All of lore.kernel.org
 help / color / mirror / Atom feed
From: Arnout Vandecappelle via buildroot <buildroot@buildroot.org>
To: Thomas Devoogdt <thomas@devoogdt.com>, buildroot@buildroot.org
Cc: Thomas Devoogdt <thomas.devoogdt@barco.com>
Subject: Re: [Buildroot] [PATCH v1] package/libfcgi: bump to 2.4.5 to fix CVE-2025-23016
Date: Fri, 2 May 2025 12:22:34 +0200	[thread overview]
Message-ID: <db69faa7-e75d-4d84-b7e3-c9a3a9a33fef@rnout.be> (raw)
In-Reply-To: <20250414212453.2903952-1-thomas@devoogdt.com>



On 14/04/2025 23:24, Thomas Devoogdt wrote:
> From: Thomas Devoogdt <thomas.devoogdt@barco.com>
> 
> Announcement:
> - https://github.com/FastCGI-Archives/fcgi2/releases/tag/2.4.5
> 
> See:
> - https://nvd.nist.gov/vuln/detail/CVE-2025-23016
> - https://github.com/advisories/GHSA-9825-56cx-cfg6
> - https://github.com/FastCGI-Archives/fcgi2/issues/67
> 
> Signed-off-by: Thomas Devoogdt <thomas.devoogdt@barco.com>

  Applied to 2025.02.x, thanks.

  Regards,
  Arnout

> ---
>   package/libfcgi/libfcgi.hash | 2 +-
>   package/libfcgi/libfcgi.mk   | 2 +-
>   2 files changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/package/libfcgi/libfcgi.hash b/package/libfcgi/libfcgi.hash
> index ca660c6ebd..371dba8939 100644
> --- a/package/libfcgi/libfcgi.hash
> +++ b/package/libfcgi/libfcgi.hash
> @@ -1,3 +1,3 @@
>   # Locally calculated
> -sha256  c0e0d9cc7d1e456d7278c974e2826f593ef5ca555783eba81e7e9c1a07ae0ecc  libfcgi-2.4.4.tar.gz
> +sha256  92b0111a98d8636e06c128444a3d4d7a720bdd54e6ee4dd0c7b67775b1b0abff  libfcgi-2.4.5.tar.gz
>   sha256  f0a8fe4513a43e8eebb24cdcf9d2e7efc52e4d8259178c6d76d3d84418397d81  LICENSE
> diff --git a/package/libfcgi/libfcgi.mk b/package/libfcgi/libfcgi.mk
> index 3c90b30e39..2348af843b 100644
> --- a/package/libfcgi/libfcgi.mk
> +++ b/package/libfcgi/libfcgi.mk
> @@ -4,7 +4,7 @@
>   #
>   ################################################################################
>   
> -LIBFCGI_VERSION = 2.4.4
> +LIBFCGI_VERSION = 2.4.5
>   LIBFCGI_SITE = $(call github,FastCGI-Archives,fcgi2,$(LIBFCGI_VERSION))
>   LIBFCGI_LICENSE = OML
>   LIBFCGI_LICENSE_FILES = LICENSE

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

  parent reply	other threads:[~2025-05-02 10:22 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-04-14 21:24 [Buildroot] [PATCH v1] package/libfcgi: bump to 2.4.5 to fix CVE-2025-23016 Thomas Devoogdt
2025-04-14 21:42 ` Julien Olivain
2025-05-02 10:22 ` Arnout Vandecappelle via buildroot [this message]
2025-05-02 10:24 ` Arnout Vandecappelle via buildroot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=db69faa7-e75d-4d84-b7e3-c9a3a9a33fef@rnout.be \
    --to=buildroot@buildroot.org \
    --cc=arnout@rnout.be \
    --cc=thomas.devoogdt@barco.com \
    --cc=thomas@devoogdt.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.