ports/opt (3.4): [notify] freetype: updated to 2.9.1. Fixes CVE-2018-6942. Closes #FS1654

crux at crux.nu crux at crux.nu
Thu May 3 21:59:00 UTC 2018


commit b6019adad062d827dd5e13885184445f76849b6b
Author: Fredrik Rinnestam <fredrik at crux.nu>
Date:   Thu May 3 23:55:10 2018 +0200

    [notify] freetype: updated to 2.9.1. Fixes CVE-2018-6942. Closes #FS1654
    
    Advisory URL: https://nvd.nist.gov/vuln/detail/CVE-2018-6942

diff --git a/freetype/.footprint b/freetype/.footprint
index c7d7f1395..5edb0dd26 100644
--- a/freetype/.footprint
+++ b/freetype/.footprint
@@ -1,6 +1,4 @@
 drwxr-xr-x	root/root	usr/
-drwxr-xr-x	root/root	usr/bin/
--rwxr-xr-x	root/root	usr/bin/freetype-config
 drwxr-xr-x	root/root	usr/include/
 drwxr-xr-x	root/root	usr/include/freetype2/
 drwxr-xr-x	root/root	usr/include/freetype2/freetype/
@@ -57,14 +55,11 @@ drwxr-xr-x	root/root	usr/include/freetype2/freetype/config/
 drwxr-xr-x	root/root	usr/lib/
 -rw-r--r--	root/root	usr/lib/libfreetype.a
 -rwxr-xr-x	root/root	usr/lib/libfreetype.la
-lrwxrwxrwx	root/root	usr/lib/libfreetype.so -> libfreetype.so.6.16.0
-lrwxrwxrwx	root/root	usr/lib/libfreetype.so.6 -> libfreetype.so.6.16.0
--rwxr-xr-x	root/root	usr/lib/libfreetype.so.6.16.0
+lrwxrwxrwx	root/root	usr/lib/libfreetype.so -> libfreetype.so.6.16.1
+lrwxrwxrwx	root/root	usr/lib/libfreetype.so.6 -> libfreetype.so.6.16.1
+-rwxr-xr-x	root/root	usr/lib/libfreetype.so.6.16.1
 drwxr-xr-x	root/root	usr/lib/pkgconfig/
 -rw-r--r--	root/root	usr/lib/pkgconfig/freetype2.pc
 drwxr-xr-x	root/root	usr/share/
 drwxr-xr-x	root/root	usr/share/aclocal/
 -rw-r--r--	root/root	usr/share/aclocal/freetype2.m4
-drwxr-xr-x	root/root	usr/share/man/
-drwxr-xr-x	root/root	usr/share/man/man1/
--rw-r--r--	root/root	usr/share/man/man1/freetype-config.1.gz
diff --git a/freetype/.md5sum b/freetype/.md5sum
index fa72720c8..552c00360 100644
--- a/freetype/.md5sum
+++ b/freetype/.md5sum
@@ -1 +1 @@
-513c403c110016fdc7e537216a642b1d  freetype-2.9.tar.bz2
+60ef7d8160cd4bf8cb118ee9d65367ca  freetype-2.9.1.tar.bz2
diff --git a/freetype/.signature b/freetype/.signature
index 2fc716aaf..032aa0e3c 100644
--- a/freetype/.signature
+++ b/freetype/.signature
@@ -1,5 +1,5 @@
 untrusted comment: verify with /etc/ports/opt.pub
-RWSE3ohX2g5d/b3hktn/BdjVFwD7jMn+sCVzaOtFrZoYKUWgqykgAdC+gjMeIkur0n3uwI8r8/tLp9uKdMHIx7dDrlbaYLLHtAY=
-SHA256 (Pkgfile) = eeed712b06d696c513b8603e19eba9cd17a1f64643c470928b44a2489ba7610f
-SHA256 (.footprint) = 93edabc23c1ccc2ebab56022b8f17c21537885fc55c9fe24be8e1c260fe99efd
-SHA256 (freetype-2.9.tar.bz2) = e6ffba3c8cef93f557d1f767d7bc3dee860ac7a3aaff588a521e081bc36f4c8a
+RWSE3ohX2g5d/Yc308aODwcAPn1gO9MoadwJmSpHjkL04L9Z3xXubIZ9w0oufFwlub1H+b7FTL0LhqDKaoSviEzbaYgR/EW5FAc=
+SHA256 (Pkgfile) = 86cc3e4f4c59fd975218a01f9216138407bb50d6fecdb601765a92b05c39a467
+SHA256 (.footprint) = 9e450e330caeb4edda03d403270d47137a72cdeed398c48e5337e1d884a01019
+SHA256 (freetype-2.9.1.tar.bz2) = db8d87ea720ea9d5edc5388fc7a0497bb11ba9fe972245e0f7f4c7e8b1e1e84d
diff --git a/freetype/Pkgfile b/freetype/Pkgfile
index 56559a7b6..62f3e8c3f 100644
--- a/freetype/Pkgfile
+++ b/freetype/Pkgfile
@@ -4,7 +4,7 @@
 # Depends on: libpng
 
 name=freetype
-version=2.9
+version=2.9.1
 release=1
 source=(http://download.savannah.gnu.org/releases/$name/$name-$version.tar.bz2)
 


More information about the CRUX mailing list