From d80f5c99fdaf2ffb20e3453236b987301b277b34 Mon Sep 17 00:00:00 2001 From: Gustavo Zacarias Date: Tue, 16 Dec 2014 11:08:17 -0300 Subject: [PATCH] subversion: security bump to version 1.7.19 Fixes: CVE-2014-3580: mod_dav_svn DoS from invalid REPORT requests. CVE-2014-8108: mod_dav_svn DoS from use of invalid transaction names. Also add hash file. Signed-off-by: Gustavo Zacarias Signed-off-by: Thomas Petazzoni --- package/subversion/subversion.hash | 2 ++ package/subversion/subversion.mk | 3 +-- 2 files changed, 3 insertions(+), 2 deletions(-) create mode 100644 package/subversion/subversion.hash diff --git a/package/subversion/subversion.hash b/package/subversion/subversion.hash new file mode 100644 index 0000000000..b6a0e88617 --- /dev/null +++ b/package/subversion/subversion.hash @@ -0,0 +1,2 @@ +# From https://mail-archives.apache.org/mod_mbox/subversion-dev/201412.mbox/%3C548F4EEB.7030601@apache.org%3E +sha1 bb3cd135bbd856e7f0f2d59313f075b9bbec9848 subversion-1.7.19.tar.gz diff --git a/package/subversion/subversion.mk b/package/subversion/subversion.mk index 5f37a87c77..3c6c3f0f73 100644 --- a/package/subversion/subversion.mk +++ b/package/subversion/subversion.mk @@ -4,11 +4,10 @@ # ################################################################################ -SUBVERSION_VERSION = 1.7.18 +SUBVERSION_VERSION = 1.7.19 SUBVERSION_SITE = http://archive.apache.org/dist/subversion SUBVERSION_LICENSE = Apache-2.0 SUBVERSION_LICENSE_FILES = LICENSE - SUBVERSION_DEPENDENCIES = host-pkgconf apr apr-util expat neon zlib sqlite SUBVERSION_CONF_OPTS = \ --with-expat=$(STAGING_DIR)/usr/include:$(STAGING_DIR)/usr/lib: \