Skip to content

Commit

Permalink
Merge pull request microsoft#6486 from microsoft/ddstreet/fasttrack-c…
Browse files Browse the repository at this point in the history
…make-cve-2023-44487

fasttrack cmake CVE 2023 44487
  • Loading branch information
ddstreetmicrosoft authored Oct 19, 2023
2 parents d888008 + bfeeb89 commit 96a3515
Show file tree
Hide file tree
Showing 4 changed files with 496 additions and 5 deletions.
6 changes: 5 additions & 1 deletion SPECS/cmake/cmake.spec
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
Summary: Cmake
Name: cmake
Version: 3.21.4
Release: 9%{?dist}
Release: 10%{?dist}
License: BSD AND LGPLv2+
Vendor: Microsoft Corporation
Distribution: Mariner
Expand All @@ -19,6 +19,7 @@ Patch4: CVE-2023-28322-lib-unify-the-upload-method-handling.patch
Patch5: CVE-2023-35945.patch
Patch6: CVE-2023-38545.patch
Patch7: CVE-2023-38546.patch
Patch8: cve-2023-44487.patch
BuildRequires: bzip2
BuildRequires: bzip2-devel
BuildRequires: curl
Expand Down Expand Up @@ -84,6 +85,9 @@ bin/ctest --force-new-ctest-process --rerun-failed --output-on-failure
%{_prefix}/doc/%{name}-*/*

%changelog
* Thu Oct 19 2023 Dan Streetman <[email protected]> - 3.21.4-10
- Patch vendored nghttp2 for CVE-2023-44487

* Tue Oct 10 2023 Mykhailo Bykhovtsev <[email protected]> - 3.21.4-9
- Patch vendored curl for CVE-2023-38545, CVE-2023-38546

Expand Down
Loading

0 comments on commit 96a3515

Please sign in to comment.