Skip to content

Commit 7f5ccbf

Browse files
[AUTO-CHERRYPICK] Upgrade ncurses to 6.4-20230520 to fix CVE-2023-50495 - branch main (#11283)
Co-authored-by: Sandeep Karambelkar <sandeep.karambelkar@gmail.com>
1 parent 381cbeb commit 7f5ccbf

7 files changed

Lines changed: 29 additions & 26 deletions

File tree

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
22
"Signatures": {
3-
"ncurses-6.4-20230423.tgz": "7d77f95eff470099cfb7cabd6d3b8766ee1c4bda33755dd5a4d73fcc85315a4f"
3+
"ncurses-6.4-20230520.tgz": "23ff1d2b51280fa92b7ff569505662370c26e85a2f26137b75ba4cd2457f1721"
44
}
55
}

SPECS/ncurses/ncurses.spec

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
1-
%global patchlevel 20230423
1+
%global patchlevel 20230520
22

33
Summary: Libraries for terminal handling of character screens
44
Name: ncurses
55
Version: 6.4
6-
Release: 2%{?dist}
6+
Release: 3%{?dist}
77
License: MIT
88
Vendor: Microsoft Corporation
99
Distribution: Mariner
@@ -233,6 +233,9 @@ xz NEWS
233233
%files term -f terms.term
234234

235235
%changelog
236+
* Mon Dec 02 2024 Sandeep Karambelkar <skarambelkar@microsoft.com> - 6.4-3
237+
- Update to version 6.4-20230520 to fix CVE-2023-50495
238+
236239
* Thu Nov 16 2023 Tobias Brick <tobiasb@microsoft.com> - 6.4-2
237240
- Update to version 6.4-20230423 to fix crash in tmux
238241

cgmanifest.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14114,7 +14114,7 @@
1411414114
"other": {
1411514115
"name": "ncurses",
1411614116
"version": "6.4",
14117-
"downloadUrl": "https://invisible-mirror.net/archives/ncurses/current/ncurses-6.4-20230423.tgz"
14117+
"downloadUrl": "https://invisible-mirror.net/archives/ncurses/current/ncurses-6.4-20230520.tgz"
1411814118
}
1411914119
}
1412014120
},

toolkit/resources/manifests/package/pkggen_core_aarch64.txt

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -33,11 +33,11 @@ libpkgconf-1.8.0-3.cm2.aarch64.rpm
3333
pkgconf-1.8.0-3.cm2.aarch64.rpm
3434
pkgconf-m4-1.8.0-3.cm2.noarch.rpm
3535
pkgconf-pkg-config-1.8.0-3.cm2.aarch64.rpm
36-
ncurses-6.4-2.cm2.aarch64.rpm
37-
ncurses-compat-6.4-2.cm2.aarch64.rpm
38-
ncurses-devel-6.4-2.cm2.aarch64.rpm
39-
ncurses-libs-6.4-2.cm2.aarch64.rpm
40-
ncurses-term-6.4-2.cm2.aarch64.rpm
36+
ncurses-6.4-3.cm2.aarch64.rpm
37+
ncurses-compat-6.4-3.cm2.aarch64.rpm
38+
ncurses-devel-6.4-3.cm2.aarch64.rpm
39+
ncurses-libs-6.4-3.cm2.aarch64.rpm
40+
ncurses-term-6.4-3.cm2.aarch64.rpm
4141
readline-8.1-1.cm2.aarch64.rpm
4242
readline-devel-8.1-1.cm2.aarch64.rpm
4343
coreutils-8.32-7.cm2.aarch64.rpm

toolkit/resources/manifests/package/pkggen_core_x86_64.txt

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -33,11 +33,11 @@ libpkgconf-1.8.0-3.cm2.x86_64.rpm
3333
pkgconf-1.8.0-3.cm2.x86_64.rpm
3434
pkgconf-m4-1.8.0-3.cm2.noarch.rpm
3535
pkgconf-pkg-config-1.8.0-3.cm2.x86_64.rpm
36-
ncurses-6.4-2.cm2.x86_64.rpm
37-
ncurses-compat-6.4-2.cm2.x86_64.rpm
38-
ncurses-devel-6.4-2.cm2.x86_64.rpm
39-
ncurses-libs-6.4-2.cm2.x86_64.rpm
40-
ncurses-term-6.4-2.cm2.x86_64.rpm
36+
ncurses-6.4-3.cm2.x86_64.rpm
37+
ncurses-compat-6.4-3.cm2.x86_64.rpm
38+
ncurses-devel-6.4-3.cm2.x86_64.rpm
39+
ncurses-libs-6.4-3.cm2.x86_64.rpm
40+
ncurses-term-6.4-3.cm2.x86_64.rpm
4141
readline-8.1-1.cm2.x86_64.rpm
4242
readline-devel-8.1-1.cm2.x86_64.rpm
4343
coreutils-8.32-7.cm2.x86_64.rpm

toolkit/resources/manifests/package/toolchain_aarch64.txt

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -251,12 +251,12 @@ mpfr-4.1.0-2.cm2.aarch64.rpm
251251
mpfr-debuginfo-4.1.0-2.cm2.aarch64.rpm
252252
mpfr-devel-4.1.0-2.cm2.aarch64.rpm
253253
msopenjdk-11-11.0.18-1.aarch64.rpm
254-
ncurses-6.4-2.cm2.aarch64.rpm
255-
ncurses-compat-6.4-2.cm2.aarch64.rpm
256-
ncurses-debuginfo-6.4-2.cm2.aarch64.rpm
257-
ncurses-devel-6.4-2.cm2.aarch64.rpm
258-
ncurses-libs-6.4-2.cm2.aarch64.rpm
259-
ncurses-term-6.4-2.cm2.aarch64.rpm
254+
ncurses-6.4-3.cm2.aarch64.rpm
255+
ncurses-compat-6.4-3.cm2.aarch64.rpm
256+
ncurses-debuginfo-6.4-3.cm2.aarch64.rpm
257+
ncurses-devel-6.4-3.cm2.aarch64.rpm
258+
ncurses-libs-6.4-3.cm2.aarch64.rpm
259+
ncurses-term-6.4-3.cm2.aarch64.rpm
260260
newt-0.52.21-5.cm2.aarch64.rpm
261261
newt-debuginfo-0.52.21-5.cm2.aarch64.rpm
262262
newt-devel-0.52.21-5.cm2.aarch64.rpm

toolkit/resources/manifests/package/toolchain_x86_64.txt

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -257,12 +257,12 @@ mpfr-4.1.0-2.cm2.x86_64.rpm
257257
mpfr-debuginfo-4.1.0-2.cm2.x86_64.rpm
258258
mpfr-devel-4.1.0-2.cm2.x86_64.rpm
259259
msopenjdk-11-11.0.18-1.x86_64.rpm
260-
ncurses-6.4-2.cm2.x86_64.rpm
261-
ncurses-compat-6.4-2.cm2.x86_64.rpm
262-
ncurses-debuginfo-6.4-2.cm2.x86_64.rpm
263-
ncurses-devel-6.4-2.cm2.x86_64.rpm
264-
ncurses-libs-6.4-2.cm2.x86_64.rpm
265-
ncurses-term-6.4-2.cm2.x86_64.rpm
260+
ncurses-6.4-3.cm2.x86_64.rpm
261+
ncurses-compat-6.4-3.cm2.x86_64.rpm
262+
ncurses-debuginfo-6.4-3.cm2.x86_64.rpm
263+
ncurses-devel-6.4-3.cm2.x86_64.rpm
264+
ncurses-libs-6.4-3.cm2.x86_64.rpm
265+
ncurses-term-6.4-3.cm2.x86_64.rpm
266266
newt-0.52.21-5.cm2.x86_64.rpm
267267
newt-debuginfo-0.52.21-5.cm2.x86_64.rpm
268268
newt-devel-0.52.21-5.cm2.x86_64.rpm

0 commit comments

Comments
 (0)