summaryrefslogtreecommitdiffstats
path: root/package/apr
diff options
context:
space:
mode:
authorBaruch Siach <baruch@tkos.co.il>2017-10-30 21:11:01 +0200
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>2017-10-30 20:43:39 +0100
commitc91981a985108a83bfeca1a61a4457b5ac785574 (patch)
treee1e77da57cb71b2f5267e5d132c42cf09a648953 /package/apr
parent3f7499471d466fadc198541b62ee55843c5a5579 (diff)
downloadbuildroot-c91981a985108a83bfeca1a61a4457b5ac785574.tar.gz
buildroot-c91981a985108a83bfeca1a61a4457b5ac785574.zip
apr: security bump to version 1.6.3
Fixes CVE-2017-12613: Out-of-bounds array deref in apr_time_exp*() functions. Use upstream provided SHA256 hash. Add license has. Signed-off-by: Baruch Siach <baruch@tkos.co.il> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
Diffstat (limited to 'package/apr')
-rw-r--r--package/apr/apr.hash6
-rw-r--r--package/apr/apr.mk2
2 files changed, 5 insertions, 3 deletions
diff --git a/package/apr/apr.hash b/package/apr/apr.hash
index 7a5969e52f..be130a5d78 100644
--- a/package/apr/apr.hash
+++ b/package/apr/apr.hash
@@ -1,2 +1,4 @@
-# From http://archive.apache.org/dist/apr/apr-1.6.2.tar.bz2.sha1
-sha1 01b0d4faa0194825e8e525b9ac7ccfb832471d50 apr-1.6.2.tar.bz2
+# From http://www.apache.org/dist/apr/apr-1.6.3.tar.bz2.sha256
+sha256 131f06d16d7aabd097fa992a33eec2b6af3962f93e6d570a9bd4d85e95993172 apr-1.6.3.tar.bz2
+# Locally calculated
+sha256 f854aeef66ecd55a126226e82b3f26793fc3b1c584647f6a0edc5639974c38ad LICENSE
diff --git a/package/apr/apr.mk b/package/apr/apr.mk
index ffb30991ec..58b1d86b28 100644
--- a/package/apr/apr.mk
+++ b/package/apr/apr.mk
@@ -4,7 +4,7 @@
#
################################################################################
-APR_VERSION = 1.6.2
+APR_VERSION = 1.6.3
APR_SOURCE = apr-$(APR_VERSION).tar.bz2
APR_SITE = http://archive.apache.org/dist/apr
APR_LICENSE = Apache-2.0
OpenPOWER on IntegriCloud