_secret-below-proc-sys-ne.patch \
|
|
file://busybox-CVE-2018-1000500.patch \
|
|
file://0001-hwclock-make-glibc-2.31-compatible.patch \
|
|
file://0001-decompress_gunzip-Fix-DoS-if-gzip-is-corrupt.patch \
|
|
file://0001-mktemp-add-tmpdir-option.patch \
|
|
file://CVE-2021-42374.patch \
|
|
file://CVE-2021-42376.patch \
|
|
file://CVE-2021-423xx-awk.patch \
|
|
file://0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch \
|
|
file://0002-nslookup-sanitize-all-printed-strings-with-printable.patch \
|
|
"
|
|
SRC_URI_append_libc-musl = " file://musl.cfg "
|
|
|
|
SRC_URI[tarball.md5sum] = "70913edaf2263a157393af07565c17f0"
|
|
SRC_URI[tarball.sha256sum] = "d0f940a72f648943c1f2211e0e3117387c31d765137d92bd8284a3fb9752a998"
|