summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorBernd Kuhls <bernd.kuhls@t-online.de>2018-07-16 19:34:57 (GMT)
committerPeter Korsgaard <peter@korsgaard.com>2018-08-09 20:58:37 (GMT)
commit574d32606a78d170290cca0709ea027f510727b6 (patch)
tree6966bae7e5da1936e02912d67ca0cfe38858c5f8
parente4eaf7311dfffff7fd753f24ce2d01a6f5188292 (diff)
downloadbuildroot-574d32606a78d170290cca0709ea027f510727b6.tar.gz
buildroot-574d32606a78d170290cca0709ea027f510727b6.tar.bz2
package/apache: security bump version to 2.4.34
Fixes: *) SECURITY: CVE-2018-8011 (cve.mitre.org) mod_md: DoS via Coredumps on specially crafted requests *) SECURITY: CVE-2018-1333 (cve.mitre.org) mod_http2: DoS for HTTP/2 connections by specially crafted requests Changelog: http://www.apache.org/dist/httpd/CHANGES_2.4.34 Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de> Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commit 8ef1aaa08478a2d84c17e8bd12e33b0802433ac1) Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
-rw-r--r--package/apache/apache.hash5
-rw-r--r--package/apache/apache.mk2
2 files changed, 4 insertions, 3 deletions
diff --git a/package/apache/apache.hash b/package/apache/apache.hash
index 76c7c76..74a48ae 100644
--- a/package/apache/apache.hash
+++ b/package/apache/apache.hash
@@ -1,3 +1,4 @@
-# From http://archive.apache.org/dist/httpd/httpd-2.4.33.tar.bz2.sha256
-sha256 de02511859b00d17845b9abdd1f975d5ccb5d0b280c567da5bf2ad4b70846f05 httpd-2.4.33.tar.bz2
+# From http://archive.apache.org/dist/httpd/httpd-2.4.34.tar.bz2.sha256
+sha256 fa53c95631febb08a9de41fd2864cfff815cf62d9306723ab0d4b8d7aa1638f0 httpd-2.4.34.tar.bz2
+# Locally computed
sha256 c49c0819a726b70142621715dae3159c47b0349c2bc9db079070f28dadac0229 LICENSE
diff --git a/package/apache/apache.mk b/package/apache/apache.mk
index eaf7b9c..14891ad 100644
--- a/package/apache/apache.mk
+++ b/package/apache/apache.mk
@@ -4,7 +4,7 @@
#
################################################################################
-APACHE_VERSION = 2.4.33
+APACHE_VERSION = 2.4.34
APACHE_SOURCE = httpd-$(APACHE_VERSION).tar.bz2
APACHE_SITE = http://archive.apache.org/dist/httpd
APACHE_LICENSE = Apache-2.0