aboutsummaryrefslogtreecommitdiffstats
path: root/main/curl/APKBUILD
diff options
context:
space:
mode:
authorNatanael Copa <ncopa@alpinelinux.org>2017-08-11 08:59:36 +0000
committerNatanael Copa <ncopa@alpinelinux.org>2017-08-11 10:54:20 +0000
commit13ee88b017ecd8c894a60178235598a526d5e4a6 (patch)
tree8f8272361b2eb26c3254285005206438949292a7 /main/curl/APKBUILD
parentc41812134d11c0ab6c6f0258de05de85638d996b (diff)
downloadaports-13ee88b017ecd8c894a60178235598a526d5e4a6.tar.bz2
aports-13ee88b017ecd8c894a60178235598a526d5e4a6.tar.xz
main/curl: security upgrade to 7.55.0
Diffstat (limited to 'main/curl/APKBUILD')
-rw-r--r--main/curl/APKBUILD14
1 files changed, 12 insertions, 2 deletions
diff --git a/main/curl/APKBUILD b/main/curl/APKBUILD
index 5b86edcf73..e348036839 100644
--- a/main/curl/APKBUILD
+++ b/main/curl/APKBUILD
@@ -3,7 +3,7 @@
# Contributor: Ɓukasz Jendrysik <scadu@yandex.com>
# Maintainer: Natanael Copa <ncopa@alpinelinux.org>
pkgname=curl
-pkgver=7.54.1
+pkgver=7.55.0
pkgrel=0
pkgdesc="An URL retrival utility and library"
url="http://curl.haxx.se"
@@ -12,10 +12,15 @@ license="MIT"
depends="ca-certificates"
makedepends="zlib-dev libressl-dev libssh2-dev groff perl"
source="http://curl.haxx.se/download/$pkgname-$pkgver.tar.bz2
+ curl-do-bounds-check-using-a-double-comparison.patch
"
subpackages="$pkgname-dbg $pkgname-doc $pkgname-dev libcurl"
# secfixes:
+# 7.55.0-r0:
+# - CVE-2017-1000099
+# - CVE-2017-1000100
+# - CVE-2017-1000101
# 7.54.0-r0:
# - CVE-2017-7468
# 7.53.1-r2:
@@ -52,6 +57,10 @@ builddir="$srcdir/$pkgname-$pkgver"
build() {
cd "$builddir"
+
+ # see https://curl.haxx.se/mail/lib-2017-08/0050.html
+ rm docs/libcurl/opts/CURLOPT_STRIP_PATH_SLASH.3
+
./configure \
--build=$CBUILD \
--host=$CHOST \
@@ -82,4 +91,5 @@ libcurl() {
mv "$pkgdir"/usr/lib "$subpkgdir"/usr
}
-sha512sums="eb9639677f0ca1521ca631c520ab83ad071c52b31690e5e7f31546f6a44b2f11d1bb62282056cffb570eb290bf1e7830e87cb536295ac6a54a904663e795f2da curl-7.54.1.tar.bz2"
+sha512sums="4975864621219e937585aaf5a9a54bba112b58bbf5a8acd92e1e972ea747a15a5564143548c5d8930b8c0d0e9d27d28225d0c81e52a1ba71e4c6f9e3859c978b curl-7.55.0.tar.bz2
+d0f102fdbc2174169b2fea9248c3187d8c546d3a788447769dceec5fb7e063adbebbc967b88d208af1355cfda600f837abdae6d2e057a096eededc1857d2b8d3 curl-do-bounds-check-using-a-double-comparison.patch"