wget: security bump to version 1.18
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Thu, 9 Jun 2016 22:04:14 +0000 (19:04 -0300)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Thu, 9 Jun 2016 22:13:29 +0000 (00:13 +0200)
Fixes:
CVE-2016-4971 - By default, on server redirects to a FTP resource, use
the original URL to get the local file name.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/wget/wget.hash
package/wget/wget.mk

index 159cd510f39683aa9b6bf2f2d71353cac0aa463c..6d267234e625893851e195df78bcc44502b614bb 100644 (file)
@@ -1,2 +1,2 @@
 # Locally calculated after checking pgp signature
-sha256  fe559b61eb9cc01635ac6206a14e02cb51591838c35fa83c7a4aacae0bdd97c9  wget-1.17.1.tar.xz
+sha256  b5b55b75726c04c06fe253daec9329a6f1a3c0c1878e3ea76ebfebc139ea9cc1  wget-1.18.tar.xz
index 2c6ccf264518affb5f87f887ad50fb3c705ca190..9cda76b6a213f001b885f1909a6a582ed6b5d96c 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-WGET_VERSION = 1.17.1
+WGET_VERSION = 1.18
 WGET_SOURCE = wget-$(WGET_VERSION).tar.xz
 WGET_SITE = $(BR2_GNU_MIRROR)/wget
 WGET_DEPENDENCIES = host-pkgconf