From 4031a0c9b943af605d0cf9e644f5d6dc0993a71cf3aea27d72480283c62c8528 Mon Sep 17 00:00:00 2001 From: Marcus Meissner Date: Tue, 7 Mar 2023 07:49:19 +0000 Subject: [PATCH] Accepting request 1069708 from home:aplanas:branches:security - Update to 0.9.6: * tpm2: Check size of buffer before accessing it (CVE-2023-1017 & CVE-2023-1018) OBS-URL: https://build.opensuse.org/request/show/1069708 OBS-URL: https://build.opensuse.org/package/show/security/libtpms?expand=0&rev=38 --- libtpms-0.9.5.tar.gz | 3 --- libtpms-0.9.6.tar.gz | 3 +++ libtpms.changes | 6 ++++++ libtpms.spec | 4 ++-- 4 files changed, 11 insertions(+), 5 deletions(-) delete mode 100644 libtpms-0.9.5.tar.gz create mode 100644 libtpms-0.9.6.tar.gz diff --git a/libtpms-0.9.5.tar.gz b/libtpms-0.9.5.tar.gz deleted file mode 100644 index 3322580..0000000 --- a/libtpms-0.9.5.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:9522c69001e46a3b0e1ccd646d36db611b2366c395099d29037f2b067bf1bc60 -size 1264086 diff --git a/libtpms-0.9.6.tar.gz b/libtpms-0.9.6.tar.gz new file mode 100644 index 0000000..aa3b569 --- /dev/null +++ b/libtpms-0.9.6.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:2807466f1563ebe45fdd12dd26e501e8a0c4fbb99c7c428fbb508789efd221c0 +size 1264338 diff --git a/libtpms.changes b/libtpms.changes index 0768d33..c1071dc 100644 --- a/libtpms.changes +++ b/libtpms.changes @@ -1,3 +1,9 @@ +------------------------------------------------------------------- +Mon Mar 6 16:32:02 UTC 2023 - Alberto Planas Dominguez + +- Update to 0.9.6: + * tpm2: Check size of buffer before accessing it (CVE-2023-1017 & CVE-2023-1018) + ------------------------------------------------------------------- Sat Dec 3 09:56:13 UTC 2022 - Dirk Müller diff --git a/libtpms.spec b/libtpms.spec index 1a62891..1382e30 100644 --- a/libtpms.spec +++ b/libtpms.spec @@ -1,7 +1,7 @@ # # spec file for package libtpms # -# Copyright (c) 2022 SUSE LLC +# Copyright (c) 2023 SUSE LLC # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -18,7 +18,7 @@ %define lname libtpms0 Name: libtpms -Version: 0.9.5 +Version: 0.9.6 Release: 0 Summary: Library providing Trusted Platform Module (TPM) functionality License: BSD-3-Clause