package/xterm: security bump to version 366
authorPeter Korsgaard <peter@korsgaard.com>
Thu, 11 Feb 2021 18:09:43 +0000 (19:09 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Fri, 12 Feb 2021 07:41:47 +0000 (08:41 +0100)
Fixes the following security issue:

CVE-2021-27135: xterm through Patch #365 allows remote attackers to cause a
denial of service (segmentation fault) or possibly have unspecified other
impact via a crafted UTF-8 character sequence.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/xterm/xterm.hash
package/xterm/xterm.mk

index 8e2d2c5309b7cf0c7449291f4e40255263f3a721..588b7fca51b9dfb5c590211a223fa5232b9b0b6d 100644 (file)
@@ -1,4 +1,4 @@
 # Locally calculated after checking pgp signature
-sha256  d81a3639e26552b6765bdcf28be1ecdb8acabf907955708e830ad6397ea10b48  xterm-363.tgz
+sha256  858b2885963fe97e712739066aadc1baeba2b33a0016303a7fec7d38bc73bf6e  xterm-366.tgz
 # Locally calculated
-sha256  c655a5fa3dec936543e02f863b8c1343d08522a2821cb484df6c5f62afa7354d  COPYING
+sha256  dfb668cc977e24649500f3cc54de3e2b793928d210715a445ab1227930b07ba6  COPYING
index 0984ef4dc8ac1364304574b8cfd1a51b68574494..f0c497e5e9a6f67d94d3b452c507a70db13fb4ab 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-XTERM_VERSION = 363
+XTERM_VERSION = 366
 XTERM_SOURCE = xterm-$(XTERM_VERSION).tgz
 XTERM_SITE = http://invisible-mirror.net/archives/xterm
 XTERM_DEPENDENCIES = ncurses xlib_libXaw host-pkgconf