Browse Source

package/rabbitmq-c: security bump to version 0.10.0

Add additional input validation to prevent integer overflow when parsing
a frame header. This addresses CVE-2019-18609.

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 63d0762ab72a3536ea2e07ac75327c7556ed72c1)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Fabrice Fontaine 5 years ago
parent
commit
3fc8d57f34
2 changed files with 3 additions and 3 deletions
  1. 1 1
      package/rabbitmq-c/rabbitmq-c.hash
  2. 2 2
      package/rabbitmq-c/rabbitmq-c.mk

+ 1 - 1
package/rabbitmq-c/rabbitmq-c.hash

@@ -1,3 +1,3 @@
 # Locally calculated
 # Locally calculated
-sha256 316c0d156452b488124806911a62e0c2aa8a546d38fc8324719cd29aaa493024 rabbitmq-c-v0.9.0.tar.gz
+sha256 6455efbaebad8891c59f274a852b75b5cc51f4d669dfc78d2ae7e6cc97fcd8c0 rabbitmq-c-0.10.0.tar.gz
 sha256 94a12c906acb31a66c2c8a6c1b6e46cab52bc5694c5ada2a06d86b05d3d3f422 LICENSE-MIT
 sha256 94a12c906acb31a66c2c8a6c1b6e46cab52bc5694c5ada2a06d86b05d3d3f422 LICENSE-MIT

+ 2 - 2
package/rabbitmq-c/rabbitmq-c.mk

@@ -4,8 +4,8 @@
 #
 #
 ################################################################################
 ################################################################################
 
 
-RABBITMQ_C_VERSION = v0.9.0
-RABBITMQ_C_SITE = $(call github,alanxz,rabbitmq-c,$(RABBITMQ_C_VERSION))
+RABBITMQ_C_VERSION = 0.10.0
+RABBITMQ_C_SITE = $(call github,alanxz,rabbitmq-c,v$(RABBITMQ_C_VERSION))
 RABBITMQ_C_LICENSE = MIT
 RABBITMQ_C_LICENSE = MIT
 RABBITMQ_C_LICENSE_FILES = LICENSE-MIT
 RABBITMQ_C_LICENSE_FILES = LICENSE-MIT
 RABBITMQ_C_INSTALL_STAGING = YES
 RABBITMQ_C_INSTALL_STAGING = YES