package/libxcrypt: security bump to version 4.4.25
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Sun, 12 Sep 2021 20:32:56 +0000 (22:32 +0200)
committerPeter Korsgaard <peter@korsgaard.com>
Mon, 13 Sep 2021 20:39:13 +0000 (22:39 +0200)
commita071bec0a0cd928443223132d47564c90bc64713
treee138b8089046a73cca69517e2dd3151849211587
parent834e543b9707aa13df3d69354709a1835529b225
package/libxcrypt: security bump to version 4.4.25

- Fix several issues found by Covscan in the testsuite. These include:
  - CWE-170: String not null terminated (STRING_NULL)
  - CWE-188: Reliance on integer endianness (INCOMPATIBLE_CAST)
  - CWE-190: Unintentional integer overflow (OVERFLOW_BEFORE_WIDEN)
  - CWE-569: Wrong sizeof argument (SIZEOF_MISMATCH)
  - CWE-573: Missing varargs init or cleanup (VARARGS)
  - CWE-687: Argument cannot be negative (NEGATIVE_RETURNS)
- Update hash of LICENSING due to files being updated with:
  https://github.com/besser82/libxcrypt/commit/44e9eb57b462cfbaeb085cea0e308511565f4a12
  https://github.com/besser82/libxcrypt/commit/578271c3776a442fa55ac5f5ea83c7dc83ede979

https://github.com/besser82/libxcrypt/blob/v4.4.25/NEWS

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/libxcrypt/libxcrypt.hash
package/libxcrypt/libxcrypt.mk