-
Notifications
You must be signed in to change notification settings - Fork 563
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
drop patches, upgrade expat to version 2.6.3
- Loading branch information
1 parent
036f6a8
commit 52c3fbf
Showing
10 changed files
with
21 additions
and
245 deletions.
There are no files selected for viewing
157 changes: 0 additions & 157 deletions
157
SPECS/expat/0-lib-Reject-negative-len-for-XML_ParseBuffer.patch
This file was deleted.
Oops, something went wrong.
31 changes: 0 additions & 31 deletions
31
SPECS/expat/1-lib-Detect-integer-overflow-in-dtdCopy.patch
This file was deleted.
Oops, something went wrong.
30 changes: 0 additions & 30 deletions
30
SPECS/expat/2-lib-Detect-integer-overflow-in-function-nextScaffoldPart.patch
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,5 +1,5 @@ | ||
{ | ||
"Signatures": { | ||
"expat-2.6.2.tar.bz2": "9c7c1b5dcbc3c237c500a8fb1493e14d9582146dd9b42aa8d3ffb856a3b927e0" | ||
"expat-2.6.3.tar.bz2": "b8baef92f328eebcf731f4d18103951c61fa8c8ec21d5ff4202fb6f2198aeb2d" | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,20 +1,14 @@ | ||
%define underscore_version %(echo %{version} | cut -d. -f1-3 --output-delimiter="_") | ||
Summary: An XML parser library | ||
Name: expat | ||
Version: 2.6.2 | ||
Release: 2%{?dist} | ||
Version: 2.6.3 | ||
Release: 1%{?dist} | ||
License: MIT | ||
Vendor: Microsoft Corporation | ||
Distribution: Azure Linux | ||
Group: System Environment/GeneralLibraries | ||
URL: https://libexpat.github.io/ | ||
Source0: https://github.com/libexpat/libexpat/releases/download/R_%{underscore_version}/%{name}-%{version}.tar.bz2 | ||
# CVE-2024-45490 | ||
Patch0: 0-lib-Reject-negative-len-for-XML_ParseBuffer.patch | ||
# CVE-2024-45491 | ||
Patch1: 1-lib-Detect-integer-overflow-in-dtdCopy.patch | ||
# CVE-2024-45492 | ||
Patch2: 2-lib-Detect-integer-overflow-in-function-nextScaffoldPart.patch | ||
Requires: %{name}-libs = %{version}-%{release} | ||
|
||
%description | ||
|
@@ -72,8 +66,8 @@ rm -rf %{buildroot}/%{_docdir}/%{name} | |
%{_libdir}/libexpat.so.1* | ||
|
||
%changelog | ||
* Tue Sep 03 2024 Gary Swalling <[email protected]> - 2.6.2-2 | ||
- Add patches to fix CVE-2024-45490, CVE-2024-45491, CVE-2024-45492 | ||
* Tue Sep 04 2024 Gary Swalling <[email protected]> - 2.6.3-1 | ||
- Upgrade to 2.6.3 to fix CVE-2024-45490, CVE-2024-45491, CVE-2024-45492 | ||
|
||
* Wed May 22 2024 Neha Agarwal <[email protected]> - 2.6.2-1 | ||
- Upgrade to v2.6.2 to fix CVE-2024-28757 | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters