summaryrefslogtreecommitdiffstats
path: root/package/pcre/pcre.hash
diff options
context:
space:
mode:
authorBernd Kuhls <bernd.kuhls@t-online.de>2017-07-13 21:39:28 +0200
committerPeter Korsgaard <peter@korsgaard.com>2017-07-13 22:13:56 +0200
commitbc6a84bb3d05e0d752ecf59bb35ac827e9b76185 (patch)
treedde5c457713372ae2bb14b2322b8b1f293c72de7 /package/pcre/pcre.hash
parent29f956d99c3b3b8a90258a88d79b6c76e724b714 (diff)
downloadbuildroot-bc6a84bb3d05e0d752ecf59bb35ac827e9b76185.tar.gz
buildroot-bc6a84bb3d05e0d752ecf59bb35ac827e9b76185.zip
package/pcre: security bump to version 8.41
Removed patches 0003 & 0004, applied upstream. Fixes the following security issues: CVE-2017-7244 - The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file. CVE-2017-7245 - Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 4) or possibly have unspecified other impact via a crafted file. CVE-2017-7246 - Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 268) or possibly have unspecified other impact via a crafted file. [Peter: add CVE info] Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Diffstat (limited to 'package/pcre/pcre.hash')
-rw-r--r--package/pcre/pcre.hash2
1 files changed, 1 insertions, 1 deletions
diff --git a/package/pcre/pcre.hash b/package/pcre/pcre.hash
index 4c3c6c32ea..b36e130178 100644
--- a/package/pcre/pcre.hash
+++ b/package/pcre/pcre.hash
@@ -1,2 +1,2 @@
# Locally calculated after checking pgp signature
-sha256 00e27a29ead4267e3de8111fcaa59b132d0533cdfdbdddf4b0604279acbcf4f4 pcre-8.40.tar.bz2
+sha256 e62c7eac5ae7c0e7286db61ff82912e1c0b7a0c13706616e94a7dd729321b530 pcre-8.41.tar.bz2
OpenPOWER on IntegriCloud