kumquat-buildroot/package/apr
Fabrice Fontaine 10d80eb39a package/apr: fix CVE-2021-35940
An out-of-bounds array read in the apr_time_exp*() functions was fixed
in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix
for this issue was not carried forward to the APR 1.7.x branch, and
hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the
same issue.

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
2022-04-04 19:35:40 +02:00
..
0001-cross-compile.patch
0002-sys-param-h.patch
0003-Merge-r1887279-from-trunk.patch
0004-apr-1.7.0-CVE-2021-35940.patch package/apr: fix CVE-2021-35940 2022-04-04 19:35:40 +02:00
apr.hash
apr.mk package/apr: fix CVE-2021-35940 2022-04-04 19:35:40 +02:00
Config.in package/apr: change URL from http to https 2022-04-02 19:28:20 +02:00