wget: Update to 1.20.3

Message ID 20190405195512.18968-1-matthias.fischer@ipfire.org
State Accepted
Commit ee44d509b61eea858e38e8a4f1f57db6f9940cf3
Headers
Series wget: Update to 1.20.3 |

Commit Message

Matthias Fischer April 6, 2019, 6:55 a.m. UTC
  For details see:
https://fossies.org/linux/wget/ChangeLog

Excerpt from "NEWS":

"2019-04-05  Tim Ruehsen  <tim.ruehsen@gmx.de>

Fix a buffer overflow vulnerability
* src/iri.c(do_conversion): Reallocate the output buffer to a larger
  size if it is already full"

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
---
 lfs/wget | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)
  

Comments

Michael Tremer April 7, 2019, 2:12 a.m. UTC | #1
Hey,

Not very good to see those vulnerabilities.

Merged.

-Michael

> On 5 Apr 2019, at 20:55, Matthias Fischer <matthias.fischer@ipfire.org> wrote:
> 
> For details see:
> https://fossies.org/linux/wget/ChangeLog
> 
> Excerpt from "NEWS":
> 
> "2019-04-05  Tim Ruehsen  <tim.ruehsen@gmx.de>
> 
> Fix a buffer overflow vulnerability
> * src/iri.c(do_conversion): Reallocate the output buffer to a larger
>  size if it is already full"
> 
> Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
> ---
> lfs/wget | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/lfs/wget b/lfs/wget
> index ac2fa826c..00ca75033 100644
> --- a/lfs/wget
> +++ b/lfs/wget
> @@ -24,7 +24,7 @@
> 
> include Config
> 
> -VER        = 1.20.2
> +VER        = 1.20.3
> 
> THISAPP    = wget-$(VER)
> DL_FILE    = $(THISAPP).tar.gz
> @@ -40,7 +40,7 @@ objects = $(DL_FILE)
> 
> $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
> 
> -$(DL_FILE)_MD5 = 2692f6678e93601441306b5c1fc6a77a
> +$(DL_FILE)_MD5 = db4e6dc7977cbddcd543b240079a4899
> 
> install : $(TARGET)
> 
> -- 
> 2.18.0
>
  

Patch

diff --git a/lfs/wget b/lfs/wget
index ac2fa826c..00ca75033 100644
--- a/lfs/wget
+++ b/lfs/wget
@@ -24,7 +24,7 @@ 
 
 include Config
 
-VER        = 1.20.2
+VER        = 1.20.3
 
 THISAPP    = wget-$(VER)
 DL_FILE    = $(THISAPP).tar.gz
@@ -40,7 +40,7 @@  objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_MD5 = 2692f6678e93601441306b5c1fc6a77a
+$(DL_FILE)_MD5 = db4e6dc7977cbddcd543b240079a4899
 
 install : $(TARGET)