Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f61d6f0c4a | ||
|
|
473640790f | ||
|
|
9ada818b86 | ||
|
|
381651fac0 |
@@ -10,6 +10,21 @@ HIGH: There is a critical bug that may affect a subset of users. Upgrade!
|
||||
CRITICAL: There is a critical bug affecting MOST USERS. Upgrade ASAP.
|
||||
--------------------------------------------------------------------------------
|
||||
|
||||
================================================================================
|
||||
Redis 3.2.5 Released Wed Oct 26 09:16:40 CEST 2016
|
||||
================================================================================
|
||||
|
||||
Upgrade urgency LOW: This release only fixes a compilation issue due to the
|
||||
missing -ldl at linking time.
|
||||
|
||||
zach shipko in commit 4736407:
|
||||
BSDs don't have -ldl
|
||||
1 file changed, 15 insertions(+), 5 deletions(-)
|
||||
|
||||
antirez in commit 9ada818:
|
||||
Fix modules compilation when libc malloc is used.
|
||||
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
================================================================================
|
||||
Redis 3.2.4 Released Mon Sep 26 08:58:21 CEST 2016
|
||||
================================================================================
|
||||
@@ -26,14 +41,25 @@ which is documented clearly here:
|
||||
|
||||
Thanks to Cory Duplantis of Cisco Talos for reporting the issue.
|
||||
|
||||
IMPACT:
|
||||
|
||||
The gist is that using CONFIG SET calls (or by manipulating redis.conf)
|
||||
an attacker is able to compromise certain fields of the "server" global
|
||||
structure, including the aof filename pointer, that could be made pointing
|
||||
to something else. In turn the AOF name is used in different contexts such
|
||||
as logging, rename(2) and open(2) syscalls, leading to potential problems.
|
||||
|
||||
Please note that since having access to CONFIG SET also means to be able
|
||||
to change the AOF filename (and many other things) directly, this issue
|
||||
actual real world impact is quite small, so I would not panik: if you
|
||||
have CONFIG SET level of access, you can do more and more easily.
|
||||
|
||||
AFFECTED VERSIONS:
|
||||
|
||||
All Redis 3.2.x versions are affected.
|
||||
|
||||
OTHER CHANGES IN THIS RELEASE:
|
||||
|
||||
This release also includes other things:
|
||||
|
||||
* TCP binding bug fixed when only certain addresses were available for
|
||||
|
||||
+15
-5
@@ -65,17 +65,27 @@ ifeq ($(uname_S),SunOS)
|
||||
FINAL_LIBS+= -ldl -lnsl -lsocket -lresolv -lpthread -lrt
|
||||
else
|
||||
ifeq ($(uname_S),Darwin)
|
||||
# Darwin (nothing to do)
|
||||
# Darwin
|
||||
FINAL_LIBS+= -ldl
|
||||
else
|
||||
ifeq ($(uname_S),AIX)
|
||||
# AIX
|
||||
FINAL_LDFLAGS+= -Wl,-bexpall
|
||||
FINAL_LIBS+= -pthread -lcrypt -lbsd
|
||||
|
||||
FINAL_LIBS+=-ldl -pthread -lcrypt -lbsd
|
||||
else
|
||||
ifeq ($(uname_S),OpenBSD)
|
||||
# OpenBSD
|
||||
FINAL_LIBS+= -lpthread
|
||||
else
|
||||
ifeq ($(uname_S),FreeBSD)
|
||||
# FreeBSD
|
||||
FINAL_LIBS+= -lpthread
|
||||
else
|
||||
# All the other OSes (notably Linux)
|
||||
FINAL_LDFLAGS+= -rdynamic
|
||||
FINAL_LIBS+= -pthread
|
||||
FINAL_LIBS+=-ldl -pthread
|
||||
endif
|
||||
endif
|
||||
endif
|
||||
endif
|
||||
endif
|
||||
@@ -95,7 +105,7 @@ endif
|
||||
ifeq ($(MALLOC),jemalloc)
|
||||
DEPENDENCY_TARGETS+= jemalloc
|
||||
FINAL_CFLAGS+= -DUSE_JEMALLOC -I../deps/jemalloc/include
|
||||
FINAL_LIBS+= ../deps/jemalloc/lib/libjemalloc.a -ldl
|
||||
FINAL_LIBS+= ../deps/jemalloc/lib/libjemalloc.a
|
||||
endif
|
||||
|
||||
REDIS_CC=$(QUIET_CC)$(CC) $(FINAL_CFLAGS)
|
||||
|
||||
+1
-1
@@ -1 +1 @@
|
||||
#define REDIS_VERSION "3.2.4"
|
||||
#define REDIS_VERSION "3.2.5"
|
||||
|
||||
Reference in New Issue
Block a user