Subject: CVS commit: pkgsrc/net/dhcpcd
From: Roy Marples
Date: 2019-04-26 16:39:24
Message id: 20190426143924.24971FB16@cvs.NetBSD.org

Log Message:
Import dhcpcd-7.2.1 with the following changes:
*  Solaris: Many more issues fixed
*  OpenBSD: Don't spam syslog when cannot send NA
*  FreeBSD: Fix fetching IPv6 address lifetimes

These security issues are also addressed:
*  auth: Use consttime_memequal to avoid latency attack
   consttime_memequal is supplied if libc does not support it
   dhcpcd >=6.2 <7.2.1 are vulnerable

*  DHCP: Fix a potential 1 byte read overflow with DHO_OPTSOVERLOADED
   dhcpcd >=4 <7.2.1 are vulnerable

*  DHCPv6: Fix a potential buffer overflow reading NA/TA addresses
   dhcpcd >=7 <7.2.1 are vulnerable

Many thanks to Maxime Villard <max@m00nbsd.net> for discovering these issues.

Files:
RevisionActionfile
1.81modifypkgsrc/net/dhcpcd/Makefile
1.78modifypkgsrc/net/dhcpcd/distinfo