Bernd Kuhls
7b0c8c6aee
package/x11r7/xapp_xlsatoms: bump version to 1.1.4
...
https://lists.x.org/archives/xorg-announce/2022-November/003258.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:32:30 +01:00
Bernd Kuhls
e20641dcf8
package/x11r7/xapp_xlsclients: bump version to 1.1.5
...
https://lists.x.org/archives/xorg-announce/2022-November/003259.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:32:27 +01:00
Bernd Kuhls
723eff5808
package/x11r7/xlib_libXdmcp: bump version to 1.1.4
...
https://lists.x.org/archives/xorg-announce/2022-November/003260.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:32:21 +01:00
Bernd Kuhls
7d2fff7804
package/x11r7/xlib_libXpm: bump version to 3.5.14
...
https://lists.x.org/archives/xorg-announce/2022-November/003261.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:32:18 +01:00
Bernd Kuhls
327d7453ba
package/x11r7/xlib_libXrandr: bump version to 1.5.3
...
https://lists.x.org/archives/xorg-announce/2022-November/003262.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:32:16 +01:00
Bernd Kuhls
9e1546672c
package/x11r7/xapp_xcursorgen: bump version to 1.0.8
...
https://lists.x.org/archives/xorg-announce/2022-December/003264.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:32:13 +01:00
Bernd Kuhls
42c8fe1914
package/x11r7/xapp_xdm: bump version to 1.1.14
...
https://lists.x.org/archives/xorg-announce/2022-December/003265.html
xlib_libXinerama is an optional dependency now.
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:32:10 +01:00
Bernd Kuhls
e708680a43
package/x11r7/xapp_xfd: bump version to 1.1.4
...
https://lists.x.org/archives/xorg-announce/2022-December/003266.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:32:06 +01:00
Bernd Kuhls
1564c1e6e9
package/x11r7/xapp_xgamma: bump version to 1.0.7
...
https://lists.x.org/archives/xorg-announce/2022-December/003267.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:32:03 +01:00
Bernd Kuhls
8f15b22fdd
package/x11r7/xapp_xinit: bump version to 1.4.2
...
https://lists.x.org/archives/xorg-announce/2022-December/003268.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:32:01 +01:00
Bernd Kuhls
3500526b18
package/x11r7/xapp_xprop: bump version to 1.2.6
...
https://lists.x.org/archives/xorg-announce/2022-December/003269.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:58 +01:00
Bernd Kuhls
835918d8e8
package/x11r7/xapp_xrandr: bump version to 1.5.2
...
https://lists.x.org/archives/xorg-announce/2022-December/003270.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:54 +01:00
Bernd Kuhls
ea7d4fe0df
package/x11r7/xapp_xset: bump version to 1.2.5
...
https://lists.x.org/archives/xorg-announce/2022-December/003271.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:51 +01:00
Bernd Kuhls
4818600510
package/x11r7/xapp_xstdcmap: bump version to 1.0.5
...
https://lists.x.org/archives/xorg-announce/2022-December/003272.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:49 +01:00
Bernd Kuhls
7f08e0d7de
package/x11r7/xapp_xvinfo: bump version to 1.1.5
...
https://lists.x.org/archives/xorg-announce/2022-December/003273.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:46 +01:00
Bernd Kuhls
4df6b365b7
package/x11r7/xdriver_xf86-video-r128: bump version to 6.12.1
...
https://lists.x.org/archives/xorg-announce/2022-December/003275.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:43 +01:00
Bernd Kuhls
d39f7ecd49
package/x11r7/xlib_libXcomposite: bump version to 0.4.6
...
https://lists.x.org/archives/xorg-announce/2022-December/003276.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:40 +01:00
Bernd Kuhls
bac3d21a3f
package/x11r7/xlib_libXdamage: bump version to 1.1.6
...
https://lists.x.org/archives/xorg-announce/2022-December/003277.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:36 +01:00
Bernd Kuhls
6b6ea10c52
package/x11r7/xlib_libXres: bump version to 1.2.2
...
https://lists.x.org/archives/xorg-announce/2022-December/003278.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:33 +01:00
Bernd Kuhls
8929d19dfb
package/x11r7/xlib_libXScrnSaver: bump version to 1.2.4
...
https://lists.x.org/archives/xorg-announce/2022-December/003279.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:30 +01:00
Bernd Kuhls
bc8b91fdad
package/x11r7/xlib_libXv: bump version to 1.0.12
...
https://lists.x.org/archives/xorg-announce/2022-December/003280.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:27 +01:00
Bernd Kuhls
d6e3bcfb37
package/x11r7/xlib_libXxf86dga: bump version to 1.1.6
...
https://lists.x.org/archives/xorg-announce/2022-December/003281.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:25 +01:00
Bernd Kuhls
38e3837027
package/x11r7/xapp_xkbcomp: bump version to 1.4.6
...
https://lists.x.org/archives/xorg-announce/2022-December/003283.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:21 +01:00
Bernd Kuhls
7436867eb1
package/x11r7/xlib_libXau: bump version to 1.0.11
...
https://lists.x.org/archives/xorg-announce/2022-December/003284.html
https://lists.x.org/archives/xorg-announce/2022-August/003201.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:17 +01:00
Bernd Kuhls
8ce4206c9e
package/x11r7/xlib_libfontenc: bump version to 1.1.7
...
https://lists.x.org/archives/xorg-announce/2022-December/003285.html
https://lists.x.org/archives/xorg-announce/2022-August/003204.html
https://lists.x.org/archives/xorg-announce/2022-August/003199.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:14 +01:00
Bernd Kuhls
1cfae45da9
package/x11r7/xlib_libxkbfile: bump version to 1.1.2
...
https://lists.x.org/archives/xorg-announce/2022-December/003286.html
https://lists.x.org/archives/xorg-announce/2022-October/003227.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:10 +01:00
Bernd Kuhls
79a72dd0a5
package/x11r7/xlib_libxshmfence: bump version to 1.3.2
...
https://lists.x.org/archives/xorg-announce/2022-December/003287.html
https://lists.x.org/archives/xorg-announce/2022-October/003229.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:07 +01:00
Bernd Kuhls
d8ae5b86ed
package/x11r7/xlib_libICE: bump version to 1.1.1
...
https://lists.x.org/archives/xorg-announce/2022-December/003288.html
https://lists.x.org/archives/xorg-announce/2022-December/003274.html
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:04 +01:00
Bernd Kuhls
82abffdbb7
package/x11r7/xdriver_xf86-input-mouse: bump version to 1.9.4
...
Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-09 17:31:00 +01:00
Peter Korsgaard
f298729fc3
Revert "package/mupdf: fix CVE-2021-4216"
...
This reverts commit 3ddca0ccb9 .
With the merge of next, we are now using mupdf 1.20.3, so this fix is no
longer needed.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-12-05 15:14:59 +01:00
Peter Korsgaard
2313f68e4c
package/sdl2_ttf: fix legal-info after bump to 2.20.1
...
Commit 93d8b71371 (package/sdl2_ttf: bump version to 2.20.1) dropped the
hash for COPYING.txt and added a hash for LICENSE.txt but forgot to adjust
SDL2_TTF_LICENSE_FILES, breaking legal-info:
>>> sdl2_ttf 2.20.1 Collecting legal info
ERROR: No hash found for COPYING.txt
cp: cannot stat '/path/to/output/build/sdl2_ttf-2.20.1/COPYING.txt': No such file or directory
make[1]: *** [package/sdl2_ttf/sdl2_ttf.mk:38: sdl2_ttf-legal-info] Error 1
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-12-05 14:18:06 +01:00
Peter Korsgaard
ac96a65a29
Revert "package/python3: fix CVE-2022-37454"
...
Fixes:
http://autobuild.buildroot.net/results/270/2707e4e5545e2cf70ad5dfa36a5c25d3a44916d2/
This reverts commit 92d96e8513 .
With the merge of next, we are now using python 3.11.0, so this fix is no
longer needed.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-12-05 13:18:02 +01:00
Peter Korsgaard
6ca0edcb5f
Merge branch 'next'
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-12-05 10:01:26 +01:00
Thomas Petazzoni
e40f96af34
DEVELOPERS: remove Sven Haardiek
...
His e-mail address no longer exists:
Your message to sven.haardiek@iotec-gmbh.de couldn't be delivered.
sven.haardiek wasn't found at iotec-gmbh.de.
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2022-12-05 09:20:54 +01:00
Thomas Petazzoni
6aca1d4d70
DEVELOPERS: remove Derrick Lyndon Pallas
...
His e-mail address no longer exists:
Your message wasn't delivered to derrick@meter.com because the address
couldn't be found, or is unable to receive mail.
Learn more here: https://support.google.com/mail/answer/6596
The response was:
The email account that you tried to reach does not exist. Please try
double-checking the recipient's email address for typos or unnecessary
spaces. Learn more at https://support.google.com/mail/answer/6596
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2022-12-05 09:19:48 +01:00
Peter Korsgaard
15d3648df9
Kickoff 2023.02 cycle
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-12-05 09:01:16 +01:00
Peter Korsgaard
45c6747fae
docs/website/news.html: add 2022.11 announcement link
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-12-05 08:59:51 +01:00
Peter Korsgaard
40bd4a32aa
Update for 2022.11
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022.11
2022-12-05 08:23:19 +01:00
Fabrice Fontaine
74b1d385b6
package/lxc: fix build with sys/pidfd.h
...
Fix the following build failure with sys/pidfd.h raised since bump to
version 5.0.1 in commit db19998035 :
In file included from ../src/lxc/utils.h:23,
from ../src/lxc/cgroups/cgfsng.c:51:
../src/lxc/process_utils.h:140:17: error: expected identifier before numeric constant
140 | #define P_PIDFD 3
| ^
Fixes:
- http://autobuild.buildroot.org/results/c9ff42a921ca47f634f908bab80c80164c227a02
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-12-05 08:14:32 +01:00
Fabrice Fontaine
5c1f67428a
utils/genrandconfig: add mxs-bootlets board handling
...
Add a custom case to make sure that a random configuration with an empty
board for mxs-bootlets doesn't fail. It reverts to
BR2_TARGET_MXS_BOOTLETS_STMP37xx in that case.
>>> mxs-bootlets 10.12.01 Building
BOARD= CROSS_COMPILE="/home/thomas/autobuild/instance-1/output-1/per-package/mxs-bootlets/host/bin/arm-buildroot-linux-uclibcgnueabi-" /usr/bin/make -j1 -C /home/thomas/autobuild/instance-1/output-1/build/mxs-bootlets-10.12.01 power_prep
/home/thomas/autobuild/instance-1/output-1/per-package/xinetd/host/bin/arm-buildroot-linux-uclibcgnueabi-gcc -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0 -static -DNO_RPC -I../../include -c -o inet_aton.o inet_aton.c
make[1]: Entering directory '/home/thomas/autobuild/instance-1/buildroot'
make[1]: warning: -j1 forced in submake: resetting jobserver mode.
build power_prep
/usr/bin/make -C power_prep ARCH= BOARD=
make[2]: Entering directory '/home/thomas/autobuild/instance-1/output-1/build/mxs-bootlets-10.12.01/power_prep'
/usr/bin/make -C ./../mach-/hw
make[3]: Entering directory '/home/thomas/autobuild/instance-1/output-1/build/mxs-bootlets-10.12.01/power_prep'
make[3]: *** ../mach-/hw: No such file or directory. Stop.
Fixes:
- http://autobuild.buildroot.org/results/44a2efc64b9b8ff4541430d6b649e7a11a4e4873
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2022-12-05 08:14:00 +01:00
Jesse Van Gavere
34c7b86224
DEVELOPERS: add Jesse for the qt6 package
...
Signed-off-by: Jesse Van Gavere <jesseevg@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-04 21:31:46 +01:00
Fabrice Fontaine
cc1edd8c06
package/qt6/qt6serialport: fix license
...
Commit 343974b995 forgot to change the
licensing information which has been updated with
https://code.qt.io/cgit/qt/qtserialport.git/commit/?id=bb05a26d52c834cc7f3c549f3e5d66f76baf42a2
resulting in the following build failure:
ERROR: LICENSE.GPL2 has wrong sha256 hash:
ERROR: expected: 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643
ERROR: got :
Fixes:
- No autobuilder failures yet
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
[yann.morin.1998@free.fr: one-item per line]
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
2022-12-04 20:57:43 +01:00
Fabrice Fontaine
d37b3f384c
package/qt6/qt6base: fix license
...
Commit 343974b995 forgot to change the
licensing information which has been updated with
https://code.qt.io/cgit/qt/qtbase.git/commit/?id=05fc3aef53348fb58be6308076e000825b704e58
resulting in the following build failure:
ERROR: LICENSE.GPL2 has wrong sha256 hash:
ERROR: expected: 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643
ERROR: got :
Fixes:
- http://autobuild.buildroot.org/results/bf20b7457349f1bb7a82d471ad2c9e4307ac540c
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
[yann.morin.1998@free.fr:
- one-item per line, both for _LICENSE and _LICENSE_FILES
- fix check-package
]
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
2022-12-04 20:57:43 +01:00
Patrick Gerber
cd95a33511
package/pkg-golang: use package go env for download step
...
Currently package secific go env is used only during package build step.
Go vendering is done during the download step and it's sometimes required
to specify package secific go env also for this step.
For example, when importing custom go modules who are hosted on a private
host, it’s required to set GOPRIVATE to avoid public sum checking.
Of all the environment variables driving the behaviour of the go command
[0], there is none that obviously have an impact on the behaviour of
go-mod, unless they are explicitly listed as such [1], so it seems
pretty safe to include the generic environment variables for the
download step.
[0] https://pkg.go.dev/cmd/go#hdr-Environment_variables
[1] https://go.dev/ref/mod#environment-variables
Signed-off-by: Patrick Gerber <pge@ik.me >
[yann.morin.1998@free.fr: add [0] and [1] and corresponding blurb]
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
2022-12-04 18:29:08 +01:00
Patrick Gerber
9fcf6ea435
package/mender-artifact: remove unnecessary GO_ENV
...
Commit 235636409f (package/mender-artifact: do not download modules
during the build process) introduced the use of GOFLAGS="-mod=vendor",
in 2020-08-13, before we had the go download post-process...
... which was introduced with ommit 24ac316ff5 (package/pkg-golang.mk:
implement Go vendoring support), in 2022-01-08, which added $(2)_DL_ENV
which contains $(HOST_GO_COMMON_ENV).
HOST_GO_COMMON_ENV, set in go/go.mk@23,i already contains
GOFLAGS="-mod=vendor".
Signed-off-by: Patrick Gerber <pge@ik.me >
[yann.morin.1998@free.fr: extend commit log]
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
2022-12-04 18:29:08 +01:00
Fabrice Fontaine
bdc9f8a247
package/python-scipy: fix sh4 build
...
Fix the following sh4 build failure raised since the addition of the
package in commit e10431db29 :
INFO: sh4aeb-linux-gcc: scipy/special/_test_round.c
scipy/special/_test_round.c: In function '__pyx_pf_5scipy_7special_11_test_round_have_fenv':
scipy/special/_test_round.c:2353:30: error: 'FE_UPWARD' undeclared (first use in this function)
2353 | __pyx_t_1 = ((fesetround(FE_UPWARD) != 0) != 0);
| ^~~~~~~~~
Retrieve debian patch as upstream doesn't want to fix this SH4 specific
issue: https://github.com/scipy/scipy/issues/15584
Fixes:
- http://autobuild.buildroot.org/results/b82d8ed02ba5d094a0d4054e0de28e95c9d3554d
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2022-12-04 14:16:07 +01:00
Vincent Stehlé
17cb635a8a
boot/edk2: bump version to edk2-stable202208
...
The Marvell Armada Devicetree files have been moved out of edk2-platforms
by commit 4b53da6b12a8 ("Marvell/Armada7k8k: Remove device tree sources
from edk2-platforms") and they are now in edk2-non-osi.
Therefore update the MACCHIATObin recipe to depend on the new edk2-non-osi
package and rework a bit the packages path to support that.
Also, drop the backported patch as it is not necessary anymore.
Signed-off-by: Vincent Stehlé <vincent.stehle@arm.com >
Cc: Dick Olsson <hi@senzilla.io >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2022-12-04 13:51:54 +01:00
Vincent Stehlé
95f72fb61a
package/edk2-non-osi: new package
...
Add a package to install the additional edk2 platforms files, not
compatible with the normal licensing requirements and held in the
edk2-non-osi repository.
Only the Marvell Armada files are copied at this point, to support building
edk2 for the MACCHIATObin platform.
The referenced commit corresponds to version edk2-stable202208 of edk2,
based on the timestamps.
This package is heavily inspired from package/edk2-platforms.
Signed-off-by: Vincent Stehlé <vincent.stehle@arm.com >
Cc: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2022-12-04 13:51:54 +01:00
Fabrice Fontaine
3341ceb1e5
package/gdb: zlib is mandatory, not optional
...
zlib is a mandatory dependency of gdb and by default, gdb will use its
internal one. Moreover, --with-zlib has been replaced by
--with-system-zlib since version 7.10 and
fa1f5da0b6
Fixes:
- https://bugs.buildroot.org/show_bug.cgi?id=15131
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-04 12:56:19 +01:00
Fabrice Fontaine
92d96e8513
package/python3: fix CVE-2022-37454
...
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an
integer overflow and resultant buffer overflow that allows attackers to
execute arbitrary code or eliminate expected cryptographic properties.
This occurs in the sponge function interface.
Python 3.11 and later switched to using tiny_sha3 in GH-32060, so they
should not be affected.
https://github.com/python/cpython/issues/98517
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2022-12-04 12:51:30 +01:00