pkgsrc/devel/apr/distinfo
he 15a221f014 Add a patch to deal with CVE-2021-35940.
An out-of-bounds array read in the apr_time_exp*() functions was
fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613).
The fix for this issue was not carried forward to the APR 1.7.x
branch, and hence version 1.7.0 regressed compared to 1.6.3 and is
vulnerable to the same issue.

https://svn.apache.org/viewvc?view=revision&revision=1891198

Bump PKGREVISION.
2021-11-28 12:57:05 +00:00

11 lines
828 B
Text

$NetBSD: distinfo,v 1.49 2021/11/28 12:57:05 he Exp $
BLAKE2s (apr-1.7.0.tar.bz2) = f6126e30d08bc9dd7333bb9ee5814d606ae3b8f26f31ac6132bc918c22e57de0
SHA512 (apr-1.7.0.tar.bz2) = 3dc42d5caf17aab16f5c154080f020d5aed761e22db4c5f6506917f6bfd2bf8becfb40af919042bd4ce1077d5de74aa666f5edfba7f275efba78e8893c115148
Size (apr-1.7.0.tar.bz2) = 872238 bytes
SHA1 (patch-atomic_unix_builtins.c) = e90d0232013650c3d227fa3a8be952c51b7148e8
SHA1 (patch-atomic_unix_builtins64.c) = e24316e93dae12efc1cbfc3f444e8622df5e5833
SHA1 (patch-include_apr__general.h) = bff357eee11218a6c53769278fc3f9094b062fdf
SHA1 (patch-include_arch_unix_apr__arch__atomic.h) = 6f226add54f5966a50985441f6903853a0728c88
SHA1 (patch-time_unix_time.c) = d3da97cb4b6c7b6416fecb49006470db46084276
SHA1 (patch-time_win32_time.c) = aee61377826292c238352241a304eb6905a1b2dc