aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLeo <thinkabit.ukim@gmail.com>2020-09-11 01:12:59 -0300
committerLeo <thinkabit.ukim@gmail.com>2020-09-11 01:12:59 -0300
commita41f7d157ff0666406baa4a218f0a947df85943a (patch)
treec7d04a7289937848296177b2c4a4b247026a3528
parentdada8ee4fb939c91b8fd82c5edc5179ebf102b62 (diff)
downloadaports-a41f7d157ff0666406baa4a218f0a947df85943a.tar.gz
aports-a41f7d157ff0666406baa4a218f0a947df85943a.tar.bz2
aports-a41f7d157ff0666406baa4a218f0a947df85943a.tar.xz
main/libssh: fix CVE-2020-16135
-rw-r--r--main/libssh/APKBUILD8
1 files changed, 6 insertions, 2 deletions
diff --git a/main/libssh/APKBUILD b/main/libssh/APKBUILD
index 1ad15f92cc6..3bb42faf467 100644
--- a/main/libssh/APKBUILD
+++ b/main/libssh/APKBUILD
@@ -2,7 +2,7 @@
# Maintainer: Natanael Copa <ncopa@alpinelinux.org>
pkgname=libssh
pkgver=0.9.4
-pkgrel=0
+pkgrel=1
pkgdesc="Library for accessing ssh client services through C libraries"
url="https://www.libssh.org/"
arch="all"
@@ -12,9 +12,12 @@ makedepends="$depends_dev cmake doxygen"
checkdepends="cmocka-dev"
subpackages="$pkgname-dev"
source="https://www.libssh.org/files/${pkgver%.*}/libssh-$pkgver.tar.xz
+ CVE-2020-16135.patch::https://git.libssh.org/projects/libssh.git/patch/?id=e631ebb3e2247dd25e9678e6827c20dc73b73238
"
# secfixes:
+# 0.9.4-r1:
+# - CVE-2020-16135
# 0.9.4-r0:
# - CVE-2020-1730
# 0.9.3-r0:
@@ -46,4 +49,5 @@ package() {
make DESTDIR="$pkgdir" install
}
-sha512sums="38705c19c293ea5e6d286d22eb17021dbe58d88c1e647b699933aa0db9ca1174d43d1ff76c1a1b17bf2cc1a8297ec02f1a67dd9e969676dd69cf6fbdae9bc8d4 libssh-0.9.4.tar.xz"
+sha512sums="38705c19c293ea5e6d286d22eb17021dbe58d88c1e647b699933aa0db9ca1174d43d1ff76c1a1b17bf2cc1a8297ec02f1a67dd9e969676dd69cf6fbdae9bc8d4 libssh-0.9.4.tar.xz
+db6bc86b982f740b94cbbebd16985faf23fb084b6af38da1f4e1e6ce0783dd9bddd755347a553765d237c338b70f9d12b60a6f7b2b4ddf836dfbeb58005fbb0a CVE-2020-16135.patch"