Go to file
Peter Korsgaard 91f4c9d412 php: security bump to version 7.1.7
Fixes the following security issues:

CVE-2017-7890 - Buffer over-read into uninitialized memory.  The GIF
decoding function gdImageCreateFromGifCtx in gd_gif_in.c (which can be
reached with a call to the imagecreatefromstring() function) uses
constant-sized color tables of size 3 * 256, but does not zero-out these
arrays before use.

CVE-2017-9224, CVE-2017-9226, CVE-2017-9227, CVE-2017-9228, CVE-2017-9229 -
Out-of-bonds access in oniguruma regexp library.

CVE-2017-11144 - In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before
7.1.7, the openssl extension PEM sealing code did not check the return value
of the OpenSSL sealing function, which could lead to a crash of the PHP
interpreter, related to an interpretation conflict for a negative number in
ext/openssl/openssl.c, and an OpenSSL documentation omission.

CVE-2017-11145 - In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before
7.1.7, lack of a bounds check in the date extension's timelib_meridian
parsing code could be used by attackers able to supply date strings to leak
information from the interpreter, related to an ext/date/lib/parse_date.c
out-of-bounds read affecting the php_parse_date function.

CVE-2017-11146 - In PHP through 5.6.31, 7.x through 7.0.21, and 7.1.x
through 7.1.7, lack of bounds checks in the date extension's
timelib_meridian parsing code could be used by attackers able to supply date
strings to leak information from the interpreter, related to
ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date
function.  NOTE: this vulnerability exists because of an incomplete fix for
CVE-2017-11145.

While we're at it, add a hash for the license file.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2017-07-11 21:30:52 +02:00
arch arch/arm: fix -mcpu default values for AArch64 2017-07-10 18:04:16 +02:00
board configs/qemu-xtensa: use overlay from the github repository 2017-07-09 16:58:30 +02:00
boot uboot: apply xtensa overlay 2017-07-09 17:03:45 +02:00
configs configs/qemu-xtensa: use overlay from the github repository 2017-07-09 16:58:30 +02:00
docs manual: patches are not applied for SITE_METHOD = local 2017-07-09 17:25:48 +02:00
fs fs/ext2: Add BR2_TARGET_ROOTFS_EXT2_MKFS_OPTIONS option 2017-07-09 15:35:42 +02:00
linux linux: apply xtensa overlay 2017-07-09 17:03:37 +02:00
package php: security bump to version 7.1.7 2017-07-11 21:30:52 +02:00
support support/testing: unbreak run-tests -l 2017-07-10 23:51:33 +02:00
system package/ifupdown-scripts: new package 2017-07-04 23:38:18 +02:00
toolchain toolchain-external: default BR2_TOOLCHAIN_EXTERNAL_PATH to empty 2017-07-10 18:03:13 +02:00
utils utils/brmake: print the error code of the build 2017-07-05 00:15:05 +02:00
.defconfig
.gitignore
.gitlab-ci.yml board: Add nanopi-m1 Support 2017-07-05 18:15:54 +02:00
.gitlab-ci.yml.in .gitlab-ci.yml: use the Buildroot CI image published on Docker Hub 2017-07-02 23:45:27 +02:00
CHANGES CHANGES: update with removal of $(HOST_DIR)/usr 2017-07-05 16:54:21 +02:00
Config.in Config.in: add BR2_HOST_GCC_AT_LEAST_7 2017-07-05 16:20:27 +02:00
Config.in.legacy arch/xtensa: allow specifying path to tarball file 2017-07-09 15:41:51 +02:00
COPYING
DEVELOPERS pcre2: new package 2017-07-09 18:13:39 +02:00
Makefile Makefile: properly create $(HOST_DIR)/usr compatibility symlink 2017-07-10 17:45:57 +02:00
Makefile.legacy Remove BR2_DEPRECATED 2016-10-15 23:14:45 +02:00
README

Buildroot is a simple, efficient and easy-to-use tool to generate embedded
Linux systems through cross-compilation.

The documentation can be found in docs/manual. You can generate a text
document with 'make manual-text' and read output/docs/manual/manual.text.
Online documentation can be found at http://buildroot.org/docs.html

To build and use the buildroot stuff, do the following:

1) run 'make menuconfig'
2) select the target architecture and the packages you wish to compile
3) run 'make'
4) wait while it compiles
5) find the kernel, bootloader, root filesystem, etc. in output/images

You do not need to be root to build or run buildroot.  Have fun!

Buildroot comes with a basic configuration for a number of boards. Run
'make list-defconfigs' to view the list of provided configurations.

Please feed suggestions, bug reports, insults, and bribes back to the
buildroot mailing list: buildroot@buildroot.org
You can also find us on #buildroot on Freenode IRC.

If you would like to contribute patches, please read
https://buildroot.org/manual.html#submitting-patches