package/libarchive: security bump to version 3.4.2
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Fri, 28 Feb 2020 22:12:34 +0000 (23:12 +0100)
committerYann E. MORIN <yann.morin.1998@free.fr>
Sat, 29 Feb 2020 16:43:59 +0000 (17:43 +0100)
commit6785c19bf5f76001b9a1237402b68fd8302e5620
tree3e34ec27a1bf1a9c9c1b97e9f2bfc54ae975b1b8
parent71d6e2cc054a3961c2357ac44ff961bc00829949
package/libarchive: security bump to version 3.4.2

- Fix CVE-2020-9308: archive_read_support_format_rar5.c in libarchive
  before 3.4.2 attempts to unpack a RAR5 file with an invalid or
  corrupted header (such as a header size of zero), leading to a SIGSEGV
  or possibly unspecified other impact.
- use --with-nettle to enable nettle support, see
  https://github.com/libarchive/libarchive/commit/f96a71144b7725ca4a94d84bd27d7dca8c2f58d2

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
[yann.morin.1998@free.fr:
  - drop new optional dependency to mbedtsl, forced off for now
]
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
package/libarchive/libarchive.hash
package/libarchive/libarchive.mk