All of lore.kernel.org
 help / color / mirror / Atom feed
* bussybox: updating to new version
@ 2017-08-18 10:16 Andrej Valek
  2017-08-18 16:00 ` Khem Raj
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Andrej Valek @ 2017-08-18 10:16 UTC (permalink / raw)
  To: openembedded-core

Hello everyone,

I would like to ask you a question about busybox upgrading.

Is there any reason, why we are still using the version 1.24.1?
I think that, the latest version 1.27.2 has a lot of fixes and it less
vulnerable then the current.

I have checked a license and it has not been changed.

Thank you for the explanation.

Andrej


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: bussybox: updating to new version
  2017-08-18 10:16 bussybox: updating to new version Andrej Valek
@ 2017-08-18 16:00 ` Khem Raj
  2017-08-18 16:12 ` Leonardo Sandoval
  2017-09-04 11:34 ` Burton, Ross
  2 siblings, 0 replies; 4+ messages in thread
From: Khem Raj @ 2017-08-18 16:00 UTC (permalink / raw)
  To: Andrej Valek; +Cc: openembedded-core

On Fri, Aug 18, 2017 at 3:16 AM, Andrej Valek <andrej.valek@siemens.com> wrote:
> Hello everyone,
>
> I would like to ask you a question about busybox upgrading.
>
> Is there any reason, why we are still using the version 1.24.1?
> I think that, the latest version 1.27.2 has a lot of fixes and it less
> vulnerable then the current.
>

I dont think its intentional. Feel free to send a patch if you can.

> I have checked a license and it has not been changed.
>
> Thank you for the explanation.
>
> Andrej
> --
> _______________________________________________
> Openembedded-core mailing list
> Openembedded-core@lists.openembedded.org
> http://lists.openembedded.org/mailman/listinfo/openembedded-core


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: bussybox: updating to new version
  2017-08-18 10:16 bussybox: updating to new version Andrej Valek
  2017-08-18 16:00 ` Khem Raj
@ 2017-08-18 16:12 ` Leonardo Sandoval
  2017-09-04 11:34 ` Burton, Ross
  2 siblings, 0 replies; 4+ messages in thread
From: Leonardo Sandoval @ 2017-08-18 16:12 UTC (permalink / raw)
  To: Andrej Valek; +Cc: openembedded-core

On Fri, 2017-08-18 at 12:16 +0200, Andrej Valek wrote:
> Hello everyone,
> 
> I would like to ask you a question about busybox upgrading.
> 
> Is there any reason, why we are still using the version 1.24.1?
> I think that, the latest version 1.27.2 has a lot of fixes and it less
> vulnerable then the current.
> 

feel free to send a patch with the upgrade. BTW, this is the upgrade
history of the recipe

http://recipes.yoctoproject.org/rrs/recipedetail/12601/

> I have checked a license and it has not been changed.
> 
> Thank you for the explanation.
> 
> Andrej




^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: bussybox: updating to new version
  2017-08-18 10:16 bussybox: updating to new version Andrej Valek
  2017-08-18 16:00 ` Khem Raj
  2017-08-18 16:12 ` Leonardo Sandoval
@ 2017-09-04 11:34 ` Burton, Ross
  2 siblings, 0 replies; 4+ messages in thread
From: Burton, Ross @ 2017-09-04 11:34 UTC (permalink / raw)
  To: Andrej Valek; +Cc: openembedded-core

[-- Attachment #1: Type: text/plain, Size: 603 bytes --]

On 18 August 2017 at 11:16, Andrej Valek <andrej.valek@siemens.com> wrote:

> Hello everyone,
>
> I would like to ask you a question about busybox upgrading.
>
> Is there any reason, why we are still using the version 1.24.1?
> I think that, the latest version 1.27.2 has a lot of fixes and it less
> vulnerable then the current.
>
> I have checked a license and it has not been changed.
>
> Thank you for the explanation.
>

The last time an upgrade was submitted it ended up with /bin/sh being suid
root so was understandably rejected.  Nobody has submitted an upgrade since.

Ross

[-- Attachment #2: Type: text/html, Size: 961 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2017-09-04 11:34 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-08-18 10:16 bussybox: updating to new version Andrej Valek
2017-08-18 16:00 ` Khem Raj
2017-08-18 16:12 ` Leonardo Sandoval
2017-09-04 11:34 ` Burton, Ross

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.