diff options
author | Natanael Copa <ncopa@alpinelinux.org> | 2017-08-11 08:59:36 +0000 |
---|---|---|
committer | Natanael Copa <ncopa@alpinelinux.org> | 2017-08-11 10:54:20 +0000 |
commit | 13ee88b017ecd8c894a60178235598a526d5e4a6 (patch) | |
tree | 8f8272361b2eb26c3254285005206438949292a7 /main/curl/APKBUILD | |
parent | c41812134d11c0ab6c6f0258de05de85638d996b (diff) | |
download | aports-13ee88b017ecd8c894a60178235598a526d5e4a6.tar.bz2 aports-13ee88b017ecd8c894a60178235598a526d5e4a6.tar.xz |
main/curl: security upgrade to 7.55.0
Diffstat (limited to 'main/curl/APKBUILD')
-rw-r--r-- | main/curl/APKBUILD | 14 |
1 files changed, 12 insertions, 2 deletions
diff --git a/main/curl/APKBUILD b/main/curl/APKBUILD index 5b86edcf73..e348036839 100644 --- a/main/curl/APKBUILD +++ b/main/curl/APKBUILD @@ -3,7 +3,7 @@ # Contributor: Ćukasz Jendrysik <scadu@yandex.com> # Maintainer: Natanael Copa <ncopa@alpinelinux.org> pkgname=curl -pkgver=7.54.1 +pkgver=7.55.0 pkgrel=0 pkgdesc="An URL retrival utility and library" url="http://curl.haxx.se" @@ -12,10 +12,15 @@ license="MIT" depends="ca-certificates" makedepends="zlib-dev libressl-dev libssh2-dev groff perl" source="http://curl.haxx.se/download/$pkgname-$pkgver.tar.bz2 + curl-do-bounds-check-using-a-double-comparison.patch " subpackages="$pkgname-dbg $pkgname-doc $pkgname-dev libcurl" # secfixes: +# 7.55.0-r0: +# - CVE-2017-1000099 +# - CVE-2017-1000100 +# - CVE-2017-1000101 # 7.54.0-r0: # - CVE-2017-7468 # 7.53.1-r2: @@ -52,6 +57,10 @@ builddir="$srcdir/$pkgname-$pkgver" build() { cd "$builddir" + + # see https://curl.haxx.se/mail/lib-2017-08/0050.html + rm docs/libcurl/opts/CURLOPT_STRIP_PATH_SLASH.3 + ./configure \ --build=$CBUILD \ --host=$CHOST \ @@ -82,4 +91,5 @@ libcurl() { mv "$pkgdir"/usr/lib "$subpkgdir"/usr } -sha512sums="eb9639677f0ca1521ca631c520ab83ad071c52b31690e5e7f31546f6a44b2f11d1bb62282056cffb570eb290bf1e7830e87cb536295ac6a54a904663e795f2da curl-7.54.1.tar.bz2" +sha512sums="4975864621219e937585aaf5a9a54bba112b58bbf5a8acd92e1e972ea747a15a5564143548c5d8930b8c0d0e9d27d28225d0c81e52a1ba71e4c6f9e3859c978b curl-7.55.0.tar.bz2 +d0f102fdbc2174169b2fea9248c3187d8c546d3a788447769dceec5fb7e063adbebbc967b88d208af1355cfda600f837abdae6d2e057a096eededc1857d2b8d3 curl-do-bounds-check-using-a-double-comparison.patch" |