aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLeo <thinkabit.ukim@gmail.com>2019-11-11 07:10:01 -0300
committerNatanael Copa <ncopa@alpinelinux.org>2019-11-11 16:08:08 +0100
commit056e278147ebf0f3781926c395e533081eb8c0f9 (patch)
treed115a4f516a36b7a48753e0a75821eaab87f8c4f
parent9fd7505b584787b0d3470b87eb9a39983cfb50ae (diff)
downloadaports-056e278147ebf0f3781926c395e533081eb8c0f9.tar.gz
aports-056e278147ebf0f3781926c395e533081eb8c0f9.tar.bz2
aports-056e278147ebf0f3781926c395e533081eb8c0f9.tar.xz
main/fribidi: fix CVE-2019-18397
ref #10943
-rw-r--r--main/fribidi/APKBUILD13
1 files changed, 10 insertions, 3 deletions
diff --git a/main/fribidi/APKBUILD b/main/fribidi/APKBUILD
index 3d4878edaa..000cd761dd 100644
--- a/main/fribidi/APKBUILD
+++ b/main/fribidi/APKBUILD
@@ -1,13 +1,19 @@
# Maintainer: Natanael Copa <ncopa@alpinelinux.org>
pkgname=fribidi
pkgver=1.0.5
-pkgrel=1
+pkgrel=2
pkgdesc="Free Implementation of the Unicode Bidirectional Algorithm"
url="https://github.com/fribidi/fribidi"
arch="all"
license="LGPL-2.0-or-later"
subpackages="$pkgname-doc $pkgname-static $pkgname-dev"
-source="https://github.com/fribidi/fribidi/releases/download/v$pkgver/fribidi-$pkgver.tar.bz2"
+source="https://github.com/fribidi/fribidi/releases/download/v$pkgver/fribidi-$pkgver.tar.bz2
+ CVE-2019-18397.patch::https://github.com/fribidi/fribidi/commit/034c6e9a1d296286305f4cfd1e0072b879f52568.patch
+ "
+
+# secfixes:
+# 1.0.5-r2:
+# - CVE-2019-18397
build() {
cd "$builddir"
@@ -31,4 +37,5 @@ package() {
make DESTDIR="$pkgdir" install
}
-sha512sums="c8fb32468be4c461832d586d6c6af65fad1cfe9d5b2fed405f247d6974425ccedeb21ad11609fbcabc3ae5d635d78d88c12d201a4d19ef997e9497054afcdeb2 fribidi-1.0.5.tar.bz2"
+sha512sums="c8fb32468be4c461832d586d6c6af65fad1cfe9d5b2fed405f247d6974425ccedeb21ad11609fbcabc3ae5d635d78d88c12d201a4d19ef997e9497054afcdeb2 fribidi-1.0.5.tar.bz2
+3d8efc59781c36203d618d3348b54fbfaff79306964e43c93d2cbe97d2e122c06a44aea519e3ea6ad78e46ecc37cf64975b8b89de0cb21048b89d0ce20e4ab46 CVE-2019-18397.patch"