Fixed security bug, see 377473. Patch only modifies one regexp.
authorConstanze Hausner <constanze@gentoo.org>
Sat, 6 Aug 2011 15:26:11 +0000 (15:26 +0000)
committerConstanze Hausner <constanze@gentoo.org>
Sat, 6 Aug 2011 15:26:11 +0000 (15:26 +0000)
Package-Manager: portage-2.1.10.3/cvs/Linux x86_64
RepoMan-Options: --force

net-firewall/shorewall/ChangeLog
net-firewall/shorewall/Manifest
net-firewall/shorewall/files/all_zone.patch [new file with mode: 0644]
net-firewall/shorewall/shorewall-4.4.15.1-r1.ebuild [new file with mode: 0644]

index daa2040a9876d375eac461e1d8afa5744c82afe8..4b4670c86e1abd621cf762f87763ee570f84087f 100644 (file)
@@ -1,6 +1,12 @@
 # ChangeLog for net-firewall/shorewall
 # Copyright 1999-2011 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/net-firewall/shorewall/ChangeLog,v 1.190 2011/07/24 15:25:33 constanze Exp $
+# $Header: /var/cvsroot/gentoo-x86/net-firewall/shorewall/ChangeLog,v 1.191 2011/08/06 15:26:11 constanze Exp $
+
+*shorewall-4.4.15.1-r1 (06 Aug 2011)
+
+  06 Aug 2011; Constanze Hausner <constanze@gentoo.org>
+  +shorewall-4.4.15.1-r1.ebuild, +files/all_zone.patch:
+  Fixed security bug, see #377473
 
 *shorewall-4.4.21-r1 (24 Jul 2011)
 
index c522fae093d7dd59c87e74c337f48899d993ed8d..8deda70b191c568e0a96d63d27fc7ce2e1e4362d 100644 (file)
@@ -1,6 +1,7 @@
 -----BEGIN PGP SIGNED MESSAGE-----
 Hash: SHA1
 
+AUX all_zone.patch 351 RMD160 eada998470b82125442d1994112143e1b5fc513b SHA1 ce665f2b0c41ac9c33e29d1bd37f94abde7eeb36 SHA256 e631e846762760989b5fa3707c0bb6c4f44f91dc2fc04cfe829ec057880b7793
 AUX shorewall.initd 1905 RMD160 a448df26dc5c5417b4247f6aa90b1211ce74aa6c SHA1 6f439e8155bc29f61c0788645f28f75050d12bc4 SHA256 64c35fbdae3e6dc9bfbbecbaa68841d9ba2f924b042ef27a1c04633db46e80d8
 DIST shorewall-4.4.15.1.tar.bz2 278607 RMD160 621b25c675bd13897c830780fd85c2b5044df1be SHA1 13eb36754d3ff259836a4f2daaf73513427e6ed4 SHA256 a89eb18435615e9a3d898308e6831ba46c9094318c9744d4ccdf34a4cb5f49e7
 DIST shorewall-4.4.19.3.tar.bz2 283592 RMD160 7a17876f604b0a628e88a9cb1eb1b7245b9de2e1 SHA1 3dae88fbbf3371532fdfae334ff8c78b9efcba9c SHA256 82baa8ce9c01ca39d5037a894e96555d10de1d98e4b627e7407361cf89c692c0
@@ -12,20 +13,21 @@ DIST shorewall-docs-html-4.4.19.3.tar.bz2 3493734 RMD160 993cdcf648557cc781d5749
 DIST shorewall-docs-html-4.4.19.4.tar.bz2 3493905 RMD160 02a5a34ec60b525ececd45f203c12b0bd3afd726 SHA1 b1360ef8b8ce3829b492b852fb2bd2a933a5be93 SHA256 934fe59e181badab87ba9ff9c1ef2706826c9fab220acf5058441765031601ce
 DIST shorewall-docs-html-4.4.20.3.tar.bz2 3502323 RMD160 92ae50e48366d1d2de8f64d0245b9a96c4f2dcbc SHA1 2137bb75a37d6170e111ed2b81d0ddebe5478f42 SHA256 aa6667f4f663ecd378dda67b08979bf22f5e0fb0eaf866d99739645c5fc1c885
 DIST shorewall-docs-html-4.4.21.tar.bz2 3532719 RMD160 f2f08ca1f7c1454e7aca4d0ecb66b81f88975678 SHA1 cbccfc798e49c6e18daa87d23cf3b5f73850d82c SHA256 e6ab31be8b3158ae05a8f07ba05d044a2d27ea5167e7a959a23c5c22b9992a4f
+EBUILD shorewall-4.4.15.1-r1.ebuild 3669 RMD160 b8a2c5890e6b69b27e601c21ba12945c0f0533e2 SHA1 db79ffd109c6cc7bf8045651354f5162c926236b SHA256 c94105e5a32fcdf753438dc32a60b2bfa4ded97418684418053068e0be37791e
 EBUILD shorewall-4.4.15.1.ebuild 3618 RMD160 223953ff5414051fc27b954af0ce50e5080211ad SHA1 7ee405df6210e5a2a9536a04e1d3d038494bfb65 SHA256 dda1507cc472846eef912b2a4567fe51fad7009341ea417e5bb34af7baf0bb0a
 EBUILD shorewall-4.4.19.3.ebuild 2160 RMD160 3e41672fb987e56b2a36e0bc61301bbf58b056ba SHA1 2c69ff84ec5ffd6ddb3c2d1e06671ef0924dd3d2 SHA256 f8680ed2b668bfebd4c1f118ebcc7cc83e06ec306f608eb913ddd3cb70aae04c
 EBUILD shorewall-4.4.19.4.ebuild 2160 RMD160 4e69323b48f07a07ce6a7759b37deb31b8f3a4af SHA1 d6d9fcb1cd9fe8c0a76f248677d6f73892967de2 SHA256 0d1fc1c7383f130a49fadb2034c3d74baf182cfe173a79f42a12ac19a85e22fa
 EBUILD shorewall-4.4.20.3.ebuild 1904 RMD160 44fd1f67388ba28419ff044df7cb0acf77329a66 SHA1 b04dede1ecf1ea26d4c69451c634230cf6de8c03 SHA256 0221d0dad2d0a38e8e4829e10754fb431a39b0f9749ac080e2858ddd9b99824a
 EBUILD shorewall-4.4.21-r1.ebuild 1929 RMD160 79cd909b043f94090668005c5db06b51d7bc9caf SHA1 0fb5c4f750e9bbdba0f24fd40ca4712961890d8b SHA256 8a8eebeda617be6a5229399cbc03caa2822839118c74600cb3f556cdeaa830e9
 EBUILD shorewall-4.4.21.ebuild 1902 RMD160 08a6b72eee59a8ec1b98f1212f7122c2297252cd SHA1 110e0df257ca08575f9f77589d45a699aef70c05 SHA256 44398328f22b7f3a0588c91a1779ee94d8c1f4b4e6df927fb955dc852d55afa0
-MISC ChangeLog 26772 RMD160 c671bb36324620a65387824a3f6470cbe8084718 SHA1 2f5f2d18c37693ae4b03fcbbe0dcc10b08be90dd SHA256 5b97e1ad9415765a4cddee12c8c19337a170694eeea5ceeaf9aafc0896501751
+MISC ChangeLog 26957 RMD160 a5f17f786cf3a27ba094f16e420344d839eac208 SHA1 4394cf2cb940edd294e78a0fb58add5613c0b396 SHA256 990e3a9f1e7cb05d560abd41341f94faa7c47fe9a2ac80dfb4795f7332738a1e
 MISC metadata.xml 306 RMD160 90a3e8c5e062df3f9292505b62d82b831bcaa1bd SHA1 47b37ae73a7a7bbf2f99307edaa7fed6fe77a799 SHA256 7f2b854d54b12215f518f9d8101dbe766e69976639f42caa2bd16e95739ae0e9
 -----BEGIN PGP SIGNATURE-----
 Version: GnuPG v2.0.17 (GNU/Linux)
 
-iJwEAQECAAYFAk4sOYYACgkQm1t7FhV+4eFsMgP+NSmXLeh9FxwH39p/NWXPtkY8
-g/bbCPx7nUdcRsPxhs64OXx1DoLxiw++uRFcAMFuvjjazcv5/VpDaM/NvNpZI1HP
-wsNuUMZhVRR60s9Rbv1ExfkLGSheLCAB+S4RqNQCUYMRmrk96sdQfrCCWvRYqxLv
-l0d1t9Gnsy5F3s3wpwk=
-=vlpQ
+iJwEAQECAAYFAk49XUYACgkQm1t7FhV+4eGsuwQAmnQn7j/LhrRTB/uH5XxuvlVz
+09fUk3z74u7QUYUDzku5bKvaW9knSUM8ZB+3CbGeZkl/QwDBDJhCWcLRj6l1PKnQ
+vUsapNBvuT49MxiSoIv/P1FaSCj+S1zl829Twb6L+Q7c9aSAG323y+6LRvFK7N5u
+iVPJ78HHOSFLNUIftl0=
+=sLgv
 -----END PGP SIGNATURE-----
diff --git a/net-firewall/shorewall/files/all_zone.patch b/net-firewall/shorewall/files/all_zone.patch
new file mode 100644 (file)
index 0000000..09384e1
--- /dev/null
@@ -0,0 +1,11 @@
+--- Perl/Shorewall/Rules_orig.pm       2011-08-06 17:12:13.000000000 +0200
++++ Perl/Shorewall/Rules.pm    2011-08-06 17:12:39.000000000 +0200
+@@ -1554,7 +1554,7 @@
+     #
+     # Handle Wildcards
+     #
+-    if ( $input =~ /^(all[-+]*)(![^:]+)?(:.*)?/ ) {
++    if ( $input =~ /^(all[-+]*)(![^:]+)?(:.*)?$/ ) {
+       $input   = $1;
+       $exclude = $2;
+       $rest    = $3;
diff --git a/net-firewall/shorewall/shorewall-4.4.15.1-r1.ebuild b/net-firewall/shorewall/shorewall-4.4.15.1-r1.ebuild
new file mode 100644 (file)
index 0000000..3297a9f
--- /dev/null
@@ -0,0 +1,101 @@
+# Copyright 1999-2011 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/net-firewall/shorewall/shorewall-4.4.15.1-r1.ebuild,v 1.1 2011/08/06 15:26:11 constanze Exp $
+
+EAPI="2"
+
+inherit eutils versionator
+
+# Select version (stable, RC, Beta):
+MY_PV_TREE=$(get_version_component_range 1-2)   # for devel versions use "development/$(get_version_component_range 1-2)"
+MY_P_BETA=""                                    # stable or experimental (eg. "-RC1" or "-Beta4")
+MY_PV_BASE=$(get_version_component_range 1-3)
+
+MY_P="${PN}-${MY_PV_BASE}${MY_P_BETA}"
+MY_P_DOCS="${P/${PN}/${PN}-docs-html}"
+
+DESCRIPTION="Shoreline Firewall is an iptables-based firewall for Linux."
+HOMEPAGE="http://www.shorewall.net/"
+SRC_URI="http://www1.shorewall.net/pub/${PN}/${MY_PV_TREE}/${MY_P}/${P}${MY_P_BETA}.tar.bz2
+       doc? ( http://www1.shorewall.net/pub/${PN}/${MY_PV_TREE}/${MY_P}/${MY_P_DOCS}.tar.bz2 )"
+
+LICENSE="GPL-2"
+SLOT="0"
+KEYWORDS="alpha amd64 hppa ppc ppc64 sparc x86"
+IUSE="doc"
+
+DEPEND=">=net-firewall/iptables-1.2.4
+       sys-apps/iproute2[-minimal]
+       dev-lang/perl
+       !net-firewall/shorewall-common
+       !net-firewall/shorewall-shell
+       !net-firewall/shorewall-perl"
+RDEPEND="${DEPEND}"
+
+src_prepare() {
+           epatch "${FILESDIR}/all_zone.patch"
+               epatch_user
+}
+
+src_compile() {
+       :;
+}
+
+src_install() {
+       keepdir /var/lib/shorewall
+
+       cd "${WORKDIR}/${P}${MY_P_BETA}"
+       PREFIX="${D}" ./install.sh || die "install.sh failed"
+       newinitd "${FILESDIR}"/shorewall.initd shorewall || die "doinitd failed"
+
+       dodoc changelog.txt releasenotes.txt || die
+
+       if use doc; then
+               cd "${WORKDIR}/${MY_P_DOCS}"
+               # install documentation
+               dohtml -r *
+               ## dosym Documentation_Index.html "/usr/share/doc/${PF}/html/index.htm"
+               # install samples
+               cp -pR "${S}${MY_P_BETA}/Samples" "${D}/usr/share/doc/${PF}"
+       fi
+}
+
+pkg_postinst() {
+       elog
+       if use doc ; then
+               elog "Documentation is available at /usr/share/doc/${PF}/html."
+               elog "Please read the Release Notes in /usr/share/doc/${PF}."
+               elog "Samples are available at /usr/share/doc/${PF}/Samples."
+       else
+               elog "Documentation is available at http://www.shorewall.net"
+       fi
+       elog "There are man pages for shorewall(8) and for each configuration file."
+       elog
+       elog "Bridging configuration has changed with kernel 2.6.20+."
+       elog "Check the documentation."
+       elog
+       elog "Do not blindly start shorewall, edit the files in /etc/shorewall first."
+       elog
+       elog "Be aware that version ${MY_PV_TREE} differs substantially from previous releases."
+       elog "Information on upgrading is available at:"
+       elog "http://www.shorewall.net/upgrade_issues.htm"
+       elog
+       elog "There is a 'shorewall compile' command to generate scripts to run"
+       elog "on systems with Shorewall Lite installed."
+       elog "Please refer to http://www.shorewall.net/CompiledPrograms.html"
+       elog "It is advised to copy the /usr/share/shorewall/configfiles dir to your"
+       elog "own 'export directories'. However, whenever you upgrade Shorewall you"
+       elog "should check for changes in configfiles and manually update your exports."
+       elog "Alternatively, if you only have one Shorewall-Lite system in your network"
+       elog "then you can use the configfiles dir but set CONFIG_PROTECT appropriately"
+       elog "in /etc/make.conf (man make.conf)."
+       elog
+       elog "Known problems:"
+       elog "http://shorewall.net/pub/${PN}/${MY_PV_TREE}/${MY_P}/known_problems.txt"
+       elog
+       elog "Whether upgrading or installing you should run shorewall check,"
+       elog "correct any errors found and run shorewall restart|start."
+       elog
+       elog "${PN} now uses Perl only. The shell compiler is obsolete."
+       elog "shorewall-common, shorewall-shell and shorewall-perl have been removed."
+}