package/spice: security bump to version 0.15.0
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Wed, 16 Jun 2021 06:10:01 +0000 (08:10 +0200)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Sun, 18 Jul 2021 21:29:47 +0000 (23:29 +0200)
Fix CVE-2021-20201: A flaw was found in spice in versions before
0.14.92. A DoS tool might make it easier for remote attackers to cause a
denial of service (CPU consumption) by performing many renegotiations
within a single connection.

https://gitlab.freedesktop.org/spice/spice/-/tags/v0.15.0

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/spice/spice.hash
package/spice/spice.mk

index 8f84c2321fba1601706b87cb5c7d91b696c8ed2e..b228f213a5467df2fa61e88fa931d6a3033530e7 100644 (file)
@@ -1,3 +1,3 @@
 # Locally calculated
-sha256  551d4be4a07667cf0543f3c895beb6da8a93ef5a9829f2ae47817be5e616a114  spice-0.14.3.tar.bz2
+sha256  b320cf8f4bd2852750acb703c15b72856027e5a8554f8217dfbb3cc09deba0f5  spice-0.15.0.tar.bz2
 sha256  dc626520dcd53a22f727af3ee42c770e56c97a64fe3adb063799d8ab032fe551  COPYING
index b515431cf1a349e5a06c7e82e6428db6dcec9844..ab35265ab41dbbd65b598a4c46ce18869c85ca9b 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-SPICE_VERSION = 0.14.3
+SPICE_VERSION = 0.15.0
 SPICE_SOURCE = spice-$(SPICE_VERSION).tar.bz2
 SPICE_SITE = http://www.spice-space.org/download/releases/spice-server
 SPICE_LICENSE = LGPL-2.1+