Go to file
Peter Korsgaard ac2ffc15ff package/git: security bump to version 2.22.2
Fixes the following security vulnerabilities:

* CVE-2019-1348:
  The --export-marks option of git fast-import is exposed also via
  the in-stream command feature export-marks=... and it allows
  overwriting arbitrary paths.

* CVE-2019-1349:
  When submodules are cloned recursively, under certain circumstances
  Git could be fooled into using the same Git directory twice. We now
  require the directory to be empty.

* CVE-2019-1350:
  Incorrect quoting of command-line arguments allowed remote code
  execution during a recursive clone in conjunction with SSH URLs.

* CVE-2019-1351:
  While the only permitted drive letters for physical drives on
  Windows are letters of the US-English alphabet, this restriction
  does not apply to virtual drives assigned via subst <letter>:
  <path>. Git mistook such paths for relative paths, allowing writing
  outside of the worktree while cloning.

* CVE-2019-1352:
  Git was unaware of NTFS Alternate Data Streams, allowing files
  inside the .git/ directory to be overwritten during a clone.

* CVE-2019-1353:
  When running Git in the Windows Subsystem for Linux (also known as
  "WSL") while accessing a working directory on a regular Windows
  drive, none of the NTFS protections were active.

* CVE-2019-1354:
  Filenames on Linux/Unix can contain backslashes. On Windows,
  backslashes are directory separators. Git did not use to refuse to
  write out tracked files with such filenames.

* CVE-2019-1387:
  Recursive clones are currently affected by a vulnerability that is
  caused by too-lax validation of submodule names, allowing very
  targeted attacks via remote code execution in recursive clones.

* CVE-2019-19604:
  The git submodule update operation can lead to execution of arbitrary
  shell commands defined in the .gitmodules file
  https://gitlab.com/gitlab-com/gl-security/disclosures/blob/master/003_git_submodule/advisory.md

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2019-12-22 21:41:41 +01:00
arch arch/riscv: set the default float ABI based on ISA extensions 2019-09-19 21:43:53 +02:00
board board/beaglebone: fix boot on BeagleBone Black 2019-11-15 23:38:29 +01:00
boot boot/optee-os: bump version to 3.7.0 2019-10-29 22:25:18 +01:00
configs configs/imx28evk: Bump U-Boot and kernel versions 2019-11-01 15:27:28 +01:00
docs Update for 2019.11 2019-12-01 22:39:47 +01:00
fs fs: don't use := when not needed 2019-10-27 10:35:06 +01:00
linux {linux, linux-headers}: bump 4.{4, 9, 14, 19}.x / 5.{3, 4}.x series 2019-12-07 13:11:57 +01:00
package package/git: security bump to version 2.22.2 2019-12-22 21:41:41 +01:00
support Update for 2019.11 2019-12-01 22:39:47 +01:00
system system: allow not setting a default, system-wide time zone 2019-11-27 21:48:38 +01:00
toolchain package/musl: add an upstream URL to Config.in 2019-11-29 09:44:09 +01:00
utils utils/genrandconfig: fix runtime issue with Python 3 2019-12-06 09:59:56 +01:00
.defconfig arch: remove support for sh64 2016-09-08 22:15:15 +02:00
.flake8 .flake8: fix check for 80/132 columns 2019-04-10 12:31:33 +02:00
.gitignore
.gitlab-ci.yml gitlab-ci: use our updated docker base image 2019-10-27 21:52:28 +01:00
.gitlab-ci.yml.in gitlab-ci: use our updated docker base image 2019-10-27 21:52:28 +01:00
CHANGES Update for 2019.11 2019-12-01 22:39:47 +01:00
Config.in Config.in: disable PIC/PIE if the toolchain does not support PIE 2019-10-28 08:43:22 +01:00
Config.in.legacy Config.in.legacy: fix small typo 2019-11-10 21:51:16 +01:00
COPYING
DEVELOPERS DEVELOPERS: add me as a maintainer for the NETCONF stack 2019-12-22 21:28:19 +01:00
Makefile Update for 2019.11 2019-12-01 22:39:47 +01:00
Makefile.legacy Remove BR2_DEPRECATED 2016-10-15 23:14:45 +02:00
README

Buildroot is a simple, efficient and easy-to-use tool to generate embedded
Linux systems through cross-compilation.

The documentation can be found in docs/manual. You can generate a text
document with 'make manual-text' and read output/docs/manual/manual.text.
Online documentation can be found at http://buildroot.org/docs.html

To build and use the buildroot stuff, do the following:

1) run 'make menuconfig'
2) select the target architecture and the packages you wish to compile
3) run 'make'
4) wait while it compiles
5) find the kernel, bootloader, root filesystem, etc. in output/images

You do not need to be root to build or run buildroot.  Have fun!

Buildroot comes with a basic configuration for a number of boards. Run
'make list-defconfigs' to view the list of provided configurations.

Please feed suggestions, bug reports, insults, and bribes back to the
buildroot mailing list: buildroot@buildroot.org
You can also find us on #buildroot on Freenode IRC.

If you would like to contribute patches, please read
https://buildroot.org/manual.html#submitting-patches