From patchwork Fri May 14 20:08:26 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Fabrice Fontaine X-Patchwork-Id: 1478678 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=busybox.net (client-ip=140.211.166.133; helo=smtp2.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=GYRyalr1; dkim-atps=neutral Received: from smtp2.osuosl.org (smtp2.osuosl.org [140.211.166.133]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4Fhfjv6tJJz9sVt for ; Sat, 15 May 2021 06:08:51 +1000 (AEST) Received: from localhost (localhost [127.0.0.1]) by smtp2.osuosl.org (Postfix) with ESMTP id 576E44061F; Fri, 14 May 2021 20:08:50 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from smtp2.osuosl.org ([127.0.0.1]) by localhost (smtp2.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Rb3UVsZW8Tyk; Fri, 14 May 2021 20:08:49 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by smtp2.osuosl.org (Postfix) with ESMTP id B339C4061E; Fri, 14 May 2021 20:08:48 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from smtp4.osuosl.org (smtp4.osuosl.org [140.211.166.137]) by ash.osuosl.org (Postfix) with ESMTP id 00BE91BF27C for ; Fri, 14 May 2021 20:08:48 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by smtp4.osuosl.org (Postfix) with ESMTP id E9D6541867 for ; Fri, 14 May 2021 20:08:47 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Authentication-Results: smtp4.osuosl.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com Received: from smtp4.osuosl.org ([127.0.0.1]) by localhost (smtp4.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kXJN5Dg8IKxw for ; Fri, 14 May 2021 20:08:46 +0000 (UTC) X-Greylist: whitelisted by SQLgrey-1.8.0 Received: from mail-wm1-x32e.google.com (mail-wm1-x32e.google.com [IPv6:2a00:1450:4864:20::32e]) by smtp4.osuosl.org (Postfix) with ESMTPS id AE27140266 for ; Fri, 14 May 2021 20:08:46 +0000 (UTC) Received: by mail-wm1-x32e.google.com with SMTP id u133so328097wmg.1 for ; Fri, 14 May 2021 13:08:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=nUAEu+xRgrqxcTk7r84bJ4CjOhPGHUlPI7tlB+nxGIw=; b=GYRyalr1u68qqZyy+p0aamf2xk5Zx8EQhfoNdSk54DV5mAdbkUqvdDMik71K4MZvUf yeFJpqFd+2fnp5ehQwylVWjYq8RipY/frNTJFWjBekV2/TKL4p/dYOvU+CyAoCjU6maX 0Up1iXvPQTvI7E6bEMUAUODfayYspVKk9v6QThSwev2qJ3c2TjW4DYmOn/IpUpRNkpgn NUFCLYOO4B22h4GiloXpW8t3XwwzEGwtk3rlJuslFvAhJ2FnGASVlnY/e/l6CqEVZnzE 27iGrcHbeQFaiN1FflFccwTbVFBNhK/S/KCTZDyf5R/cdDnSR7EO3/w9HgIEjxO3/MKd GXzQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=nUAEu+xRgrqxcTk7r84bJ4CjOhPGHUlPI7tlB+nxGIw=; b=uKOot5600soEc+71gQgwnTwyJeHUZfvUWuEyU3+IT1f4exUPF98ZfJ1+2T/qH87Xp7 8yNIZG2qa/r7bpSCmHnzVJj2WNW3i6W4aWSy+d6P3Jv596czEoSf1EmXHveCNysCvjER lGD1L9Gq8m+Mk6Z8o2PH92b3xmlnuevGAVSv4WgnWBqJMINlL83ZdhcHj7wf6XbSmvbZ GEaHIPuuul97F+iCScdjN67GwsZdl1aOAtPoJjNSZy8eTw6U/sBd3BFAptMww6ia3PMg aAJMk97T1xWBvEnNztneOdgtCacWEACM4qov2HUqxAgHkHorEg64i9aqQIzEgo/vkd5j 2ODQ== X-Gm-Message-State: AOAM533n7HcU0jT4M+l+XXNp+OplpbnwssiM3BsfxR/HLpLRESf8vpRx xTiOOIyTBvhW1Fo9Qv7xDieXqvOr0OA= X-Google-Smtp-Source: ABdhPJwVdScGpQZLa/G16VxyZ61LbA1kPHGfx0dTYQqyArNxMxKUb9rSRDrD6rxYwjDSOcpHjDxGLw== X-Received: by 2002:a7b:c4cb:: with SMTP id g11mr3049910wmk.168.1621022924576; Fri, 14 May 2021 13:08:44 -0700 (PDT) Received: from kali.home (lfbn-ren-1-1383-171.w86-229.abo.wanadoo.fr. [86.229.230.171]) by smtp.gmail.com with ESMTPSA id f1sm8401938wrr.63.2021.05.14.13.08.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 May 2021 13:08:44 -0700 (PDT) From: Fabrice Fontaine To: buildroot@buildroot.org Date: Fri, 14 May 2021 22:08:26 +0200 Message-Id: <20210514200826.2237923-1-fontaine.fabrice@gmail.com> X-Mailer: git-send-email 2.30.2 MIME-Version: 1.0 Subject: [Buildroot] [PATCH 1/1] package/live555: security bump to version 2021.05.03 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Fabrice Fontaine Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" Fix CVE-2021-28899: Vulnerability in the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaSubsessionLive OnDemandServerMediaSubsession subclasses in Networks LIVE555 Streaming Media before 2021.3.16. http://live555.com/liveMedia/public/changelog.txt Signed-off-by: Fabrice Fontaine --- package/live555/live555.hash | 4 ++-- package/live555/live555.mk | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/package/live555/live555.hash b/package/live555/live555.hash index 5e65cacd7b..d4fa93d029 100644 --- a/package/live555/live555.hash +++ b/package/live555/live555.hash @@ -1,5 +1,5 @@ # From http://www.live555.com/liveMedia/public/live555-latest-md5.txt -md5 4645d2a0c865505c85b48af5317bcb4a live.2020.08.19.tar.gz +md5 3c1992b0e9b871bcad7491a3da541781 live.2021.05.03.tar.gz # Locally generated -sha256 af3af7f2510b0b45f38892c232abca2cee2ab36a62503e7085b47ed2c3c2c537 live.2020.08.19.tar.gz +sha256 ae73241f9cc4ab740d60737c0438d62a7635af3822de5d84acf275793de42029 live.2021.05.03.tar.gz sha256 da7eabb7bafdf7d3ae5e9f223aa5bdc1eece45ac569dc21b3b037520b4464768 COPYING.LESSER diff --git a/package/live555/live555.mk b/package/live555/live555.mk index 9a5c1c7c0d..effd4517cf 100644 --- a/package/live555/live555.mk +++ b/package/live555/live555.mk @@ -4,7 +4,7 @@ # ################################################################################ -LIVE555_VERSION = 2020.08.19 +LIVE555_VERSION = 2021.05.03 LIVE555_SOURCE = live.$(LIVE555_VERSION).tar.gz LIVE555_SITE = http://www.live555.com/liveMedia/public # There is a COPYING file with the GPL-3.0 license text, but none of