SECURITY update to libksba-1.6.3

Fix for CVE-2022-47629.

References:
https://dev.gnupg.org/T6284
https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html

Even though the update to 1.6.2 fixed one integer overflow
(CVE-2022-3515), upstream later rolled another release.  This one was
missed by portroach until recently...
This commit is contained in:
jca 2022-12-27 17:33:43 +00:00
parent 884cb506c5
commit 356afb8ca4
2 changed files with 3 additions and 4 deletions

View File

@ -1,7 +1,6 @@
COMMENT = X.509 library
DISTNAME = libksba-1.6.2
REVISION = 0
DISTNAME = libksba-1.6.3
CATEGORIES = security
SHARED_LIBS = ksba 2.0 # 22.0

View File

@ -1,2 +1,2 @@
SHA256 (libksba-1.6.2.tar.bz2) = /OAcysWYEr3a3/rP8BfawuR2K9tuvG/+BvbtT2GSyXE=
SIZE (libksba-1.6.2.tar.bz2) = 667846
SHA256 (libksba-1.6.3.tar.bz2) = P3LGjbMJceu/FDZ1J3GUI/Ck1fgQP8n0ocAan6RA3lw=
SIZE (libksba-1.6.3.tar.bz2) = 668287