From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:35539) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ea3s5-0000Va-Us for guix-patches@gnu.org; Fri, 12 Jan 2018 13:16:06 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ea3s3-0008O0-9i for guix-patches@gnu.org; Fri, 12 Jan 2018 13:16:05 -0500 Received: from debbugs.gnu.org ([208.118.235.43]:46200) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1ea3s3-0008N2-0S for guix-patches@gnu.org; Fri, 12 Jan 2018 13:16:03 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1ea3s2-0005t2-O0 for guix-patches@gnu.org; Fri, 12 Jan 2018 13:16:02 -0500 Subject: bug#30082: [v2] gnu: transmission: Fix a DNS rebinding vulnerability that allows RCE. Resent-To: guix-patches@gnu.org Resent-Message-ID: Date: Fri, 12 Jan 2018 10:14:56 -0800 From: Leo Famulari Message-ID: <20180112181456.GA1311@jasmine.lan> References: <139e227515c0e99297951c92d498e3c01f34ccf4.1515712746.git.leo@famulari.name> <723dcdea4d11c70e1f7731b3abfdca424a930743.1515713957.git.leo@famulari.name> <87a7xkeytk.fsf@fastmail.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="EeQfGwPcQSOJBaQU" Content-Disposition: inline In-Reply-To: <87a7xkeytk.fsf@fastmail.com> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: Marius Bakke Cc: 30082-done@debbugs.gnu.org --EeQfGwPcQSOJBaQU Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Fri, Jan 12, 2018 at 12:54:31AM +0100, Marius Bakke wrote: > Leo Famulari writes: >=20 > > * gnu/packages/patches/transmission-fix-dns-rebinding-vuln.patch: New f= ile. > > * gnu/local.mk (dist_patch_DATA): Add it. > > * gnu/packages/bittorrent.scm (transmission)[source]: Use it. >=20 > Holy! LGTM, and thanks a lot for this extremely quick fix. Pushed as 6b433caed2c86bf41acfa65dd507292e8a0ab2ac --EeQfGwPcQSOJBaQU Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAlpY+yAACgkQJkb6MLrK fwgTJxAA2UHw7MEc9YMGGztpHs1kikIbTYqvjKrsvfJDzqQyBesJydHdvTLI0azS 6vdUOjAOJ6ze11kREUS1NwA6vV3ptNPShG+sNnRrb0YShfW/Quv0qig7Jl+I11cc ydjU+l6IIJG/5ngqNZqS1UL9Qhd4zfRaMthRmToSNx8wt+Jc+7YKVDCltehpacbR eJGZDMrB4bQAq2v1i6mmpX0p22fQ8RemF6FAGkVU87o7iIyVxyLg/UlCdO7ioKwI JSMPCGcwDLYKEtK/8kfVjqujQdwL/SmN7qKYHe66bOAD8aVWpdeeC5MmKCK7DWM3 YkghBBQjRqXlN+FxNNJilBLd7rQ3di7VeCL4g38Xem3lFQJGkUZEg+Ac000qd1Ot Mg2H5WoFhf7CmALJuJ83cFkPSTCIsJPY632Tf4sLE8sEmNYqZ4w55LJcnYFYDjb4 spLk7GdboM3sqH4+r9+WDIrB39WQBgfoxH95aKD1CkIQpOfbkkPrOy0Rs6210wVq p8yRftTfMfSh3ipKRcPIpDgoRxhzKFF8biJELawUOFZ70ByLcCbFC0eZ3b64exY1 m17nL5XX3HYY30c/KYXsk+EwjgA/37cHYO8t4P8vS7ZB4w89U9mWlFjtCIP/PW6K 1BtJf2zeKgQUzJ2HaFs4p3nGjrwMV6eFs0yyhquMyuhuMsqybZ0= =XWXz -----END PGP SIGNATURE----- --EeQfGwPcQSOJBaQU--