gd: security bump to version 2.2.5
authorPeter Korsgaard <peter@korsgaard.com>
Thu, 7 Sep 2017 14:45:51 +0000 (16:45 +0200)
committerPeter Korsgaard <peter@korsgaard.com>
Fri, 8 Sep 2017 09:13:57 +0000 (11:13 +0200)
commit3b85d24c1d927590ed3a336794562e9a512fc216
treea383f07f5182b9b80680b00f43c95e5adbb6b987
parentf396d1310b630c8d2307f505ec95a17d27d29f23
gd: security bump to version 2.2.5

Fixes the following security issues:

CVE-2017-6362: Double-free in gdImagePngPtr()
CVE-2017-7890: Buffer over-read into uninitialized memory

Drop patches no more needed:

0001-gdlib-config.patch: @LIBICONV@ is nowadays correct AC_SUBST'ed by
configure

0002-gd_bmp-fix-build-with-uClibc.patch: upstream uses ceil() since
https://github.com/libgd/libgd/commit/6913dd3cd2a7c2914ad9622419f9343bfe956135

While we're at it, add a hash for the license file.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/gd/0001-gdlib-config.patch [deleted file]
package/gd/0002-gd_bmp-fix-build-with-uClibc.patch [deleted file]
package/gd/gd.hash
package/gd/gd.mk