Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

alpine: bump 3.4.4 and fix openssl (CVE-2016-7052) #2266

Merged
merged 1 commit into from
Oct 18, 2016

Conversation

ncopa
Copy link
Contributor

@ncopa ncopa commented Oct 18, 2016

Alpine edge switched to libressl

Alpine edge switched to libressl
@yosifkit
Copy link
Member

diff --git a/alpine_3.1/rootfs.tar.gz b/alpine_3.1/rootfs.tar.gz
index 926dda9..9d42ff5 100644
Binary files a/alpine_3.1/rootfs.tar.gz and b/alpine_3.1/rootfs.tar.gz differ
diff --git a/alpine_3.2/rootfs.tar.gz b/alpine_3.2/rootfs.tar.gz
index 7320424..cd5306c 100644
Binary files a/alpine_3.2/rootfs.tar.gz and b/alpine_3.2/rootfs.tar.gz differ
diff --git a/alpine_3.3/rootfs.tar.gz b/alpine_3.3/rootfs.tar.gz
index 6aa53fe..4a94217 100644
Binary files a/alpine_3.3/rootfs.tar.gz and b/alpine_3.3/rootfs.tar.gz differ
diff --git a/alpine_edge/rootfs.tar.gz b/alpine_edge/rootfs.tar.gz
index c70660f..464dcb5 100644
Binary files a/alpine_edge/rootfs.tar.gz and b/alpine_edge/rootfs.tar.gz differ
diff --git a/alpine_edge/rootfs.tar.gz  'tar -t' b/alpine_edge/rootfs.tar.gz  'tar -t'
index 517f6d6..a196a43 100644
--- a/alpine_edge/rootfs.tar.gz  'tar -t'   
+++ b/alpine_edge/rootfs.tar.gz  'tar -t'   
@@ -159,8 +159,10 @@
 ./lib/firmware/
 ./lib/ld-musl-x86_64.so.1
 ./lib/libc.musl-x86_64.so.1
-./lib/libcrypto.so.1.0.0
-./lib/libssl.so.1.0.0
+./lib/libcrypto.so.38
+./lib/libcrypto.so.38.0.0
+./lib/libssl.so.39
+./lib/libssl.so.39.0.0
 ./lib/libz.so.1
 ./lib/libz.so.1.2.8
 ./lib/mdev/
@@ -187,6 +189,7 @@
 ./sbin/fstrim
 ./sbin/getty
 ./sbin/halt
+./sbin/hdparm
 ./sbin/hwclock
 ./sbin/ifconfig
 ./sbin/ifdown
@@ -252,7 +255,6 @@
 ./usr/bin/clear
 ./usr/bin/cmp
 ./usr/bin/comm
-./usr/bin/c_rehash
 ./usr/bin/crontab
 ./usr/bin/cryptpw
 ./usr/bin/cut
@@ -376,21 +378,10 @@
 ./usr/bin/xzcat
 ./usr/bin/yes
 ./usr/lib/
-./usr/lib/engines/
-./usr/lib/engines/lib4758cca.so
-./usr/lib/engines/libaep.so
-./usr/lib/engines/libatalla.so
-./usr/lib/engines/libcapi.so
-./usr/lib/engines/libchil.so
-./usr/lib/engines/libcswift.so
-./usr/lib/engines/libgmp.so
-./usr/lib/engines/libgost.so
-./usr/lib/engines/libnuron.so
-./usr/lib/engines/libpadlock.so
-./usr/lib/engines/libsureware.so
-./usr/lib/engines/libubsec.so
-./usr/lib/libcrypto.so.1.0.0
-./usr/lib/libssl.so.1.0.0
+./usr/lib/libcrypto.so.38
+./usr/lib/libcrypto.so.38.0.0
+./usr/lib/libssl.so.39
+./usr/lib/libssl.so.39.0.0
 ./usr/local/
 ./usr/local/bin/
 ./usr/local/lib/
diff --git a/alpine_latest/rootfs.tar.gz b/alpine_latest/rootfs.tar.gz
index 55794f2..1279a34 100644
Binary files a/alpine_latest/rootfs.tar.gz and b/alpine_latest/rootfs.tar.gz differ

Build test of #2266; 5bbfc90 (alpine):

$ bashbrew build alpine:3.1
Building bashbrew/cache:45cb4b4eae6f6534170188fa209e22c31f64ce15274992ef03db064af9ec0d01 (alpine:3.1)
Tagging alpine:3.1

$ test/run.sh alpine:3.1
testing alpine:3.1
    'utc' [1/4]...passed
    'cve-2014--shellshock' [2/4]...passed
    'no-hard-coded-passwords' [3/4]...passed
    'override-cmd' [4/4]...passed


$ bashbrew build alpine:3.2
Building bashbrew/cache:a70a0011b7b3d2e2ebb558831fcf62bf9019cd89356bd9bcc54ac66462d56b56 (alpine:3.2)
Tagging alpine:3.2

$ test/run.sh alpine:3.2
testing alpine:3.2
    'utc' [1/4]...passed
    'cve-2014--shellshock' [2/4]...passed
    'no-hard-coded-passwords' [3/4]...passed
    'override-cmd' [4/4]...passed


$ bashbrew build alpine:3.3
Building bashbrew/cache:96200d19c45a8bb75e73e35b606a8f8c9f4449e0fc52aeb6eb213aa90476f067 (alpine:3.3)
Tagging alpine:3.3

$ test/run.sh alpine:3.3
testing alpine:3.3
    'utc' [1/4]...passed
    'cve-2014--shellshock' [2/4]...passed
    'no-hard-coded-passwords' [3/4]...passed
    'override-cmd' [4/4]...passed


$ bashbrew build alpine:3.4
Building bashbrew/cache:5419aae11243d63680d07ebc8bbae11d02cbadac98fb005b3663dc79ee127327 (alpine:3.4)
Tagging alpine:3.4
Tagging alpine:latest

$ test/run.sh alpine:3.4
testing alpine:3.4
    'utc' [1/4]...passed
    'cve-2014--shellshock' [2/4]...passed
    'no-hard-coded-passwords' [3/4]...passed
    'override-cmd' [4/4]...passed


$ bashbrew build alpine:edge
Using bashbrew/cache:af0373ca73948394bdb5581df1cb79cda493acef05412d6c6f0928e950a10833 (alpine:edge)
Tagging alpine:edge

$ test/run.sh alpine:edge
testing alpine:edge
    'utc' [1/4]...passed
    'cve-2014--shellshock' [2/4]...passed
    'no-hard-coded-passwords' [3/4]...passed
    'override-cmd' [4/4]...passed

@tianon
Copy link
Member

tianon commented Oct 18, 2016

cc @caervs @toli

@yosifkit yosifkit merged commit 8b824e5 into docker-library:master Oct 18, 2016
@ncopa ncopa deleted the alpine-openssl-fixes branch October 19, 2016 07:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants