From: Baruch Siach Date: Mon, 30 Oct 2017 19:11:01 +0000 (+0200) Subject: apr: security bump to version 1.6.3 X-Git-Url: https://git.libre-soc.org/?a=commitdiff_plain;h=c91981a985108a83bfeca1a61a4457b5ac785574;p=buildroot.git apr: security bump to version 1.6.3 Fixes CVE-2017-12613: Out-of-bounds array deref in apr_time_exp*() functions. Use upstream provided SHA256 hash. Add license has. Signed-off-by: Baruch Siach Signed-off-by: Thomas Petazzoni --- diff --git a/package/apr/apr.hash b/package/apr/apr.hash index 7a5969e52f..be130a5d78 100644 --- a/package/apr/apr.hash +++ b/package/apr/apr.hash @@ -1,2 +1,4 @@ -# From http://archive.apache.org/dist/apr/apr-1.6.2.tar.bz2.sha1 -sha1 01b0d4faa0194825e8e525b9ac7ccfb832471d50 apr-1.6.2.tar.bz2 +# From http://www.apache.org/dist/apr/apr-1.6.3.tar.bz2.sha256 +sha256 131f06d16d7aabd097fa992a33eec2b6af3962f93e6d570a9bd4d85e95993172 apr-1.6.3.tar.bz2 +# Locally calculated +sha256 f854aeef66ecd55a126226e82b3f26793fc3b1c584647f6a0edc5639974c38ad LICENSE diff --git a/package/apr/apr.mk b/package/apr/apr.mk index ffb30991ec..58b1d86b28 100644 --- a/package/apr/apr.mk +++ b/package/apr/apr.mk @@ -4,7 +4,7 @@ # ################################################################################ -APR_VERSION = 1.6.2 +APR_VERSION = 1.6.3 APR_SOURCE = apr-$(APR_VERSION).tar.bz2 APR_SITE = http://archive.apache.org/dist/apr APR_LICENSE = Apache-2.0