pkgsrc/graphics/xpm/distinfo
jlam f705b2b3cc Apply fixes derived from the HEAD branch of X.Org (6.8.99) to address
problems noted in CAN-2004-0914:

    Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as
    used in XFree86 and other packages, include (1) multiple integer
    overflows, (2) out-of-bounds memory accesses, (3) directory
    traversal, (4) shell metacharacter, (5) endless loops, and (6)
    memory leaks, which could allow remote attackers to obtain
    sensitive information, cause a denial of service (application
    crash), or execute arbitary code via a certain XPM image file.

Bump PKGREVISION to 4.  Since this is a security-related fix, also
bump the BUILDLINK_RECOMMENDED version for this package.
2005-06-14 18:10:37 +00:00

24 lines
1.3 KiB
Text

$NetBSD: distinfo,v 1.13 2005/06/14 18:10:37 jlam Exp $
SHA1 (xpm-3.4k.tar.gz) = a8eac19e5772bf7b3b177353686c1401fbf334bd
RMD160 (xpm-3.4k.tar.gz) = 65a2e58f97724a48a6834aab991341771c5a1faf
Size (xpm-3.4k.tar.gz) = 148887 bytes
SHA1 (patch-aa) = 33725beb53dc01b022e5110dbffab4c6a3ae65dc
SHA1 (patch-ab) = 0c8f317cdbde27929790e46d1711ada5e454b79d
SHA1 (patch-ac) = 80c8c58a526ccc8651862d87cc5cd92d8aa9fb2d
SHA1 (patch-ad) = d352c47831955845e5805ac737031f2ff179b0df
SHA1 (patch-ae) = 9b11253041212c8e43c426be4729363e4f8e122a
SHA1 (patch-af) = be7953d5baf84d2b08e89576755428d3bc57e8c2
SHA1 (patch-ag) = 74f8e7ed98e6d6c85168464e71274dc1ecb56297
SHA1 (patch-ah) = ffa827d23283c9e937071a202f7f7d5b7846d9d0
SHA1 (patch-ai) = 619392a9bde70210c5f6e0fa1b7f1e278cd68bfb
SHA1 (patch-aj) = db0de3aff27606aceb67027691cb6f55c549478a
SHA1 (patch-ak) = 011da5204f825aaaf4aed4536cfb29a7f63efc5d
SHA1 (patch-al) = 09ceea05f856edd3fad3aedabbdf535c9d919cd9
SHA1 (patch-am) = 3f69a82cb9ebaa4e0fc7ce5c63a938cec31bbbd3
SHA1 (patch-an) = f8f0602116e9000f2506230f0d65eac1171c2904
SHA1 (patch-ao) = 7681e03f1f317ef5e694a464f1efad82d9de78c2
SHA1 (patch-ap) = 6ccb211e9051374cf7cdb6138a6520943e1cd645
SHA1 (patch-aq) = 6d3f3554c7d66d3d9879dc2b352310e32799926c
SHA1 (patch-ar) = c6a5ef0af6568f519467b753aae5050a0513f99e
SHA1 (patch-as) = f11694bc7fb300450fd07d496975bfb0fbb6b68f