apr: security bump to version 1.6.3
authorBaruch Siach <baruch@tkos.co.il>
Mon, 30 Oct 2017 19:11:01 +0000 (21:11 +0200)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Mon, 30 Oct 2017 19:43:39 +0000 (20:43 +0100)
Fixes CVE-2017-12613: Out-of-bounds array deref in apr_time_exp*()
functions.

Use upstream provided SHA256 hash.

Add license has.

Signed-off-by: Baruch Siach <baruch@tkos.co.il>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/apr/apr.hash
package/apr/apr.mk

index 7a5969e52fdbf106f2b9e4b7c27375a654e3e772..be130a5d780c40ecf019ee9d71291c83e8bae490 100644 (file)
@@ -1,2 +1,4 @@
-# From http://archive.apache.org/dist/apr/apr-1.6.2.tar.bz2.sha1
-sha1 01b0d4faa0194825e8e525b9ac7ccfb832471d50  apr-1.6.2.tar.bz2
+# From http://www.apache.org/dist/apr/apr-1.6.3.tar.bz2.sha256
+sha256 131f06d16d7aabd097fa992a33eec2b6af3962f93e6d570a9bd4d85e95993172  apr-1.6.3.tar.bz2
+# Locally calculated
+sha256 f854aeef66ecd55a126226e82b3f26793fc3b1c584647f6a0edc5639974c38ad  LICENSE
index ffb30991ecbf1119de4632ec8de18e8d7b7c18b9..58b1d86b28451a7a2ff543a841a8ef790f566abb 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-APR_VERSION = 1.6.2
+APR_VERSION = 1.6.3
 APR_SOURCE = apr-$(APR_VERSION).tar.bz2
 APR_SITE = http://archive.apache.org/dist/apr
 APR_LICENSE = Apache-2.0