From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Mon, 05 Aug 2024 08:56:05 +0200 Received: from metis.whiteo.stw.pengutronix.de ([2a0a:edc0:2:b01:1d::104]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1sardV-006PDn-1p for lore@lore.pengutronix.de; Mon, 05 Aug 2024 08:56:05 +0200 Received: from localhost ([127.0.0.1] helo=metis.whiteo.stw.pengutronix.de) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1sardV-0001EY-5J; Mon, 05 Aug 2024 08:56:05 +0200 Received: from drehscheibe.grey.stw.pengutronix.de ([2a0a:edc0:0:c01:1d::a2]) by metis.whiteo.stw.pengutronix.de with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1sarXR-0003q9-Pw; Mon, 05 Aug 2024 08:49:49 +0200 Received: from [2a0a:edc0:0:1101:1d::54] (helo=dude05.red.stw.pengutronix.de) by drehscheibe.grey.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sarXR-004eBx-8P; Mon, 05 Aug 2024 08:49:49 +0200 Received: from mol by dude05.red.stw.pengutronix.de with local (Exim 4.96) (envelope-from ) id 1sarXR-003jic-0h; Mon, 05 Aug 2024 08:49:49 +0200 From: Michael Olbrich To: ptxdist@pengutronix.de Date: Mon, 5 Aug 2024 08:49:49 +0200 Message-Id: <20240805064949.890719-1-m.olbrich@pengutronix.de> X-Mailer: git-send-email 2.39.2 In-Reply-To: <20240720083628.2470255-1-christian.melki@t2data.com> References: <20240720083628.2470255-1-christian.melki@t2data.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: Re: [ptxdist] [APPLIED] orc: Version bump. 0.4.38 -> 0.4.39 X-BeenThere: ptxdist@pengutronix.de X-Mailman-Version: 2.1.29 Precedence: list List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: ptxdist@pengutronix.de Cc: Christian Melki Sender: "ptxdist" X-SA-Exim-Connect-IP: 127.0.0.1 X-SA-Exim-Mail-From: ptxdist-bounces@pengutronix.de X-SA-Exim-Scanned: No (on metis.whiteo.stw.pengutronix.de); SAEximRunCond expanded to false Thanks, applied as 8bc95742522b6c968f12e4f6a013d42e5581f278. Michael [sent from post-receive hook] On Mon, 05 Aug 2024 08:49:49 +0200, Christian Melki wrote: > Minor changes. > https://discourse.gstreamer.org/t/orc-0-4-39-release/1969 > > Plugs minor CVE: > CVE-2024-40897 - Fix error message printing buffer overflow leading to possible code execution in orcc. > > Signed-off-by: Christian Melki > Message-Id: <20240720083628.2470255-1-christian.melki@t2data.com> > Signed-off-by: Michael Olbrich > > diff --git a/rules/orc.make b/rules/orc.make > index fd3b5bf36390..a26e110226fa 100644 > --- a/rules/orc.make > +++ b/rules/orc.make > @@ -14,8 +14,8 @@ PACKAGES-$(PTXCONF_ORC) += orc > # > # Paths and names > # > -ORC_VERSION := 0.4.38 > -ORC_MD5 := 309ed9f12724e861bed05e8e84e22968 > +ORC_VERSION := 0.4.39 > +ORC_MD5 := 9e25d04059d581702dcd0aca214bb5e8 > ORC := orc-$(ORC_VERSION) > ORC_SUFFIX := tar.xz > ORC_URL := http://gstreamer.freedesktop.org/data/src/orc/$(ORC).$(ORC_SUFFIX)