c-ares: update to version 1.17.2
authorPetr Štetiar <ynezz@true.cz>
Tue, 10 Aug 2021 07:15:06 +0000 (09:15 +0200)
committerKarl Palsson <karlp@etactica.com>
Fri, 20 Aug 2021 10:33:33 +0000 (10:33 +0000)
Missing input validation of host names returned by Domain Name Servers
in the c-ares library can lead to output of wrong hostnames (leading to
Domain Hijacking).

The Common Vulnerabilities and Exposures (CVE) project has assigned the
name CVE-2021-3672 to this issue.

References: https://c-ares.haxx.se/adv_20210810.html
Signed-off-by: Petr Štetiar <ynezz@true.cz>
libs/c-ares/Makefile

index 885b81812423e960751f48a0fa6b24fc4b12a105..495d03ef95355a18572e98f8806caf3778031e15 100644 (file)
@@ -9,12 +9,12 @@
 include $(TOPDIR)/rules.mk
 
 PKG_NAME:=c-ares
-PKG_VERSION:=1.17.1
+PKG_VERSION:=1.17.2
 PKG_RELEASE:=1
 
 PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz
 PKG_SOURCE_URL:=https://c-ares.haxx.se/download
-PKG_HASH:=d73dd0f6de824afd407ce10750ea081af47eba52b8a6cb307d220131ad93fc40
+PKG_HASH:=4803c844ce20ce510ef0eb83f8ea41fa24ecaae9d280c468c582d2bb25b3913d
 
 PKG_LICENSE:=MIT
 PKG_LICENSE_FILES:=LICENSE.md