1 |
commit: 3fb4979bc5980af0060e50e80ee5bea3ae72a713 |
2 |
Author: Eray Aslan <eras <AT> gentoo <DOT> org> |
3 |
AuthorDate: Mon Nov 7 10:43:02 2022 +0000 |
4 |
Commit: Eray Aslan <eras <AT> gentoo <DOT> org> |
5 |
CommitDate: Mon Nov 7 10:43:02 2022 +0000 |
6 |
URL: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=3fb4979b |
7 |
|
8 |
app-crypt/mit-krb5: drop 1.19.2-r4, 1.19.3-r2 |
9 |
|
10 |
Signed-off-by: Eray Aslan <eras <AT> gentoo.org> |
11 |
|
12 |
app-crypt/mit-krb5/Manifest | 2 - |
13 |
.../mit-krb5/files/mit-krb5-CVE-2021-37750.patch | 43 ------ |
14 |
app-crypt/mit-krb5/mit-krb5-1.19.2-r4.ebuild | 162 --------------------- |
15 |
app-crypt/mit-krb5/mit-krb5-1.19.3-r2.ebuild | 161 -------------------- |
16 |
4 files changed, 368 deletions(-) |
17 |
|
18 |
diff --git a/app-crypt/mit-krb5/Manifest b/app-crypt/mit-krb5/Manifest |
19 |
index 04c701bf322e..ed2f9ab88d2c 100644 |
20 |
--- a/app-crypt/mit-krb5/Manifest |
21 |
+++ b/app-crypt/mit-krb5/Manifest |
22 |
@@ -1,3 +1 @@ |
23 |
-DIST krb5-1.19.2.tar.gz 8741053 BLAKE2B 963722721201e75381c91a2af6e982f569a5b1602beb2d1ded83d35f6f914235a6ed91e5d54f56c97e94921a32ed27c49aded258327966ee13d39485208c38d8 SHA512 b90d6ed0e1e8a87eb5cb2c36d88b823a6a6caabf85e5d419adb8a930f7eea09a5f8491464e7e454cca7ba88be09d19415962fe0036ad2e31fc584f9fc0bbd470 |
24 |
-DIST krb5-1.19.3.tar.gz 8741343 BLAKE2B 79e68237ee82affa85299060c509e303453c0fab965adc6b9ed305ab64a1f73bd51e65df1b3faadc60815cd506ffefaeed535765ca060d393a9141812f85b48a SHA512 18235440d6f7d8a72c5d7ca5cd8c6465e8adf091d85c483225c7b00d64b4688c1c7924cb800c2fc17e590b2709f1a9de48e6ec79f6debd11dcb7d6fa16c6f351 |
25 |
DIST krb5-1.20.tar.gz 8660756 BLAKE2B fdaaab6c16dbe073c4308f312e321536b582b75fad10e5450be66b6b828825c8c775e56f5287d4a7df819d20889e5c0d9cc1d179d861c9caba185332c0db7387 SHA512 9aed84a971a4d74188468870260087ec7c3a614cceb5fe32ad7da1cb8db3d66e00df801c9f900f0131ac56eb828674b8be93df474c2d13b892b70c7977388604 |
26 |
|
27 |
diff --git a/app-crypt/mit-krb5/files/mit-krb5-CVE-2021-37750.patch b/app-crypt/mit-krb5/files/mit-krb5-CVE-2021-37750.patch |
28 |
deleted file mode 100644 |
29 |
index 2f4c949e9f31..000000000000 |
30 |
--- a/app-crypt/mit-krb5/files/mit-krb5-CVE-2021-37750.patch |
31 |
+++ /dev/null |
32 |
@@ -1,43 +0,0 @@ |
33 |
-From d775c95af7606a51bf79547a94fa52ddd1cb7f49 Mon Sep 17 00:00:00 2001 |
34 |
-From: Greg Hudson <ghudson@×××.edu> |
35 |
-Date: Tue, 3 Aug 2021 01:15:27 -0400 |
36 |
-Subject: [PATCH] Fix KDC null deref on TGS inner body null server |
37 |
- |
38 |
-After the KDC decodes a FAST inner body, it does not check for a null |
39 |
-server. Prior to commit 39548a5b17bbda9eeb63625a201cfd19b9de1c5b this |
40 |
-would typically result in an error from krb5_unparse_name(), but with |
41 |
-the addition of get_local_tgt() it results in a null dereference. Add |
42 |
-a null check. |
43 |
- |
44 |
-Reported by Joseph Sutton of Catalyst. |
45 |
- |
46 |
-CVE-2021-37750: |
47 |
- |
48 |
-In MIT krb5 releases 1.14 and later, an authenticated attacker can |
49 |
-cause a null dereference in the KDC by sending a FAST TGS request with |
50 |
-no server field. |
51 |
- |
52 |
-ticket: 9008 (new) |
53 |
-tags: pullup |
54 |
-target_version: 1.19-next |
55 |
-target_version: 1.18-next |
56 |
---- |
57 |
- src/kdc/do_tgs_req.c | 5 +++++ |
58 |
- 1 file changed, 5 insertions(+) |
59 |
- |
60 |
-diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c |
61 |
-index 582e497cc9..32dc65fa8e 100644 |
62 |
---- a/kdc/do_tgs_req.c |
63 |
-+++ b/kdc/do_tgs_req.c |
64 |
-@@ -204,6 +204,11 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, |
65 |
- status = "FIND_FAST"; |
66 |
- goto cleanup; |
67 |
- } |
68 |
-+ if (sprinc == NULL) { |
69 |
-+ status = "NULL_SERVER"; |
70 |
-+ errcode = KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN; |
71 |
-+ goto cleanup; |
72 |
-+ } |
73 |
- |
74 |
- errcode = get_local_tgt(kdc_context, &sprinc->realm, header_server, |
75 |
- &local_tgt, &local_tgt_storage, &local_tgt_key); |
76 |
|
77 |
diff --git a/app-crypt/mit-krb5/mit-krb5-1.19.2-r4.ebuild b/app-crypt/mit-krb5/mit-krb5-1.19.2-r4.ebuild |
78 |
deleted file mode 100644 |
79 |
index a88217f5154c..000000000000 |
80 |
--- a/app-crypt/mit-krb5/mit-krb5-1.19.2-r4.ebuild |
81 |
+++ /dev/null |
82 |
@@ -1,162 +0,0 @@ |
83 |
-# Copyright 1999-2022 Gentoo Authors |
84 |
-# Distributed under the terms of the GNU General Public License v2 |
85 |
- |
86 |
-EAPI=8 |
87 |
- |
88 |
-PYTHON_COMPAT=( python3_{8..10} ) |
89 |
-inherit autotools flag-o-matic multilib-minimal python-any-r1 systemd toolchain-funcs |
90 |
- |
91 |
-MY_P="${P/mit-}" |
92 |
-P_DIR=$(ver_cut 1-2) |
93 |
-DESCRIPTION="MIT Kerberos V" |
94 |
-HOMEPAGE="https://web.mit.edu/kerberos/www/" |
95 |
-SRC_URI="https://web.mit.edu/kerberos/dist/krb5/${P_DIR}/${MY_P}.tar.gz" |
96 |
- |
97 |
-LICENSE="openafs-krb5-a BSD MIT OPENLDAP BSD-2 HPND BSD-4 ISC RSA CC-BY-SA-3.0 || ( BSD-2 GPL-2+ )" |
98 |
-SLOT="0" |
99 |
-KEYWORDS="~alpha amd64 arm arm64 hppa ~ia64 ~mips ~ppc ppc64 ~riscv ~s390 sparc x86" |
100 |
-IUSE="cpu_flags_x86_aes doc +keyutils lmdb nls openldap +pkinit selinux +threads test xinetd" |
101 |
- |
102 |
-# some tests requires network access |
103 |
-RESTRICT="test" |
104 |
- |
105 |
-DEPEND=" |
106 |
- !!app-crypt/heimdal |
107 |
- >=sys-fs/e2fsprogs-1.46.4-r51[${MULTILIB_USEDEP}] |
108 |
- || ( |
109 |
- >=dev-libs/libverto-0.2.5[libev,${MULTILIB_USEDEP}] |
110 |
- >=dev-libs/libverto-0.2.5[libevent,${MULTILIB_USEDEP}] |
111 |
- ) |
112 |
- keyutils? ( >=sys-apps/keyutils-1.5.8:=[${MULTILIB_USEDEP}] ) |
113 |
- lmdb? ( dev-db/lmdb:= ) |
114 |
- nls? ( sys-devel/gettext[${MULTILIB_USEDEP}] ) |
115 |
- openldap? ( >=net-nds/openldap-2.4.38-r1:=[${MULTILIB_USEDEP}] ) |
116 |
- pkinit? ( >=dev-libs/openssl-1.0.1h-r2:0=[${MULTILIB_USEDEP}] ) |
117 |
- xinetd? ( sys-apps/xinetd ) |
118 |
- " |
119 |
-BDEPEND=" |
120 |
- ${PYTHON_DEPS} |
121 |
- virtual/yacc |
122 |
- cpu_flags_x86_aes? ( |
123 |
- amd64? ( dev-lang/yasm ) |
124 |
- x86? ( dev-lang/yasm ) |
125 |
- ) |
126 |
- doc? ( virtual/latex-base ) |
127 |
- test? ( |
128 |
- ${PYTHON_DEPS} |
129 |
- dev-lang/tcl:0 |
130 |
- dev-util/dejagnu |
131 |
- dev-util/cmocka |
132 |
- )" |
133 |
-RDEPEND="${DEPEND} |
134 |
- selinux? ( sec-policy/selinux-kerberos )" |
135 |
- |
136 |
-S=${WORKDIR}/${MY_P}/src |
137 |
- |
138 |
-PATCHES=( |
139 |
- "${FILESDIR}/${PN}-1.12_warn_cflags.patch" |
140 |
- "${FILESDIR}/${PN}-config_LDFLAGS-r1.patch" |
141 |
- "${FILESDIR}/${PN}_dont_create_rundir.patch" |
142 |
- "${FILESDIR}/${PN}-1.18.2-krb5-config.patch" |
143 |
- "${FILESDIR}/${PN}-CVE-2021-37750.patch" |
144 |
-) |
145 |
- |
146 |
-MULTILIB_CHOST_TOOLS=( |
147 |
- /usr/bin/krb5-config |
148 |
-) |
149 |
- |
150 |
-src_prepare() { |
151 |
- default |
152 |
- # Make sure we always use the system copies. |
153 |
- rm -rf util/{et,ss,verto} |
154 |
- sed -i 's:^[[:space:]]*util/verto$::' configure.ac || die |
155 |
- |
156 |
- eautoreconf |
157 |
-} |
158 |
- |
159 |
-src_configure() { |
160 |
- # QA |
161 |
- append-flags -fno-strict-aliasing |
162 |
- append-flags -fno-strict-overflow |
163 |
- |
164 |
- multilib-minimal_src_configure |
165 |
-} |
166 |
- |
167 |
-multilib_src_configure() { |
168 |
- ECONF_SOURCE=${S} \ |
169 |
- AR="$(tc-getAR)" \ |
170 |
- WARN_CFLAGS="set" \ |
171 |
- econf \ |
172 |
- $(use_with openldap ldap) \ |
173 |
- "$(multilib_native_use_with test tcl "${EPREFIX}/usr")" \ |
174 |
- $(use_enable nls) \ |
175 |
- $(use_enable pkinit) \ |
176 |
- $(use_enable threads thread-support) \ |
177 |
- $(use_with lmdb) \ |
178 |
- $(use_with keyutils) \ |
179 |
- --without-hesiod \ |
180 |
- --enable-shared \ |
181 |
- --with-system-et \ |
182 |
- --with-system-ss \ |
183 |
- --enable-dns-for-realm \ |
184 |
- --enable-kdc-lookaside-cache \ |
185 |
- --with-system-verto \ |
186 |
- --disable-rpath |
187 |
-} |
188 |
- |
189 |
-multilib_src_compile() { |
190 |
- emake -j1 |
191 |
-} |
192 |
- |
193 |
-multilib_src_test() { |
194 |
- multilib_is_native_abi && emake -j1 check |
195 |
-} |
196 |
- |
197 |
-multilib_src_install() { |
198 |
- emake \ |
199 |
- DESTDIR="${D}" \ |
200 |
- EXAMPLEDIR="${EPREFIX}/usr/share/doc/${PF}/examples" \ |
201 |
- install |
202 |
-} |
203 |
- |
204 |
-multilib_src_install_all() { |
205 |
- # default database dir |
206 |
- keepdir /var/lib/krb5kdc |
207 |
- |
208 |
- cd .. |
209 |
- dodoc README |
210 |
- |
211 |
- if use doc; then |
212 |
- dodoc -r doc/html |
213 |
- docinto pdf |
214 |
- dodoc doc/pdf/*.pdf |
215 |
- fi |
216 |
- |
217 |
- newinitd "${FILESDIR}"/mit-krb5kadmind.initd-r2 mit-krb5kadmind |
218 |
- newinitd "${FILESDIR}"/mit-krb5kdc.initd-r2 mit-krb5kdc |
219 |
- newinitd "${FILESDIR}"/mit-krb5kpropd.initd-r2 mit-krb5kpropd |
220 |
- newconfd "${FILESDIR}"/mit-krb5kadmind.confd mit-krb5kadmind |
221 |
- newconfd "${FILESDIR}"/mit-krb5kdc.confd mit-krb5kdc |
222 |
- newconfd "${FILESDIR}"/mit-krb5kpropd.confd mit-krb5kpropd |
223 |
- |
224 |
- systemd_newunit "${FILESDIR}"/mit-krb5kadmind.service mit-krb5kadmind.service |
225 |
- systemd_newunit "${FILESDIR}"/mit-krb5kdc.service mit-krb5kdc.service |
226 |
- systemd_newunit "${FILESDIR}"/mit-krb5kpropd.service mit-krb5kpropd.service |
227 |
- systemd_newunit "${FILESDIR}"/mit-krb5kpropd_at.service "mit-krb5kpropd@.service" |
228 |
- systemd_newunit "${FILESDIR}"/mit-krb5kpropd.socket mit-krb5kpropd.socket |
229 |
- |
230 |
- insinto /etc |
231 |
- newins "${ED}/usr/share/doc/${PF}/examples/krb5.conf" krb5.conf.example |
232 |
- insinto /var/lib/krb5kdc |
233 |
- newins "${ED}/usr/share/doc/${PF}/examples/kdc.conf" kdc.conf.example |
234 |
- |
235 |
- if use openldap ; then |
236 |
- insinto /etc/openldap/schema |
237 |
- doins "${S}/plugins/kdb/ldap/libkdb_ldap/kerberos.schema" |
238 |
- fi |
239 |
- |
240 |
- if use xinetd ; then |
241 |
- insinto /etc/xinetd.d |
242 |
- newins "${FILESDIR}/kpropd.xinetd" kpropd |
243 |
- fi |
244 |
-} |
245 |
|
246 |
diff --git a/app-crypt/mit-krb5/mit-krb5-1.19.3-r2.ebuild b/app-crypt/mit-krb5/mit-krb5-1.19.3-r2.ebuild |
247 |
deleted file mode 100644 |
248 |
index e90b52a26ebe..000000000000 |
249 |
--- a/app-crypt/mit-krb5/mit-krb5-1.19.3-r2.ebuild |
250 |
+++ /dev/null |
251 |
@@ -1,161 +0,0 @@ |
252 |
-# Copyright 1999-2022 Gentoo Authors |
253 |
-# Distributed under the terms of the GNU General Public License v2 |
254 |
- |
255 |
-EAPI=8 |
256 |
- |
257 |
-PYTHON_COMPAT=( python3_{8..10} ) |
258 |
-inherit autotools flag-o-matic multilib-minimal python-any-r1 systemd toolchain-funcs |
259 |
- |
260 |
-MY_P="${P/mit-}" |
261 |
-P_DIR=$(ver_cut 1-2) |
262 |
-DESCRIPTION="MIT Kerberos V" |
263 |
-HOMEPAGE="https://web.mit.edu/kerberos/www/" |
264 |
-SRC_URI="https://web.mit.edu/kerberos/dist/krb5/${P_DIR}/${MY_P}.tar.gz" |
265 |
- |
266 |
-LICENSE="openafs-krb5-a BSD MIT OPENLDAP BSD-2 HPND BSD-4 ISC RSA CC-BY-SA-3.0 || ( BSD-2 GPL-2+ )" |
267 |
-SLOT="0" |
268 |
-KEYWORDS="~alpha ~amd64 ~arm ~arm64 ~hppa ~ia64 ~loong ~mips ~ppc ~ppc64 ~riscv ~s390 ~sparc ~x86" |
269 |
-IUSE="cpu_flags_x86_aes doc +keyutils lmdb nls openldap +pkinit selinux +threads test xinetd" |
270 |
- |
271 |
-# some tests requires network access |
272 |
-RESTRICT="test" |
273 |
- |
274 |
-DEPEND=" |
275 |
- !!app-crypt/heimdal |
276 |
- >=sys-fs/e2fsprogs-1.46.4-r51[${MULTILIB_USEDEP}] |
277 |
- || ( |
278 |
- >=dev-libs/libverto-0.2.5[libev,${MULTILIB_USEDEP}] |
279 |
- >=dev-libs/libverto-0.2.5[libevent,${MULTILIB_USEDEP}] |
280 |
- ) |
281 |
- keyutils? ( >=sys-apps/keyutils-1.5.8:=[${MULTILIB_USEDEP}] ) |
282 |
- lmdb? ( dev-db/lmdb:= ) |
283 |
- nls? ( sys-devel/gettext[${MULTILIB_USEDEP}] ) |
284 |
- openldap? ( >=net-nds/openldap-2.4.38-r1:=[${MULTILIB_USEDEP}] ) |
285 |
- pkinit? ( >=dev-libs/openssl-1.0.1h-r2:0=[${MULTILIB_USEDEP}] ) |
286 |
- xinetd? ( sys-apps/xinetd ) |
287 |
- " |
288 |
-BDEPEND=" |
289 |
- ${PYTHON_DEPS} |
290 |
- virtual/yacc |
291 |
- cpu_flags_x86_aes? ( |
292 |
- amd64? ( dev-lang/yasm ) |
293 |
- x86? ( dev-lang/yasm ) |
294 |
- ) |
295 |
- doc? ( virtual/latex-base ) |
296 |
- test? ( |
297 |
- ${PYTHON_DEPS} |
298 |
- dev-lang/tcl:0 |
299 |
- dev-util/dejagnu |
300 |
- dev-util/cmocka |
301 |
- )" |
302 |
-RDEPEND="${DEPEND} |
303 |
- selinux? ( sec-policy/selinux-kerberos )" |
304 |
- |
305 |
-S=${WORKDIR}/${MY_P}/src |
306 |
- |
307 |
-PATCHES=( |
308 |
- "${FILESDIR}/${PN}-1.12_warn_cflags.patch" |
309 |
- "${FILESDIR}/${PN}-config_LDFLAGS-r1.patch" |
310 |
- "${FILESDIR}/${PN}_dont_create_rundir.patch" |
311 |
- "${FILESDIR}/${PN}-1.18.2-krb5-config.patch" |
312 |
-) |
313 |
- |
314 |
-MULTILIB_CHOST_TOOLS=( |
315 |
- /usr/bin/krb5-config |
316 |
-) |
317 |
- |
318 |
-src_prepare() { |
319 |
- default |
320 |
- # Make sure we always use the system copies. |
321 |
- rm -rf util/{et,ss,verto} |
322 |
- sed -i 's:^[[:space:]]*util/verto$::' configure.ac || die |
323 |
- |
324 |
- eautoreconf |
325 |
-} |
326 |
- |
327 |
-src_configure() { |
328 |
- # QA |
329 |
- append-flags -fno-strict-aliasing |
330 |
- append-flags -fno-strict-overflow |
331 |
- |
332 |
- multilib-minimal_src_configure |
333 |
-} |
334 |
- |
335 |
-multilib_src_configure() { |
336 |
- ECONF_SOURCE=${S} \ |
337 |
- AR="$(tc-getAR)" \ |
338 |
- WARN_CFLAGS="set" \ |
339 |
- econf \ |
340 |
- $(use_with openldap ldap) \ |
341 |
- "$(multilib_native_use_with test tcl "${EPREFIX}/usr")" \ |
342 |
- $(use_enable nls) \ |
343 |
- $(use_enable pkinit) \ |
344 |
- $(use_enable threads thread-support) \ |
345 |
- $(use_with lmdb) \ |
346 |
- $(use_with keyutils) \ |
347 |
- --without-hesiod \ |
348 |
- --enable-shared \ |
349 |
- --with-system-et \ |
350 |
- --with-system-ss \ |
351 |
- --enable-dns-for-realm \ |
352 |
- --enable-kdc-lookaside-cache \ |
353 |
- --with-system-verto \ |
354 |
- --disable-rpath |
355 |
-} |
356 |
- |
357 |
-multilib_src_compile() { |
358 |
- emake -j1 |
359 |
-} |
360 |
- |
361 |
-multilib_src_test() { |
362 |
- multilib_is_native_abi && emake -j1 check |
363 |
-} |
364 |
- |
365 |
-multilib_src_install() { |
366 |
- emake \ |
367 |
- DESTDIR="${D}" \ |
368 |
- EXAMPLEDIR="${EPREFIX}/usr/share/doc/${PF}/examples" \ |
369 |
- install |
370 |
-} |
371 |
- |
372 |
-multilib_src_install_all() { |
373 |
- # default database dir |
374 |
- keepdir /var/lib/krb5kdc |
375 |
- |
376 |
- cd .. |
377 |
- dodoc README |
378 |
- |
379 |
- if use doc; then |
380 |
- dodoc -r doc/html |
381 |
- docinto pdf |
382 |
- dodoc doc/pdf/*.pdf |
383 |
- fi |
384 |
- |
385 |
- newinitd "${FILESDIR}"/mit-krb5kadmind.initd-r2 mit-krb5kadmind |
386 |
- newinitd "${FILESDIR}"/mit-krb5kdc.initd-r2 mit-krb5kdc |
387 |
- newinitd "${FILESDIR}"/mit-krb5kpropd.initd-r2 mit-krb5kpropd |
388 |
- newconfd "${FILESDIR}"/mit-krb5kadmind.confd mit-krb5kadmind |
389 |
- newconfd "${FILESDIR}"/mit-krb5kdc.confd mit-krb5kdc |
390 |
- newconfd "${FILESDIR}"/mit-krb5kpropd.confd mit-krb5kpropd |
391 |
- |
392 |
- systemd_newunit "${FILESDIR}"/mit-krb5kadmind.service mit-krb5kadmind.service |
393 |
- systemd_newunit "${FILESDIR}"/mit-krb5kdc.service mit-krb5kdc.service |
394 |
- systemd_newunit "${FILESDIR}"/mit-krb5kpropd.service mit-krb5kpropd.service |
395 |
- systemd_newunit "${FILESDIR}"/mit-krb5kpropd_at.service "mit-krb5kpropd@.service" |
396 |
- systemd_newunit "${FILESDIR}"/mit-krb5kpropd.socket mit-krb5kpropd.socket |
397 |
- |
398 |
- insinto /etc |
399 |
- newins "${ED}/usr/share/doc/${PF}/examples/krb5.conf" krb5.conf.example |
400 |
- insinto /var/lib/krb5kdc |
401 |
- newins "${ED}/usr/share/doc/${PF}/examples/kdc.conf" kdc.conf.example |
402 |
- |
403 |
- if use openldap ; then |
404 |
- insinto /etc/openldap/schema |
405 |
- doins "${S}/plugins/kdb/ldap/libkdb_ldap/kerberos.schema" |
406 |
- fi |
407 |
- |
408 |
- if use xinetd ; then |
409 |
- insinto /etc/xinetd.d |
410 |
- newins "${FILESDIR}/kpropd.xinetd" kpropd |
411 |
- fi |
412 |
-} |