An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue. https://svn.apache.org/viewvc?view=revision&revision=1891198 Bump PKGREVISION.
11 lines
828 B
Text
11 lines
828 B
Text
$NetBSD: distinfo,v 1.49 2021/11/28 12:57:05 he Exp $
|
|
|
|
BLAKE2s (apr-1.7.0.tar.bz2) = f6126e30d08bc9dd7333bb9ee5814d606ae3b8f26f31ac6132bc918c22e57de0
|
|
SHA512 (apr-1.7.0.tar.bz2) = 3dc42d5caf17aab16f5c154080f020d5aed761e22db4c5f6506917f6bfd2bf8becfb40af919042bd4ce1077d5de74aa666f5edfba7f275efba78e8893c115148
|
|
Size (apr-1.7.0.tar.bz2) = 872238 bytes
|
|
SHA1 (patch-atomic_unix_builtins.c) = e90d0232013650c3d227fa3a8be952c51b7148e8
|
|
SHA1 (patch-atomic_unix_builtins64.c) = e24316e93dae12efc1cbfc3f444e8622df5e5833
|
|
SHA1 (patch-include_apr__general.h) = bff357eee11218a6c53769278fc3f9094b062fdf
|
|
SHA1 (patch-include_arch_unix_apr__arch__atomic.h) = 6f226add54f5966a50985441f6903853a0728c88
|
|
SHA1 (patch-time_unix_time.c) = d3da97cb4b6c7b6416fecb49006470db46084276
|
|
SHA1 (patch-time_win32_time.c) = aee61377826292c238352241a304eb6905a1b2dc
|