libpjsip: security bump to 2.7.2
authorAdam Duskett <aduskett@gmail.com>
Mon, 12 Mar 2018 08:44:44 +0000 (04:44 -0400)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 13 Mar 2018 22:27:14 +0000 (23:27 +0100)
Fixes the following vulnerabilities:

- CVE-2018-1000098: Crash when parsing SDP with an invalid media format
  description

- CVE-2018-1000099: Crash when receiving SDP with invalid fmtp attribute

[Peter: add CVE info]
Signed-off-by: Adam Duskett <aduskett@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/libpjsip/libpjsip.hash
package/libpjsip/libpjsip.mk

index edac3d578f80c6280bdae7669411cffdd52438ae..36c2ea12893f376be66b8ba20eb68d552b97430c 100644 (file)
@@ -1,6 +1,6 @@
-# From http://www.pjsip.org/release/2.7.1/MD5SUM.TXT
-md5    99a64110fa5c2debff40e0e8d4676380  pjproject-2.7.1.tar.bz2
+# From http://www.pjsip.org/release/2.7.2/MD5SUM.TXT
+md5    fa3f0bc098c4bff48ddd92db1c016a7a  pjproject-2.7.2.tar.bz2
 
 # Locally computed
-sha256 59fabc62a02b2b80857297cfb10e2c68c473f4a0acc6e848cfefe8421f2c3126        pjproject-2.7.1.tar.bz2
+sha256 9c2c828abab7626edf18e04b041ef274bfaa86f99adf2c25ff56f1509e813772        pjproject-2.7.2.tar.bz2
 sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643        COPYING
index 53b654d072c37296682b2ad41d862cdf4c36c60f..db9e474be76fa90d703efc67406355f8be4a14d1 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-LIBPJSIP_VERSION = 2.7.1
+LIBPJSIP_VERSION = 2.7.2
 LIBPJSIP_SOURCE = pjproject-$(LIBPJSIP_VERSION).tar.bz2
 LIBPJSIP_SITE = http://www.pjsip.org/release/$(LIBPJSIP_VERSION)
 LIBPJSIP_DEPENDENCIES = libsrtp