From 06fcd50956a51f4457bb9c8d9cd10cb8ae1989b6 Mon Sep 17 00:00:00 2001 From: Richard W.M. Jones Date: May 03 2021 10:28:30 +0000 Subject: New upstream version 1.3.20. Fixes CVE-2021-3504 missing bounds check in hivex_open. --- diff --git a/.gitignore b/.gitignore index 3929073..c8a3433 100644 --- a/.gitignore +++ b/.gitignore @@ -1,9 +1,4 @@ /.build-* /clog /hivex-*.tar.gz -/hivex-1.3.14.tar.gz.sig -/hivex-1.3.15.tar.gz.sig -/hivex-1.3.16.tar.gz.sig -/hivex-1.3.17.tar.gz.sig -/hivex-1.3.18.tar.gz.sig -/hivex-1.3.19.tar.gz.sig +/hivex-*.tar.gz.sig diff --git a/hivex.spec b/hivex.spec index 8e62deb..1a40e0d 100644 --- a/hivex.spec +++ b/hivex.spec @@ -9,8 +9,8 @@ %global verify_tarball_signature 1 Name: hivex -Version: 1.3.19 -Release: 10%{?dist} +Version: 1.3.20 +Release: 1%{?dist} Summary: Read and write Windows Registry binary hive files License: LGPLv2 @@ -302,6 +302,10 @@ fi %changelog +* Mon May 3 2021 Richard W.M. Jones - 1.3.20-1 +- New upstream version 1.3.20. +- Fixes CVE-2021-3504 missing bounds check in hivex_open. + * Tue Mar 30 2021 Richard W.M. Jones - 1.3.19-10 - Bump and rebuild for ELN. diff --git a/sources b/sources index 35aa274..c24d36a 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (hivex-1.3.19.tar.gz) = dc271349c6efa7b55ba144617e57fe4e7ce855ec1f4ef9f84ee86eeefd3a34cb6b26078786e1568f3008b922a31b758ff2c2734e599b67e0e210aa72e9f41177 -SHA512 (hivex-1.3.19.tar.gz.sig) = 8b9c8c9b6cef47036df70f79219ed91d592dbc8ae1de8f1378cdd0f18ab043fb2d16c6907d05240cb3d015360c721c922df198bd383e79e54b83c218c8c565fb +SHA512 (hivex-1.3.20.tar.gz) = 366e84c2a13ff53c70036df60db6e2b469cd06e3405761df73c47978b4fa0245246a1ea912aa5852b1272221d55c6c100b40b00e4c9a6f5668d12ff7f93c787a +SHA512 (hivex-1.3.20.tar.gz.sig) = 965d14010ac31893eb51bb095b1ef6b983750031a34117329c8d2aa20f7f54a828e45c60992b0b823bea35d20fc4cfc77e4a9d2f99965cd3a84216a8059c013d