summaryrefslogtreecommitdiffstats
path: root/package/apr-util/apr-util.hash
diff options
context:
space:
mode:
authorBaruch Siach <baruch@tkos.co.il>2017-10-30 21:11:02 +0200
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>2017-10-30 20:43:40 +0100
commit1d3c611dee82090d9456730e24af368b51dcb4a9 (patch)
tree26132f1486d5bc7d8aadd5746c8591fe4798cabe /package/apr-util/apr-util.hash
parentc91981a985108a83bfeca1a61a4457b5ac785574 (diff)
downloadbuildroot-1d3c611dee82090d9456730e24af368b51dcb4a9.tar.gz
buildroot-1d3c611dee82090d9456730e24af368b51dcb4a9.zip
apr-util: security bump to version 1.6.1
Fixes CVE-2017-12618: Out-of-bounds access in corrupted SDBM database. Switch to bz2 compressed tarball. Use upstream provided SHA256 hash. Add license hash. Signed-off-by: Baruch Siach <baruch@tkos.co.il> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
Diffstat (limited to 'package/apr-util/apr-util.hash')
-rw-r--r--package/apr-util/apr-util.hash6
1 files changed, 4 insertions, 2 deletions
diff --git a/package/apr-util/apr-util.hash b/package/apr-util/apr-util.hash
index 3db4396058..82ad475619 100644
--- a/package/apr-util/apr-util.hash
+++ b/package/apr-util/apr-util.hash
@@ -1,2 +1,4 @@
-# From http://archive.apache.org/dist/apr/apr-util-1.5.4.tar.gz.sha1
-sha1 72cc3ac693b52fb831063d5c0de18723bc8e0095 apr-util-1.5.4.tar.gz
+# From http://www.apache.org/dist/apr/apr-util-1.6.1.tar.bz2.sha256
+sha256 d3e12f7b6ad12687572a3a39475545a072608f4ba03a6ce8a3778f607dd0035b apr-util-1.6.1.tar.bz2
+# Locally calculated
+sha256 ef5609d18601645ad6fe22c6c122094be40e976725c1d0490778abacc836e7a2 LICENSE
OpenPOWER on IntegriCloud