Go to file
Peter Korsgaard c5c106e4e3 package/mosquitto: security bump to version 1.6.6
Fixes a security issue. From the annoncement:

A vulnerability exists in Mosquitto versions 1.5 to 1.6.5 inclusive.

If a client sends a SUBSCRIBE packet containing a topic that consists of
approximately 65400 or more '/' characters, i.e.  the topic hierarchy
separator, then a stack overflow will occur.

The issue is fixed in Mosquitto 1.6.6 and 1.5.9.  Patches for older versions
are available at https://mosquitto.org/files/cve/2019-hier

The fix addresses the problem by restricting the allowed number of topic
hierarchy levels to 200.  An alternative fix is to increase the size of the
stack by a small amount.

https://mosquitto.org/blog/2019/09/version-1-6-6-released/

Also notice that 1.6.5 silently fixed a security issue:

CVE-2019-11778

A vulnerability exists in Mosquitto version 1.6 to 1.6.4 inclusive, known as CVE-2019-11778

If an MQTT v5 client connects to Mosquitto, sets a last will and testament,
sets a will delay interval, sets a session expiry interval, and the will
delay interval is set longer than the session expiry interval, then a use
after free error occurs, which has the potential to cause a crash in some
situations.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
2019-09-18 17:49:58 +02:00
arch ARC: Add support for ARC HS48 v3.1 processor 2019-08-03 17:30:52 +02:00
board configs/lafrite: new defconfig 2019-09-15 16:00:56 +02:00
boot boot/afboot-stm32: bump to version 0.2 2019-09-17 22:02:37 +02:00
configs configs/lafrite: new defconfig 2019-09-15 16:00:56 +02:00
docs docs/manual/adding-packages-python.txt: fix outdated Python 3 explanation 2019-09-10 19:29:21 +02:00
fs fs/common.mk: enable multithreaded xz compression 2019-08-03 19:29:47 +02:00
linux package/xtables-addons: bump to version 3.4 2019-09-15 21:25:39 +02:00
package package/mosquitto: security bump to version 1.6.6 2019-09-18 17:49:58 +02:00
support support/dependencies/dependencies.sh: check for JSON:PP Perl module 2019-09-17 22:36:42 +02:00
system system/skeleton: drop PAGER from /etc/profile 2019-09-07 21:58:04 +02:00
toolchain toolchain/wrapper: also dump args it was called with 2019-08-18 00:19:57 +02:00
utils utils/scancpan: improve license file detection 2019-09-17 22:51:01 +02:00
.defconfig
.flake8 .flake8: fix check for 80/132 columns 2019-04-10 12:31:33 +02:00
.gitignore
.gitlab-ci.yml configs/lafrite: new defconfig 2019-09-15 16:00:56 +02:00
.gitlab-ci.yml.in .gitlab-ci.yml: add trigger per job 2019-05-01 15:42:45 +02:00
CHANGES Update for 2019.05.2 2019-09-03 13:14:45 +02:00
Config.in core: split generated kconfig file 2019-08-04 00:13:37 +02:00
Config.in.legacy package/hostapd: remove support for Realtek drivers 2019-09-07 14:36:23 +02:00
COPYING
DEVELOPERS DEVELOPERS: trim runtime tests for Ricardo Martincoski 2019-09-17 22:51:28 +02:00
Makefile Merge branch 'next' 2019-09-03 15:03:02 +02:00
Makefile.legacy
README README: add reference to submitting-patches 2016-02-01 19:16:08 +01:00

Buildroot is a simple, efficient and easy-to-use tool to generate embedded
Linux systems through cross-compilation.

The documentation can be found in docs/manual. You can generate a text
document with 'make manual-text' and read output/docs/manual/manual.text.
Online documentation can be found at http://buildroot.org/docs.html

To build and use the buildroot stuff, do the following:

1) run 'make menuconfig'
2) select the target architecture and the packages you wish to compile
3) run 'make'
4) wait while it compiles
5) find the kernel, bootloader, root filesystem, etc. in output/images

You do not need to be root to build or run buildroot.  Have fun!

Buildroot comes with a basic configuration for a number of boards. Run
'make list-defconfigs' to view the list of provided configurations.

Please feed suggestions, bug reports, insults, and bribes back to the
buildroot mailing list: buildroot@buildroot.org
You can also find us on #buildroot on Freenode IRC.

If you would like to contribute patches, please read
https://buildroot.org/manual.html#submitting-patches