From c51f9881d6737ba63ae4ce6f1ea436eeec364e09 Mon Sep 17 00:00:00 2001 From: Francois Perrad Date: Wed, 17 Jul 2024 19:02:56 +0200 Subject: [PATCH] package/libgtk3: security bump to version 3.24.43 fix CVE-2024-6655 (Library injection from CWD) Signed-off-by: Francois Perrad Signed-off-by: Thomas Petazzoni --- package/libgtk3/libgtk3.hash | 4 ++-- package/libgtk3/libgtk3.mk | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/package/libgtk3/libgtk3.hash b/package/libgtk3/libgtk3.hash index a1d8b1694d..6a682a7412 100644 --- a/package/libgtk3/libgtk3.hash +++ b/package/libgtk3/libgtk3.hash @@ -1,5 +1,5 @@ -# From https://download.gnome.org/sources/gtk+/3.24/gtk+-3.24.42.sha256sum -sha256 50f89f615092d4dd01bbd759719f8bd380e5f149f6fd78a94725e2de112377e2 gtk+-3.24.42.tar.xz +# From https://download.gnome.org/sources/gtk+/3.24/gtk+-3.24.43.sha256sum +sha256 7e04f0648515034b806b74ae5d774d87cffb1a2a96c468cb5be476d51bf2f3c7 gtk+-3.24.43.tar.xz # Hash for license file: sha256 b7993225104d90ddd8024fd838faf300bea5e83d91203eab98e29512acebd69c COPYING diff --git a/package/libgtk3/libgtk3.mk b/package/libgtk3/libgtk3.mk index 547fd194a5..d6d7c64a54 100644 --- a/package/libgtk3/libgtk3.mk +++ b/package/libgtk3/libgtk3.mk @@ -5,7 +5,7 @@ ################################################################################ LIBGTK3_VERSION_MAJOR = 3.24 -LIBGTK3_VERSION = $(LIBGTK3_VERSION_MAJOR).42 +LIBGTK3_VERSION = $(LIBGTK3_VERSION_MAJOR).43 LIBGTK3_SOURCE = gtk+-$(LIBGTK3_VERSION).tar.xz LIBGTK3_SITE = https://download.gnome.org/sources/gtk+/$(LIBGTK3_VERSION_MAJOR) LIBGTK3_LICENSE = LGPL-2.0+