Skip to content
Commit 20bf02ce authored by Titouan Christophe's avatar Titouan Christophe Committed by Peter Korsgaard
Browse files

package/thrift: security bump to v0.13



Drop patch because the linker error no longer appears on br-x86-64-musl.

v0.13.0 fixes the following CVEs:

CVE-2019-0205: In Apache Thrift all versions up to and including 0.12.0,
a server or client may run into an endless loop when feed with specific
input data. Because the issue had already been partially fixed in version
0.11.0, depending on the installed version it affects only certain
language bindings.

CVE-2019-0210: In Apache Thrift 0.9.3 to 0.12.0, a server implemented
in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with
invalid input data.

Also update the hash file to the new two-spaces convention

Signed-off-by: default avatarTitouan Christophe <titouan.christophe@railnova.eu>
Signed-off-by: default avatarPeter Korsgaard <peter@korsgaard.com>
parent e78684e4
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment