mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-01 21:23:51 -09:00
In Buildroot there are multiple way to apply patches on a package [1]
- Adding `.patch` file in the package directory.
- Define `<pkg>_PATCH` variable with the location of the patch tar.gz.
It used to download Debian patches tarball.
- Implement custom patching logic with `PRE`/`POST` patches hooks.
To make the CycloneDX SBOM generation not dependant on downloading the
packages, the two last options have the downside of not appearing on the
generated SBOM.
The heirloom-mailx package is downloading a tarball from the Debian
mirror with the `<pkg>_PATCH` method [2].
To improve the tracking of the patched vulnerabilities for the
heirloom-mailx package this commit import the patches previously
downloaded with the `_PATCH` variable in the Buildroot tree. This allows
to add the `CVE:` trailer [3] on the patches that fix vulnerabilities to
better track which patch is fixing the vulnerability.
[1] https://buildroot.org/downloads/manual/manual.html#patch-policy
[2] http://snapshot.debian.org/archive/debian/20150815T155609Z/pool/main/h/heirloom-mailx/heirloom-mailx_12.5-5.debian.tar.xz
[3] 1167d0ff3d docs/manual: mention CVE trailer
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
40 lines
1.2 KiB
Diff
40 lines
1.2 KiB
Diff
From: Hilko Bengen <bengen@debian.org>
|
|
Date: Wed, 27 Apr 2011 00:18:42 +0200
|
|
Subject: Patched out SSL2 support since it is no longer supported by OpenSSL.
|
|
|
|
Upstream: https://sources.debian.org/patches/heirloom-mailx/12.5-4/0002-Patched-out-SSL2-support-since-it-is-no-longer-suppo.patch/
|
|
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
|
|
---
|
|
mailx.1 | 2 +-
|
|
openssl.c | 4 +---
|
|
2 files changed, 2 insertions(+), 4 deletions(-)
|
|
|
|
diff --git a/mailx.1 b/mailx.1
|
|
index 417ea04..a02e430 100644
|
|
--- a/mailx.1
|
|
+++ b/mailx.1
|
|
@@ -3575,7 +3575,7 @@ Only applicable if SSL/TLS support is built using OpenSSL.
|
|
.TP
|
|
.B ssl-method
|
|
Selects a SSL/TLS protocol version;
|
|
-valid values are `ssl2', `ssl3', and `tls1'.
|
|
+valid values are `ssl3', and `tls1'.
|
|
If unset, the method is selected automatically,
|
|
if possible.
|
|
.TP
|
|
diff --git a/openssl.c b/openssl.c
|
|
index b4e33fc..44fe4e5 100644
|
|
--- a/openssl.c
|
|
+++ b/openssl.c
|
|
@@ -216,9 +216,7 @@ ssl_select_method(const char *uhp)
|
|
|
|
cp = ssl_method_string(uhp);
|
|
if (cp != NULL) {
|
|
- if (equal(cp, "ssl2"))
|
|
- method = SSLv2_client_method();
|
|
- else if (equal(cp, "ssl3"))
|
|
+ if (equal(cp, "ssl3"))
|
|
method = SSLv3_client_method();
|
|
else if (equal(cp, "tls1"))
|
|
method = TLSv1_client_method();
|