From 82855ec0a6cb3ab7959d7afa3e3c6c2f843287ce6f9efe219f4dea0356a2d851 Mon Sep 17 00:00:00 2001 From: Jan Engelhardt Date: Mon, 29 Mar 2021 21:44:45 +0000 Subject: [PATCH 1/3] - Update to release 1.14.3 OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libupnp?expand=0&rev=42 --- libupnp-1.14.2.tar.bz2 | 3 --- libupnp-1.14.3.tar.bz2 | 3 +++ libupnp.changes | 6 ++++++ libupnp.spec | 2 +- 4 files changed, 10 insertions(+), 4 deletions(-) delete mode 100644 libupnp-1.14.2.tar.bz2 create mode 100644 libupnp-1.14.3.tar.bz2 diff --git a/libupnp-1.14.2.tar.bz2 b/libupnp-1.14.2.tar.bz2 deleted file mode 100644 index 9cb4902..0000000 --- a/libupnp-1.14.2.tar.bz2 +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:ffe3045b91a4c951d105e0db98cd043341f1f4342ddaf23916e15a5792d5c270 -size 672650 diff --git a/libupnp-1.14.3.tar.bz2 b/libupnp-1.14.3.tar.bz2 new file mode 100644 index 0000000..caa52e9 --- /dev/null +++ b/libupnp-1.14.3.tar.bz2 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:7140a712de055c7c9b3438c48e0ccaecb4760a496f0979f9e2ef3e7442da4502 +size 680217 diff --git a/libupnp.changes b/libupnp.changes index f946ca9..e356666 100644 --- a/libupnp.changes +++ b/libupnp.changes @@ -1,3 +1,9 @@ +------------------------------------------------------------------- +Mon Mar 29 21:44:30 UTC 2021 - Jan Engelhardt + +- Update to release 1.14.3 + * Fix for gena leak. + ------------------------------------------------------------------- Mon Mar 1 06:47:53 UTC 2021 - Jan Engelhardt diff --git a/libupnp.spec b/libupnp.spec index e13cc67..0157fba 100644 --- a/libupnp.spec +++ b/libupnp.spec @@ -20,7 +20,7 @@ %define pnpver 17 %define ixmlver 11 Name: libupnp -Version: 1.14.2 +Version: 1.14.3 Release: 0 Summary: An implementation of Universal Plug and Play (UPnP) License: BSD-3-Clause From b46eaaaa43a3eb4d78b0161090edb56ce3c8b6ecfbef074e065b7d921a9a8f49 Mon Sep 17 00:00:00 2001 From: Jan Engelhardt Date: Tue, 30 Mar 2021 06:47:29 +0000 Subject: [PATCH 2/3] - Update to release 1.14.4 OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libupnp?expand=0&rev=43 --- libupnp-1.14.3.tar.bz2 | 3 --- libupnp-1.14.4.tar.bz2 | 3 +++ libupnp.changes | 4 ++-- libupnp.spec | 2 +- 4 files changed, 6 insertions(+), 6 deletions(-) delete mode 100644 libupnp-1.14.3.tar.bz2 create mode 100644 libupnp-1.14.4.tar.bz2 diff --git a/libupnp-1.14.3.tar.bz2 b/libupnp-1.14.3.tar.bz2 deleted file mode 100644 index caa52e9..0000000 --- a/libupnp-1.14.3.tar.bz2 +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:7140a712de055c7c9b3438c48e0ccaecb4760a496f0979f9e2ef3e7442da4502 -size 680217 diff --git a/libupnp-1.14.4.tar.bz2 b/libupnp-1.14.4.tar.bz2 new file mode 100644 index 0000000..da16138 --- /dev/null +++ b/libupnp-1.14.4.tar.bz2 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:cd649ef53070e9b88680f730ed5b3f919658582d43dd315a2ed8b6105c6fbe63 +size 681245 diff --git a/libupnp.changes b/libupnp.changes index e356666..533d347 100644 --- a/libupnp.changes +++ b/libupnp.changes @@ -1,7 +1,7 @@ ------------------------------------------------------------------- -Mon Mar 29 21:44:30 UTC 2021 - Jan Engelhardt +Tue Mar 30 06:28:49 UTC 2021 - Jan Engelhardt -- Update to release 1.14.3 +- Update to release 1.14.4 * Fix for gena leak. ------------------------------------------------------------------- diff --git a/libupnp.spec b/libupnp.spec index 0157fba..a3a8c59 100644 --- a/libupnp.spec +++ b/libupnp.spec @@ -20,7 +20,7 @@ %define pnpver 17 %define ixmlver 11 Name: libupnp -Version: 1.14.3 +Version: 1.14.4 Release: 0 Summary: An implementation of Universal Plug and Play (UPnP) License: BSD-3-Clause From 243f32121b2157bf8c05d7fd52c15c95057a1a913c9630553ce35ecd54679c9f Mon Sep 17 00:00:00 2001 From: Jan Engelhardt Date: Tue, 6 Apr 2021 23:39:20 +0000 Subject: [PATCH 3/3] - Update to release 1.14.5 OBS-URL: https://build.opensuse.org/package/show/devel:libraries:c_c++/libupnp?expand=0&rev=44 --- libupnp-1.14.4.tar.bz2 | 3 --- libupnp-1.14.5.tar.bz2 | 3 +++ libupnp.changes | 7 +++++++ libupnp.spec | 2 +- 4 files changed, 11 insertions(+), 4 deletions(-) delete mode 100644 libupnp-1.14.4.tar.bz2 create mode 100644 libupnp-1.14.5.tar.bz2 diff --git a/libupnp-1.14.4.tar.bz2 b/libupnp-1.14.4.tar.bz2 deleted file mode 100644 index da16138..0000000 --- a/libupnp-1.14.4.tar.bz2 +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:cd649ef53070e9b88680f730ed5b3f919658582d43dd315a2ed8b6105c6fbe63 -size 681245 diff --git a/libupnp-1.14.5.tar.bz2 b/libupnp-1.14.5.tar.bz2 new file mode 100644 index 0000000..fc33d9a --- /dev/null +++ b/libupnp-1.14.5.tar.bz2 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:227ffa407be6b91d4e42abee1dd27e4b8d7e5ba8d3d45394cca4e1eadc65149a +size 677825 diff --git a/libupnp.changes b/libupnp.changes index 533d347..fadd3ae 100644 --- a/libupnp.changes +++ b/libupnp.changes @@ -1,3 +1,10 @@ +------------------------------------------------------------------- +Tue Apr 6 23:38:27 UTC 2021 - Jan Engelhardt + +- Update to release 1.14.5 + * Non-recursive version of ixmlNode_free() avoids stack overflow + attack (Fixes CVE-2021-28302). + ------------------------------------------------------------------- Tue Mar 30 06:28:49 UTC 2021 - Jan Engelhardt diff --git a/libupnp.spec b/libupnp.spec index a3a8c59..80df1ea 100644 --- a/libupnp.spec +++ b/libupnp.spec @@ -20,7 +20,7 @@ %define pnpver 17 %define ixmlver 11 Name: libupnp -Version: 1.14.4 +Version: 1.14.5 Release: 0 Summary: An implementation of Universal Plug and Play (UPnP) License: BSD-3-Clause