From 7fb3c96a7b4bfab1272991a997d6b507b38d19c5 Mon Sep 17 00:00:00 2001 From: Fabrice Fontaine Date: Tue, 28 Nov 2023 21:21:13 +0100 Subject: [PATCH] package/squid: security bump to version 6.5 Fix CVE-2023-5824, CVE-2023-46724, CVE-2023-46846, CVE-2023-46847 and CVE-2023-46848 https://github.com/squid-cache/squid/security/advisories/GHSA-543m-w2m2-g255 https://github.com/squid-cache/squid/security/advisories/GHSA-j83v-w3p4-5cqh https://github.com/squid-cache/squid/security/advisories/GHSA-73m6-jm96-c6r3 https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g https://github.com/squid-cache/squid/security/advisories/GHSA-2g3c-pg7q-g59w https://github.com/squid-cache/squid/blob/SQUID_6_5/ChangeLog Signed-off-by: Fabrice Fontaine Signed-off-by: Peter Korsgaard --- package/squid/squid.hash | 8 ++++---- package/squid/squid.mk | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package/squid/squid.hash b/package/squid/squid.hash index a6d4c5d0569b..a163bd9ad3d2 100644 --- a/package/squid/squid.hash +++ b/package/squid/squid.hash @@ -1,6 +1,6 @@ -# From http://www.squid-cache.org/Versions/v6/squid-6.3.tar.xz.asc -md5 2512b5d27856e6f91a97719784506893 squid-6.3.tar.xz -sha1 7bd74034015c6a4d345a4d277a431908bed2ec4a squid-6.3.tar.xz +# From http://www.squid-cache.org/Versions/v6/squid-6.5.tar.xz.asc +md5 da2797d899cf538fab7f504fdf3c18bf squid-6.5.tar.xz +sha1 07a08394625948750264778c82e19cf24ea7cb1f squid-6.5.tar.xz # Locally calculated -sha256 74a0f5586a7a5d89573d502708d5e1d66ddf0430cf4802cc7261b765653248fa squid-6.3.tar.xz +sha256 5070f8a3ae6666870c8fc716326befb0a1abe8b5ff3a6f3932cbc5543d7c8549 squid-6.5.tar.xz sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 COPYING diff --git a/package/squid/squid.mk b/package/squid/squid.mk index 019a2029528e..c1477b1adff6 100644 --- a/package/squid/squid.mk +++ b/package/squid/squid.mk @@ -4,7 +4,7 @@ # ################################################################################ -SQUID_VERSION = 6.3 +SQUID_VERSION = 6.5 SQUID_SOURCE = squid-$(SQUID_VERSION).tar.xz SQUID_SITE = http://www.squid-cache.org/Versions/v6 SQUID_LICENSE = GPL-2.0+