Addresses https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6250
Update zmq to 4.3.1 #15188
pull rex4539 wants to merge 1 commits into bitcoin:master from rex4539:update-zmq changing 2 files +3 −3-
rex4539 commented at 4:26 PM on January 17, 2019: contributor
-
hebasto commented at 4:35 PM on January 17, 2019: member
Should doc/dependencies.md be updated as well?
- laanwj added the label Build system on Jan 17, 2019
- laanwj added the label Needs backport on Jan 17, 2019
- laanwj added this to the milestone 0.17.2 on Jan 17, 2019
-
laanwj commented at 4:47 PM on January 17, 2019: member
adding backport label for 0.17.2 as this is a security bugfix
- laanwj added the label Needs gitian build on Jan 17, 2019
-
practicalswift commented at 8:33 PM on January 17, 2019: contributor
Concept ACK
-
fanquake commented at 3:25 AM on January 18, 2019: member
Concept ACK. I had a local branch with the same change. We'll need to review changes to
libzmq.pcand related build files.Note: At the moment, trying to
./configureCore with a brew installed zeromq (only version 4.3.1), is broken. Related PRs https://github.com/Homebrew/homebrew-core/pull/35940 & https://github.com/Homebrew/homebrew-core/pull/36121. -
3046e5fc01
Update zmq to 4.3.1
Addresses https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6250
-
in doc/dependencies.md:29 in fea0e7e74a outdated
25 | @@ -26,5 +26,5 @@ These are the dependencies currently used by Bitcoin Core. You can find instruct 26 | | Qt | [5.9.7](https://download.qt.io/official_releases/qt/) | [5.2](https://github.com/bitcoin/bitcoin/pull/14725) | No | | | 27 | | XCB | | | | | [Yes](https://github.com/bitcoin/bitcoin/blob/master/depends/packages/qt.mk#L87) (Linux only) | 28 | | xkbcommon | | | | | [Yes](https://github.com/bitcoin/bitcoin/blob/master/depends/packages/qt.mk#L86) (Linux only) | 29 | -| ZeroMQ | [4.2.5](https://github.com/zeromq/libzmq/releases) | 4.0.0 | No | | | 30 | +| ZeroMQ | [4.3.1](https://github.com/zeromq/libzmq/releases) | 4.0.0 | Yes | | |
fanquake commented at 3:26 AM on January 18, 2019:If we are updating for the CVE, this should remain as
No.DrahtBot commented at 1:32 PM on January 18, 2019: member<!--a722867cd34abeea1fadc8d60700f111-->
Gitian builds for commit 12b30105fc59daef2ae2fd8f81be1159ca68f94a (master):
f42c5da596c6c7b974cb2c53ba133fae...bitcoin-0.17.99-aarch64-linux-gnu-debug.tar.gze1ba57bab31824475df0212c2c473f43...bitcoin-0.17.99-aarch64-linux-gnu.tar.gz87a9c200633e81bf9bf19d354b9938ad...bitcoin-0.17.99-arm-linux-gnueabihf-debug.tar.gzce5f3c165d57f0d1a8846fd721850025...bitcoin-0.17.99-arm-linux-gnueabihf.tar.gz25e1f6836152f151cff5b804e5ad718c...bitcoin-0.17.99-i686-pc-linux-gnu-debug.tar.gzfa0cf17b130c041fb444d5b9bc87b143...bitcoin-0.17.99-i686-pc-linux-gnu.tar.gzead87c34a7b3af746bce2f590e2ebaa1...bitcoin-0.17.99-osx-unsigned.dmge746ab34689b835f37aae5d8da289821...bitcoin-0.17.99-osx64.tar.gzaeb16ad83f2616de743598b9155c128e...bitcoin-0.17.99-riscv64-linux-gnu-debug.tar.gze1f85ba54c4303dd7d5679ef1228d6d6...bitcoin-0.17.99-riscv64-linux-gnu.tar.gz8930fa2dfb19187cec2f14721e8d0fdd...bitcoin-0.17.99-win32-debug.zip713005fd1f1c2b09568c38369f9fee0d...bitcoin-0.17.99-win32-setup-unsigned.exedcda001e6c6220e9df504739a4d7fedf...bitcoin-0.17.99-win32.zipe4a502cea3bf09e14381a6f81f6ea2eb...bitcoin-0.17.99-win64-debug.zip8b7d2b3c41e0d057e6a9aff89554df26...bitcoin-0.17.99-win64-setup-unsigned.exec20d88be72ecc046f2e28b0556986303...bitcoin-0.17.99-win64.zip27cb4e8932c4fd38495855e388ac431f...bitcoin-0.17.99-x86_64-linux-gnu-debug.tar.gze1e98f412eec2f6485cfacfe3f93c056...bitcoin-0.17.99-x86_64-linux-gnu.tar.gz54f5fcdfda10f8c558760bf405fded49...bitcoin-0.17.99.tar.gz3e9c2fda5bb85b37c0ac18d919100842...bitcoin-linux-0.18-res.yml5c46e05a5b4e13b2ac8f9a39d9cf7f74...bitcoin-linux-build.log515955065476b6149b3d5606b0188bbd...bitcoin-osx-0.18-res.yml78135ea57882c343ae33ba614925e4ce...bitcoin-osx-build.logfdd9fc9a249c2b6385a6042c3a6f2a95...bitcoin-win-0.18-res.ymlc00923378d1c2ed388de91b135e8df01...bitcoin-win-build.log
Gitian builds for commit 607eaa233355590ec4c2fdd532201e1a8edcd5bd (master and this pull):
185621fe389033dfe2c8052b13907a8e...bitcoin-0.17.99-aarch64-linux-gnu-debug.tar.gz597c257b292c906282355cc39c090dad...bitcoin-0.17.99-aarch64-linux-gnu.tar.gz6ec8c814dc544483607dbfa055c421fc...bitcoin-0.17.99-arm-linux-gnueabihf-debug.tar.gz9460d390098d38f55ca8c29a7366f5a5...bitcoin-0.17.99-arm-linux-gnueabihf.tar.gz7e7359bc20423d99edb812dac586ae2b...bitcoin-0.17.99-i686-pc-linux-gnu-debug.tar.gz271fd387734a8a264545b20e5491d1cc...bitcoin-0.17.99-i686-pc-linux-gnu.tar.gze8c8eb83b9a41d113b2182c0826b7b1a...bitcoin-0.17.99-osx-unsigned.dmg2ddc2a0592d7a9e18936d9e0796f3713...bitcoin-0.17.99-osx64.tar.gzd255089a736d4f2d4cd6e4de7e220120...bitcoin-0.17.99-riscv64-linux-gnu-debug.tar.gzf3013302a6f10700cca807268e315a6b...bitcoin-0.17.99-riscv64-linux-gnu.tar.gze092ffe47815cfd1a5a3129e65a18d9c...bitcoin-0.17.99-win32-debug.zipa00a3a297fee105b69a690009686abdb...bitcoin-0.17.99-win32-setup-unsigned.exe00e01fec552ada8dc43cfc172992b980...bitcoin-0.17.99-win32.zip8abf017591aa66164630a3712f0bb321...bitcoin-0.17.99-win64-debug.zip8475e9fad20f9a46711165c5bea2cc9f...bitcoin-0.17.99-win64-setup-unsigned.exe8a8d5f7402358a567fd256f892fda946...bitcoin-0.17.99-win64.zipe535c9b44be1e3c90f062d4105b3a4cf...bitcoin-0.17.99-x86_64-linux-gnu-debug.tar.gzaa88ed30b57e07b015454facffa9312f...bitcoin-0.17.99-x86_64-linux-gnu.tar.gze11e468ff9986393bb971ac1c1f4b15d...bitcoin-0.17.99.tar.gz833241e162c3004221ee79f099bc09cb...bitcoin-linux-0.18-res.yml746c6dd0fd03f34b713f6b71685c3d67...bitcoin-linux-build.log536f856a9c4688fee3085ab99d49ebe2...bitcoin-osx-0.18-res.yml73fc8403f171911b960e7c97ba3f0bea...bitcoin-osx-build.log10ada40cdb242f1778d989aecedf9515...bitcoin-win-0.18-res.yml02d881eaeb95d2ad074402d4f874fd07...bitcoin-win-build.log
DrahtBot removed the label Needs gitian build on Jan 18, 2019laanwj commented at 3:16 PM on January 18, 2019: memberutACK 3046e5fc019c7276300c65500fb4701e70f6c9d8
laanwj commented at 3:17 PM on January 18, 2019: memberNote: At the moment, trying to ./configure Core with a brew installed zeromq (only version 4.3.1), is broken. Related PRs Homebrew/homebrew-core#35940 & Homebrew/homebrew-core#36121.
As the gitian configure/build completes without problems, this seems to be specific to brew.
laanwj merged this on Jan 21, 2019laanwj closed this on Jan 21, 2019laanwj referenced this in commit 9fa2b89ed1 on Jan 21, 2019fanquake referenced this in commit 8418707286 on Jan 25, 2019fanquake removed the label Needs backport on Jan 25, 2019laanwj referenced this in commit 09a9238c04 on Jan 30, 2019sidhujag referenced this in commit d857393a6b on Feb 14, 2019thrasher- referenced this in commit 4bb0905839 on Feb 19, 2019thrasher- referenced this in commit e134c28ab3 on Feb 19, 2019justinvforvendetta referenced this in commit 565bf431d1 on Feb 19, 2019justinvforvendetta referenced this in commit c8cf8ce2bd on Feb 19, 2019justinvforvendetta referenced this in commit f78d0a80c3 on Feb 24, 2019justinvforvendetta referenced this in commit 0eee18b002 on Feb 24, 2019justinvforvendetta referenced this in commit 96e1b3cb57 on Feb 28, 2019Rishabh42 referenced this in commit b4bf7944db on Mar 22, 2019uhliksk referenced this in commit f3ba0d3f26 on Apr 21, 2019Rishabh42 referenced this in commit ce3547fae6 on Apr 22, 2019uhliksk referenced this in commit 2eab86b94d on May 1, 2019deadalnix referenced this in commit 1a7a047db4 on Mar 31, 2020ftrader referenced this in commit 55c001e63f on Aug 13, 2021dzutto referenced this in commit 7033d51f70 on Sep 9, 2021UdjinM6 referenced this in commit 1dbf7b9d83 on Sep 9, 2021DrahtBot locked this on Dec 16, 2021LabelsMilestone
0.17.2
This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-04-26 09:15 UTC
More mirrored repositories can be found on mirror.b10c.me