Subject: CVS commit: pkgsrc/net
From: Thomas Klausner
Date: 2018-01-16 10:37:00
Message id: 20180116093700.96098FBDE@cvs.NetBSD.org

Log Message:
transmission*: Fix security issue

Fix a weakness that allows remote code execution via the Transmission
RPC server using DNS rebinding:

https://bugs.chromium.org/p/project-zero/issues/detail?id=1447

Patch adapted from Tavis Ormandy's patch on the Transmission master
branch to the Transmission 2.92 release by Leo Famulari
<leo@famulari.name>:

https://github.com/transmission/transmission/pull/468/commits

Via FreeBSD ports.

Bump PKGREVISION.

Files:
RevisionActionfile
1.13modifypkgsrc/net/transmission/Makefile
1.13modifypkgsrc/net/transmission/distinfo
1.26modifypkgsrc/net/transmission-gtk/Makefile
1.30modifypkgsrc/net/transmission-qt/Makefile
1.1addpkgsrc/net/transmission/patches/patch-libtransmission_quark.c
1.1addpkgsrc/net/transmission/patches/patch-libtransmission_quark.h
1.1addpkgsrc/net/transmission/patches/patch-libtransmission_rpc-server.c
1.1addpkgsrc/net/transmission/patches/patch-libtransmission_rpc-server.h
1.1addpkgsrc/net/transmission/patches/patch-libtransmission_session.c
1.1addpkgsrc/net/transmission/patches/patch-libtransmission_transmission.h
1.1addpkgsrc/net/transmission/patches/patch-libtransmission_web.c