package/thrift: security bump to version 0.14.1
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Sun, 13 Jun 2021 09:13:56 +0000 (11:13 +0200)
committerArnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
Tue, 13 Jul 2021 20:05:43 +0000 (22:05 +0200)
commit7ecbb956e2c6a6dd42126657e05e86072f3fc140
tree4c4e22c11c32c1aaa549de727e97167847e192e5
parent5675f09e584e124201451a0feee6e22d8ea2b84a
package/thrift: security bump to version 0.14.1

Fix CVE-2020-13949: In Apache Thrift 0.9.3 to 0.13.0, malicious RPC
clients could send short messages which would result in a large memory
allocation, potentially leading to denial of service.

- Disable javascript and nodejs which have been added with
  https://github.com/apache/thrift/commit/61d502075bf5da10331c201f604acdfefc4d5edc
- Update hash of LICENSE, license for windows-specific files added:
  https://github.com/apache/thrift/commit/98854c48744f20b3f551817273ed502835477f09

https://github.com/apache/thrift/blob/v0.14.1/CHANGES.md

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
package/thrift/thrift.hash
package/thrift/thrift.mk