Commit Graph

257 Commits

Author SHA1 Message Date
Tobias Frost
bb305bcdf7 Fix segfault in CVE-2023-39355.patch
(and use posix_memalign instead of memalign)
2023-10-07 17:08:05 +02:00
Tobias Frost
f1641af0fd Touch changelog timestamp. 2023-10-07 13:29:57 +02:00
Tobias Frost
b743b819c0 CVE-2023-40589 2023-10-07 13:29:15 +02:00
Tobias Frost
d9179e0766 CVE-2023-40569 2023-10-07 13:27:15 +02:00
Tobias Frost
24c51f4ed8 CVE-2023-40188.patch 2023-10-07 13:17:33 +02:00
Tobias Frost
f6f2bf7896 CVE-2023-40186 2023-10-07 13:11:23 +02:00
Tobias Frost
0f3fd7d339 0045-CVE-2023-40181.patch 2023-10-07 12:53:23 +02:00
Tobias Frost
d1217c6dad Apply upstream patch for CVE-2023-40567. 2023-10-07 12:53:18 +02:00
Tobias Frost
09055cabae Backport upstream patch for CVE-2023-39356. 2023-10-07 12:33:20 +02:00
Tobias Frost
ab18013d96 Backport CVE-2023-39354. 2023-10-07 12:07:10 +02:00
Tobias Frost
2dacc519e5 Backport patch for CVE-2023-39353. 2023-10-07 11:28:59 +02:00
Tobias Frost
792f6a14d1 Backport patch for CVE-2023-39352. 2023-10-07 11:10:12 +02:00
Tobias Frost
a4c483bc30 Cherry-pick upstream patch for CVE-2023-39351. 2023-10-07 10:58:09 +02:00
Tobias Frost
43cbb16760 Revisit CVE-2023-39350 after updates/clarifactions from upstream. 2023-10-07 10:51:05 +02:00
Tobias Frost
500b4499a7 Backport CVE-2023-40589.
replaced WINPR_ASSERT with plain assert, as this macro is defined only in later versions and if verbose asserting is disabled it will actually do assert() itself.
2023-10-03 11:14:37 +02:00
Tobias Frost
6ae95183f4 Backport of CVE-2023-39355
upstream is using in later version aligned memory allocation, so using memaling to simulate that.
That of course required to memset it afterwards, as upstream used calloc for the allocation before.
2023-10-03 10:57:01 +02:00
Tobias Frost
21305b53c4 Disable piuparts and blhc
piuparts is broken for buster
blhc is failing, but not going to fix that for the DLA.
2023-10-03 10:15:50 +02:00
Tobias Frost
efc916e1a4 CVE-2023-39354 2023-10-03 10:08:48 +02:00
Tobias Frost
b6e609f697 CVE-2023-39350 2023-10-03 10:07:13 +02:00
Tobias Frost
0333c99067 Enable Salsa CI 2023-10-03 09:35:54 +02:00
Tobias Frost
6e4db706a5 Debian release 2.3.0+dfsg1-2+deb11u1
-----BEGIN PGP SIGNATURE-----
 
 iQJVBAABCAA/FiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAmInCfghHG1pa2UuZ2Fi
 cmllbEBkYXMtbmV0endlcmt0ZWFtLmRlAAoJEJr0azAldxsxnVsP/iCyxT55ot9U
 DP/mn1sY4R10wEu306RiSHYpIHdhoI5zmpwywq936DC/J7WUebZD0PZfANv5lioX
 VwoJSVXUhsvk67VTR77zFsTwU66E4mtvruh6rP0SO6ooRRbqQedVFsZAAMbugHAL
 3bMPMbJ1jklWsIui/x3ggmEQ5wy8c1kOIttn8PXmo/h4P3cOuuHDSJM1y0BpoqIs
 P7MsK3TTycobUg1sgrtrj/rKrIeqiS3NRZQ0VSiHunSCQdPYPm5CChSaVsgyAenC
 VmnU5+pLSgBYunMh7OFUQCgdBQzKnUIZ9BSxc3ybRnW5hqREpdcwMZ8Nf8oLluEw
 1FYSaqNKpfP0CkwkjWO0qPXiWIoqZIhGC1xA5SivNf2poWkmhhwLH+PXZFHCmlFc
 ba8iFrG9gt4tSM45mVbpJTHbNTHjwsQpbHB+V9zyWt5VC5zsdzsIn1Kxl8obGdvD
 JN+3oo9yTrVw4Mh5fmN52aRtmrd/QVeJKTBv8zN9L7LFi/8Bwb5P7lsqlArNOpQi
 oL1xt6Uv2nHowCteue75DKEt3Q7hxKUrZFtjTPjbuv2ZJk2TSJ27rv9RQ4dhj7hO
 RCDg2sa/AMnyrj0pK9wtaRpUrhAuKEHRfs+8n39z2aqi6CMbMM3p3P8DB2bjhpcc
 v1IXrs60cxRvsg1zhL2bhk1KCAVJrkZc
 =01RW
 -----END PGP SIGNATURE-----

Merge tag 'debian/2.3.0+dfsg1-2+deb11u1' into debian/buster to prepare a
backport for buster.

Debian release 2.3.0+dfsg1-2+deb11u1

Adapt to buster.
2023-10-03 01:16:50 +02:00
Mike Gabriel
0359d79a4b upload to bullseye (debian/2.3.0+dfsg1-2+deb11u1) 2022-03-08 08:46:53 +01:00
Mike Gabriel
6dd3e7854d debian/patches: Trivial rebase of 1001_keep-symbol-DumpThreadHandles-if-debugging-is-disabled.patch against v2.3.0. 2022-03-08 08:45:25 +01:00
Mike Gabriel
03201de47f debian/patches: Add 1001_keep-symbol-DumpThreadHandles-if-debugging-is-disabled.patch. Keep DumpThreadHandles as a symbol even if WITH_DEBUG_THREADS is OFF.
(cherry picked from commit f726052dd4)
2022-03-08 08:44:42 +01:00
Bernhard Miklautz
4db4aa6d33 debian/rules: Disable additional debug logging. (Closes: #1006683).
(cherry picked from commit a90b67e6c0)
2022-03-08 08:15:32 +01:00
Mike Gabriel
21d2367ceb upload to unstable (debian/2.3.0+dfsg1-2) 2021-05-16 23:57:27 +02:00
Mike Gabriel
1a69e83215 debian/patches: Add 0035-Fixed-6989-Use-X509_STORE_set_default_paths.patch. Fix Windows 10 logon when using an internal trusted root CA. 2021-05-16 23:37:01 +02:00
Mike Gabriel
91e29c5e59 debian/patches: Add 0034-Fixed-6938-Remote-app-mode-clipboard-fix.patch. In remote app mode the _FREERDP_TIMESTAMP_PROPERTY does not work. Therefore ignore it. 2021-05-16 23:32:35 +02:00
Mike Gabriel
ff70cab82f debian/patches: add forgotten patch files 2021-04-29 12:34:37 +02:00
Mike Gabriel
2d7707f3f8 debian/changelog: update from Git history 2021-04-29 12:18:15 +02:00
Mike Gabriel
fc8bd9add6 debian/patches: Backport changes from 2.3.2 (bound checks, API compat fixes, Smartcard issues fixes, etc.).
0001-Added-compatibility-define.patch
    0003-Reverted-connectErrorCode-removal.patch
    0004-Fixed-a-leak-on-mouse-cursor-updates.patch
    0007-Fixed-format-string-in-smartcard_trace_state_return.patch
    0008-Fixed-linking-dependencies-for-client-geometry-chann.patch
    0010-Fixed-smartcard_convert_string_list-with-0-length.patch
    0012-Parse-on-a-copy-of-the-argument-string-for-printer.patch
    0015-Fix-xf_Pointer_SetPosition-with-smart-sizing.patch
    0017-Backported-6865-Disable-websockets-command-line-opti.patch
    0019-Check-smartcard_convert_string_list-for-NULL-string.patch
    0020-Use-specific-names-for-drive-hotplug-special-values.patch
    0021-Filter-RDPDR-types-other-than-drives-on-windows-hotp.patch
    0023-use-tlsOut-BIO-when-using-websocket-in-rdg_bio_ctrl.patch
    0024-Added-bounds-checks-to-gfx-commands.patch
    0025-Added-bounds-check-in-rdpgfx_recv_wire_to_surface_1_.patch
    0026-Added-fuzzying-test-for-planar-decoder.patch
    0027-Added-missing-bounds-check.patch
    0028-Fixed-mac-issues-with-smartcard-context-cleanup-6890.patch
    0031-Fix-monitor-list.patch
    0032-Fixed-CodeQL-warnings.patch
    0033-Reverted-winpr_BinToHexString-argument-change.patch
2021-04-29 12:05:39 +02:00
Mike Gabriel
a58a05cff9 debian/watch: Fix Github watch URL. 2021-04-29 11:54:12 +02:00
Mike Gabriel
702fe3f9aa upload to unstable (debian/2.3.0+dfsg1-1) 2021-02-25 16:50:58 +01:00
Mike Gabriel
bf9eaf6dde debian/control: Bump to Standards-Version: 4.5.1. No changes needed. 2021-02-25 16:16:25 +01:00
Mike Gabriel
4a2c5cc4fa debian/watch: Switch to format version 4. 2021-02-25 16:15:48 +01:00
Mike Gabriel
1fc6dbb280 debian/*.symbols: Update symbols for FreeRDP 2.3.0. 2021-02-25 16:14:28 +01:00
Mike Gabriel
69806bec69 debian/patches: Revert upstream's removal of the connectErrorCode symbol via 2002_revert-e4b30a5cb6100a8ea4f320b829c9c5712ed4a783.patch. This re-instates ABI compatibility with FreeRDP 2.2.0. 2021-02-25 16:14:02 +01:00
Mike Gabriel
5243d7ecba debian/patches: Drop 1001_spelling-fixes.patch. Applied upstream. 2021-02-25 16:13:02 +01:00
Mike Gabriel
6e36b45ff9 debian/copyright: Update copyright attributions: 2021-02-25 16:12:08 +01:00
Mike Gabriel
98586d2380 debian/copyright: Update auto-generated copyright.in file. 2021-02-25 16:11:54 +01:00
Mike Gabriel
0dc851016e Update upstream source from tag 'upstream/2.3.0+dfsg1'
Update to upstream version '2.3.0+dfsg1'
with Debian dir aaa97caffc
2021-02-25 15:19:16 +01:00
Mike Gabriel
3685742385 New upstream version 2.3.0+dfsg1 2021-02-25 15:19:08 +01:00
Mike Gabriel
ed9b274020 prepare new upstream release (v2.3.0+dfsg1) 2021-02-25 15:07:23 +01:00
Mike Gabriel
6d198059a2 Merge branch 'fix-backports-deps' into 'master'
Add missed binary version deps to avoid issue in some cases like upgrade to -backports

See merge request debian-remote-team/freerdp2!4
2021-02-25 14:05:13 +00:00
Fabio Fantoni
7966d9219f Add missed binary version deps to avoid issue in some cases like upgrade to -backports
In some cases like upgrade to -backports don't update all deps correctly
causing issues.
I already had in past, doing for example:
sudo apt -t buster-backports install freerdp2-x11
and latest times I workaround it with:
sudo apt -t buster-backports install freerdp2-x11 libfreerdp-client2-2
libfreerdp2-2 libwinpr2-2

This commit solve this issue adding binary version dependency on any
component (not only for x11 client but also wayland client, server and
other components used by other software, for example remmina).
Also avoided to add duplicate entries (if already present in other deps
of the component)

Closes: #964147
2021-02-15 15:51:02 +01:00
Mike Gabriel
b87910fc96 upload to unstable (debian/2.2.0+dfsg1-1) 2020-08-25 09:47:07 +02:00
Mike Gabriel
c118a0148b debian/libfreerdp-server2-2.symbols: Update symbols. 2020-08-25 09:45:26 +02:00
Mike Gabriel
cd9ec0da61 debian/libfreerdp2-2.symbols: Update symbols. 2020-08-25 09:35:27 +02:00
Mike Gabriel
fe6378ecd3 debian/copyright: Update copyright attributions. 2020-08-25 09:35:15 +02:00
Mike Gabriel
5c9c6b6890 debian/patches: Drop 0001-mask-CACHED_BRUSH-when-checking-brush-style.patch. Applied upstream. 2020-08-25 09:22:25 +02:00