Browse Source

package/exfat-utils: security bump to version 1.4.0

Fix CVE-2022-29973: relan exFAT 1.3.0 allows local users to obtain
sensitive information (data from deleted files in the filesystem) in
certain situations involving offsets beyond ValidDataLength.

https://github.com/relan/exfat/releases/tag/v1.4.0

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit d7085ab3eaeb05fedefdb862efe78ad85ab80187)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Fabrice Fontaine 2 years ago
parent
commit
cb2d0c50e6
2 changed files with 2 additions and 2 deletions
  1. 1 1
      package/exfat-utils/exfat-utils.hash
  2. 1 1
      package/exfat-utils/exfat-utils.mk

+ 1 - 1
package/exfat-utils/exfat-utils.hash

@@ -1,3 +1,3 @@
 # Locally calculated
-sha256  dfebd07a7b907e2d603d3a9626e6440bd43ec6c4e8c07ccfc57ce9502b724835  exfat-utils-1.3.0.tar.gz
+sha256  241575fa93104406a47e79e53e4d907bae69886f11621f70a45276c62b75bf69  exfat-utils-1.4.0.tar.gz
 sha256  8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643  COPYING

+ 1 - 1
package/exfat-utils/exfat-utils.mk

@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-EXFAT_UTILS_VERSION = 1.3.0
+EXFAT_UTILS_VERSION = 1.4.0
 EXFAT_UTILS_SITE = https://github.com/relan/exfat/releases/download/v$(EXFAT_UTILS_VERSION)
 EXFAT_UTILS_LICENSE = GPL-2.0+
 EXFAT_UTILS_LICENSE_FILES = COPYING