[dev] c-ares: bump version to fix CVE-2021-3672 (#1685)

* c-ares: bump version to fix CVE-2021-3672
* cgmanifest: c-ares: bump version 1.17.1 -> 1.18.1
* c-ares: appease spec-linter

Signed-off-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
This commit is contained in:
Muhammad Falak R Wani 2021-12-01 19:13:24 +05:30 коммит произвёл GitHub
Родитель bad368c4d2
Коммит b175f4efe2
Не найден ключ, соответствующий данной подписи
Идентификатор ключа GPG: 4AEE18F83AFDEB23
3 изменённых файлов: 29 добавлений и 23 удалений

Просмотреть файл

@ -1,5 +1,5 @@
{
"Signatures": {
"c-ares-1.17.1.tar.gz": "d73dd0f6de824afd407ce10750ea081af47eba52b8a6cb307d220131ad93fc40"
"c-ares-1.18.1.tar.gz": "1a7d52a8a84a9fbffb1be9133c0f6e17217d91ea5a6fa61f6b4729cda78ebbcf"
}
}
}

Просмотреть файл

@ -1,6 +1,6 @@
Summary: A library that performs asynchronous DNS operations
Name: c-ares
Version: 1.17.1
Version: 1.18.1
Release: 1%{?dist}
License: MIT
Vendor: Microsoft Corporation
@ -21,7 +21,7 @@ by Greg Hudson at MIT.
Summary: Development files for c-ares
Group: Development/Libraries
Requires: %{name} = %{version}-%{release}
Requires: pkg-config
Requires: pkgconfig
%description devel
This package contains the header files and libraries needed to
@ -44,10 +44,11 @@ rm -f %{buildroot}/%{_libdir}/libcares.la
%check
make %{?_smp_mflags} check
%clean
%{clean}
rm -rf %{buildroot}
%post -p /sbin/ldconfig
%postun -p /sbin/ldconfig
@ -62,6 +63,7 @@ rm -rf %{buildroot}
%{_includedir}/ares.h
%{_includedir}/ares_build.h
%{_includedir}/ares_dns.h
%{_includedir}/ares_nameser.h
%{_includedir}/ares_rules.h
%{_includedir}/ares_version.h
%{_libdir}/*.so
@ -69,30 +71,34 @@ rm -rf %{buildroot}
%{_mandir}/man3/ares_*
%changelog
* Sun Nov 28 2021 Muhammad Falak <mwani@microsoft.com> - 1.18.1-1
- Bump version to fix CVE-2021-3672
- License verified
* Mon Mar 15 2021 Nick Samson <nisamson@microsoft.com> - 1.17.1-1
- Removed %%sha line. Upgraded to 1.17.1 to address CVE-2020-8277.
- License confirmed as MIT. Changed URLs to use HTTPS.
* Sat May 09 2020 Nick Samson <nisamson@microsoft.com> - 1.14.0-3
- Added %%license line automatically
* Sat May 09 2020 Nick Samson <nisamson@microsoft.com> - 1.14.0-3
- Added %%license line automatically
* Tue Sep 03 2019 Mateusz Malisz <mamalisz@microsoft.com> 1.14.0-2
- Initial CBL-Mariner import from Photon (license: Apache2).
* Tue Sep 03 2019 Mateusz Malisz <mamalisz@microsoft.com> 1.14.0-2
- Initial CBL-Mariner import from Photon (license: Apache2).
* Fri Sep 21 2018 Sujay G <gsujay@vmware.com> 1.14.0-1
- Bump c-ares version to 1.14.0
* Fri Sep 21 2018 Sujay G <gsujay@vmware.com> 1.14.0-1
- Bump c-ares version to 1.14.0
* Fri Sep 29 2017 Dheeraj Shetty <dheerajs@vmware.com> 1.12.0-2
- Fix for CVE-2017-1000381
* Fri Sep 29 2017 Dheeraj Shetty <dheerajs@vmware.com> 1.12.0-2
- Fix for CVE-2017-1000381
* Fri Apr 07 2017 Anish Swaminathan <anishs@vmware.com> 1.12.0-1
- Upgrade to 1.12.0
* Fri Apr 07 2017 Anish Swaminathan <anishs@vmware.com> 1.12.0-1
- Upgrade to 1.12.0
* Wed Oct 05 2016 Xiaolin Li <xiaolinl@vmware.com> 1.10.0-3
- Apply patch for CVE-2016-5180.
* Wed Oct 05 2016 Xiaolin Li <xiaolinl@vmware.com> 1.10.0-3
- Apply patch for CVE-2016-5180.
* Tue May 24 2016 Priyesh Padmavilasom <ppadmavilasom@vmware.com> 1.10.0-2
- GA - Bump release of all rpms
* Tue May 24 2016 Priyesh Padmavilasom <ppadmavilasom@vmware.com> 1.10.0-2
- GA - Bump release of all rpms
* Wed Feb 03 2016 Anish Swaminathan <anishs@vmware.com> - 1.10.0-1
- Initial version
* Wed Feb 03 2016 Anish Swaminathan <anishs@vmware.com> - 1.10.0-1
- Initial version

Просмотреть файл

@ -586,8 +586,8 @@
"type": "other",
"other": {
"name": "c-ares",
"version": "1.17.1",
"downloadUrl": "https://c-ares.haxx.se/download/c-ares-1.17.1.tar.gz"
"version": "1.18.1",
"downloadUrl": "https://c-ares.haxx.se/download/c-ares-1.18.1.tar.gz"
}
}
},