aboutsummaryrefslogtreecommitdiffstats
path: root/main/fribidi
diff options
context:
space:
mode:
authorLeo <thinkabit.ukim@gmail.com>2019-11-11 07:10:01 -0300
committerNatanael Copa <ncopa@alpinelinux.org>2019-11-11 16:17:39 +0100
commitf49f79ef74f6410eadb866875ab2c2e95bd96ba8 (patch)
tree18b874420f4fd6d214ac545f1f3c34ab959e7fbb /main/fribidi
parent3f0b215e21eca7395224b2eb4c9ef16ce7992771 (diff)
downloadaports-f49f79ef74f6410eadb866875ab2c2e95bd96ba8.tar.bz2
aports-f49f79ef74f6410eadb866875ab2c2e95bd96ba8.tar.xz
main/fribidi: fix CVE-2019-18397
ref #10943
Diffstat (limited to 'main/fribidi')
-rw-r--r--main/fribidi/APKBUILD14
1 files changed, 11 insertions, 3 deletions
diff --git a/main/fribidi/APKBUILD b/main/fribidi/APKBUILD
index f8ab6a5c2a..9b4d868a54 100644
--- a/main/fribidi/APKBUILD
+++ b/main/fribidi/APKBUILD
@@ -1,7 +1,7 @@
# Maintainer: Natanael Copa <ncopa@alpinelinux.org>
pkgname=fribidi
pkgver=1.0.2
-pkgrel=0
+pkgrel=1
pkgdesc="Free Implementation of the Unicode Bidirectional Algorithm"
url="http://fribidi.org"
arch="all"
@@ -9,7 +9,14 @@ license="LGPL-2.0-or-later"
subpackages="$pkgname-dev"
depends=""
makedepends=""
-source="https://github.com/fribidi/fribidi/releases/download/v$pkgver/fribidi-$pkgver.tar.bz2"
+source="https://github.com/fribidi/fribidi/releases/download/v$pkgver/fribidi-$pkgver.tar.bz2
+ CVE-2019-18397.patch::https://github.com/fribidi/fribidi/commit/034c6e9a1d296286305f4cfd1e0072b879f52568.patch
+ "
+builddir="$srcdir"/$pkgname-$pkgver
+
+# secfixes:
+# 1.0.2-r1:
+# - CVE-2019-18397
build() {
cd "$builddir"
@@ -33,4 +40,5 @@ package() {
make DESTDIR="$pkgdir" install
}
-sha512sums="a474d01368b85c166e08a236425b6f13b88f2cf83308bf0df21c9fe034b1909edea30b778122719fcb8af72bdcf34f2f82f696031bcce077cf8ac764f019acaa fribidi-1.0.2.tar.bz2"
+sha512sums="a474d01368b85c166e08a236425b6f13b88f2cf83308bf0df21c9fe034b1909edea30b778122719fcb8af72bdcf34f2f82f696031bcce077cf8ac764f019acaa fribidi-1.0.2.tar.bz2
+3d8efc59781c36203d618d3348b54fbfaff79306964e43c93d2cbe97d2e122c06a44aea519e3ea6ad78e46ecc37cf64975b8b89de0cb21048b89d0ce20e4ab46 CVE-2019-18397.patch"