From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Fri, 09 May 2025 09:29:21 +0200 Received: from metis.whiteo.stw.pengutronix.de ([2a0a:edc0:2:b01:1d::104]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1uDIAa-003irQ-3D for lore@lore.pengutronix.de; Fri, 09 May 2025 09:29:21 +0200 Received: from localhost ([127.0.0.1] helo=metis.whiteo.stw.pengutronix.de) by metis.whiteo.stw.pengutronix.de with esmtp (Exim 4.92) (envelope-from ) id 1uDIAa-0000EJ-Pe; Fri, 09 May 2025 09:29:20 +0200 Received: from drehscheibe.grey.stw.pengutronix.de ([2a0a:edc0:0:c01:1d::a2]) by metis.whiteo.stw.pengutronix.de with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1uDI6Y-0005sy-EL; Fri, 09 May 2025 09:25:10 +0200 Received: from dude05.red.stw.pengutronix.de ([2a0a:edc0:0:1101:1d::54]) by drehscheibe.grey.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1uDI6Y-001qrh-0n; Fri, 09 May 2025 09:25:10 +0200 Received: from mol by dude05.red.stw.pengutronix.de with local (Exim 4.96) (envelope-from ) id 1uDI6Y-00BF2g-0e; Fri, 09 May 2025 09:25:10 +0200 From: Michael Olbrich To: ptxdist@pengutronix.de Date: Fri, 9 May 2025 09:25:10 +0200 Message-Id: <20250509072510.2679423-1-m.olbrich@pengutronix.de> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20250415110728.529785-1-ada@thorsis.com> References: <20250415110728.529785-1-ada@thorsis.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: Re: [ptxdist] [APPLIED] fcgi: version bump 2.4.2 -> 2.4.5 X-BeenThere: ptxdist@pengutronix.de X-Mailman-Version: 2.1.29 Precedence: list List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: ptxdist@pengutronix.de Cc: Alexander Dahl Sender: "ptxdist" X-SA-Exim-Connect-IP: 127.0.0.1 X-SA-Exim-Mail-From: ptxdist-bounces@pengutronix.de X-SA-Exim-Scanned: No (on metis.whiteo.stw.pengutronix.de); SAEximRunCond expanded to false Thanks, applied as c244a79b1b73430e0f2cbedb5126a41e9d794756. Michael [sent from post-receive hook] On Fri, 09 May 2025 09:25:10 +0200, Alexander Dahl wrote: > Mitigates CVE-2025-23016. > > Link: https://github.com/FastCGI-Archives/fcgi2/compare/2.4.2...2.4.3 > Link: https://github.com/FastCGI-Archives/fcgi2/compare/2.4.3...2.4.4 > Link: https://github.com/FastCGI-Archives/fcgi2/compare/2.4.4...2.4.5 > Link: https://github.com/advisories/GHSA-9825-56cx-cfg6 > Signed-off-by: Alexander Dahl > Message-Id: <20250415110728.529785-1-ada@thorsis.com> > Signed-off-by: Michael Olbrich > > diff --git a/patches/fcgi-2.4.2/autogen.sh b/patches/fcgi-2.4.5/autogen.sh > similarity index 100% > rename from patches/fcgi-2.4.2/autogen.sh > rename to patches/fcgi-2.4.5/autogen.sh > diff --git a/rules/fcgi.make b/rules/fcgi.make > index 1ff327672b03..249eb2e27ad2 100644 > --- a/rules/fcgi.make > +++ b/rules/fcgi.make > @@ -12,15 +12,15 @@ PACKAGES-$(PTXCONF_FCGI) += fcgi > # > # Paths and names > # > -FCGI_VERSION := 2.4.2 > -FCGI_MD5 := 146376d5c5c059b9184755db76505fab > +FCGI_VERSION := 2.4.5 > +FCGI_MD5 := 2d87ab3f5b1321cd39e1b6a9bd9e3088 > FCGI := fcgi-$(FCGI_VERSION) > FCGI_SUFFIX := tar.gz > FCGI_URL := https://github.com/FastCGI-Archives/fcgi2/archive/$(FCGI_VERSION).$(FCGI_SUFFIX) > FCGI_SOURCE := $(SRCDIR)/$(FCGI).$(FCGI_SUFFIX) > FCGI_DIR := $(BUILDDIR)/$(FCGI) > FCGI_LICENSE := OML > -FCGI_LICENSE_FILES := file://LICENSE.TERMS;md5=e3aacac3a647af6e7e31f181cda0a06a > +FCGI_LICENSE_FILES := file://LICENSE;md5=e3aacac3a647af6e7e31f181cda0a06a > > # ---------------------------------------------------------------------------- > # Prepare