package/spice: security bump to version 0.14.2
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Sun, 17 Nov 2019 16:44:52 +0000 (17:44 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Sat, 23 Nov 2019 13:27:09 +0000 (14:27 +0100)
- Fix CVE-2019-3813: fix off-by-one error in group/slot boundary check
- Add license hash

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/spice/spice.hash
package/spice/spice.mk

index 1a25926ab20da28001c5d98f500f2f4d7f8fd6be..4243244129aa5515ea94d83dd1b491d4bb1c3caa 100644 (file)
@@ -1,2 +1,3 @@
 # Locally calculated
-sha256 1ead5de63d06eededed4017db37240f07bef0abffbaf621899647e7e685a1519        spice-0.14.1.tar.bz2
+sha256 b203b3882e06f4c7249a3150d90c84e1a90490d41ead255a3d2cede46f4a29a7        spice-0.14.2.tar.bz2
+sha256 dc626520dcd53a22f727af3ee42c770e56c97a64fe3adb063799d8ab032fe551        COPYING
index b663479920dde883a2944dc4273be071d0fa702a..8c421abf2e74e558ad412067dc1e367478392dab 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-SPICE_VERSION = 0.14.1
+SPICE_VERSION = 0.14.2
 SPICE_SOURCE = spice-$(SPICE_VERSION).tar.bz2
 SPICE_SITE = http://www.spice-space.org/download/releases/spice-server
 SPICE_LICENSE = LGPL-2.1+