apr-util: security bump to version 1.6.1
authorBaruch Siach <baruch@tkos.co.il>
Mon, 30 Oct 2017 19:11:02 +0000 (21:11 +0200)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Mon, 30 Oct 2017 19:43:40 +0000 (20:43 +0100)
Fixes CVE-2017-12618: Out-of-bounds access in corrupted SDBM database.

Switch to bz2 compressed tarball.

Use upstream provided SHA256 hash.

Add license hash.

Signed-off-by: Baruch Siach <baruch@tkos.co.il>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/apr-util/apr-util.hash
package/apr-util/apr-util.mk

index 3db43960585b919fd5048aff50f8e09c004746fa..82ad475619e17e43d239dc64828f0728566636a0 100644 (file)
@@ -1,2 +1,4 @@
-# From http://archive.apache.org/dist/apr/apr-util-1.5.4.tar.gz.sha1
-sha1   72cc3ac693b52fb831063d5c0de18723bc8e0095        apr-util-1.5.4.tar.gz
+# From http://www.apache.org/dist/apr/apr-util-1.6.1.tar.bz2.sha256
+sha256 d3e12f7b6ad12687572a3a39475545a072608f4ba03a6ce8a3778f607dd0035b        apr-util-1.6.1.tar.bz2
+# Locally calculated
+sha256 ef5609d18601645ad6fe22c6c122094be40e976725c1d0490778abacc836e7a2        LICENSE
index bc0572e1109ab6699be661648222a8384a1510f1..c44cef009f82b6e41655e912ec71814abf3e3c5c 100644 (file)
@@ -4,7 +4,8 @@
 #
 ################################################################################
 
-APR_UTIL_VERSION = 1.5.4
+APR_UTIL_VERSION = 1.6.1
+APR_UTIL_SOURCE = apr-util-$(APR_UTIL_VERSION).tar.bz2
 APR_UTIL_SITE = http://archive.apache.org/dist/apr
 APR_UTIL_LICENSE = Apache-2.0
 APR_UTIL_LICENSE_FILES = LICENSE