package/ghostscript: security bump to version 9.53.0
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Sat, 12 Sep 2020 16:59:07 +0000 (18:59 +0200)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Sun, 13 Sep 2020 19:22:28 +0000 (21:22 +0200)
commitcae8be20edc59ab80fd97790e7015f5d8f7e556b
treed1df86d494def9c4fa06eae75dc02991419b7308
parentf9a2d65cae88ca7c641af2f69161ab0d21bac91c
package/ghostscript: security bump to version 9.53.0

- Use tar.gz as SHA512SUMS does not contain the hash for tar.xz
- Fix CVE-2020-15900: A memory corruption issue was found in Artifex
  Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator
  can allow overriding of file access controls. The 'rsearch'
  calculation for the 'post' size resulted in a size that was too large,
  and could underflow to max uint32_t.

https://www.ghostscript.com/doc/9.53.0/News.htm

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/ghostscript/0002-configure.ac-fix-cross-compilation.patch [new file with mode: 0644]
package/ghostscript/ghostscript.hash
package/ghostscript/ghostscript.mk