SHA256
1
0
forked from pool/apr

- security update

- deleted patches
  - apr-CVE-2021-3594.patch (renamed)
- added patches
  + apr-CVE-2021-35940.patch (correct name)
  fix CVE-2021-35940 [bsc#1190072], Regression of fix in apr 1.7
  + apr-CVE-2021-35940.patch

OBS-URL: https://build.opensuse.org/package/show/Apache/apr?expand=0&rev=38
This commit is contained in:
Petr Gajdos 2022-02-22 08:25:02 +00:00 committed by Git OBS Bridge
parent adb77ee1a0
commit 4a4e46d510
3 changed files with 12 additions and 4 deletions

View File

@ -1,3 +1,11 @@
-------------------------------------------------------------------
Tue Feb 22 08:22:54 UTC 2022 - pgajdos@suse.com
- deleted patches
- apr-CVE-2021-3594.patch (renamed)
- added patches
+ apr-CVE-2021-35940.patch (correct name)
------------------------------------------------------------------- -------------------------------------------------------------------
Tue Oct 19 14:34:24 UTC 2021 - pgajdos@suse.com Tue Oct 19 14:34:24 UTC 2021 - pgajdos@suse.com
@ -8,8 +16,8 @@ Thu Sep 2 07:15:59 UTC 2021 - pgajdos@suse.com
- security update - security update
- added patches - added patches
fix CVE-2021-3594 [bsc#1187367], invalid pointer initialization may lead to information disclosure (udp) fix CVE-2021-35940 [bsc#1190072], Regression of fix in apr 1.7
+ apr-CVE-2021-3594.patch + apr-CVE-2021-35940.patch
------------------------------------------------------------------- -------------------------------------------------------------------
Sat Aug 3 14:11:24 UTC 2019 - Manu Maier <mmanu84@outlook.de> Sat Aug 3 14:11:24 UTC 2019 - Manu Maier <mmanu84@outlook.de>

View File

@ -1,7 +1,7 @@
# #
# spec file for package apr # spec file for package apr
# #
# Copyright (c) 2021 SUSE LLC # Copyright (c) 2022 SUSE LLC
# #
# All modifications and additions to the file contributed by third parties # All modifications and additions to the file contributed by third parties
# remain the property of their copyright owners, unless otherwise agreed # remain the property of their copyright owners, unless otherwise agreed
@ -35,7 +35,7 @@ Patch9: apr-proc-mutex-map-anon.patch
# prevent random failures of the testsuite (sendfile test) # prevent random failures of the testsuite (sendfile test)
Patch10: apr-test-sendfile-timeout.patch Patch10: apr-test-sendfile-timeout.patch
# CVE-2021-3594 [bsc#1187367], invalid pointer initialization may lead to information disclosure (udp) # CVE-2021-3594 [bsc#1187367], invalid pointer initialization may lead to information disclosure (udp)
Patch11: apr-CVE-2021-3594.patch Patch11: apr-CVE-2021-35940.patch
BuildRequires: doxygen BuildRequires: doxygen
BuildRequires: fdupes BuildRequires: fdupes
BuildRequires: libtool BuildRequires: libtool