tcpreplay: security bump to version 4.3.1
authorBaruch Siach <baruch@tkos.co.il>
Tue, 8 Jan 2019 16:13:58 +0000 (18:13 +0200)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 8 Jan 2019 20:06:40 +0000 (21:06 +0100)
commitf5961ff56a8db95d0f34c640e0b7d7e7b07e540e
treea4c0955e603a93bade1f730012c39b8c75d1b334
parent6d385dc403df5c485617e7f85291d0183bf5e915
tcpreplay: security bump to version 4.3.1

Upstream CHANGELOG entry for 4.3.0 lists these fixes:

    - CVE-2018-18408 use-after-free in post_args (#489)
    - CVE-2018-18407 heap-buffer-overflow csum_replace4 (#488)
    - CVE-2018-17974 heap-buffer-overflow dlt_en10mb_encode (#486)
    - CVE-2018-17580 heap-buffer-overflow fast_edit_packet (#485)
    - CVE-2018-17582 heap-buffer-overflow in get_next_packet (#484)
    - CVE-2018-13112 heap-buffer-overflow in get_l2len (#477 dup #408)

Drop tr_cv_libpcap_version and ac_cv_have_bpf; unused in current
configure script.

Make configure script use pcap-config to list library dependencies.
Unfortunately, pcap-config is not entirely correct, so we still need to
set the LIBS variable for static linking.

Use the smaller tar.xz archive.

Add license file hash.

Signed-off-by: Baruch Siach <baruch@tkos.co.il>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/tcpreplay/tcpreplay.hash
package/tcpreplay/tcpreplay.mk