File tree Expand file tree Collapse file tree
toolkit/resources/manifests/package Expand file tree Collapse file tree Load Diff This file was deleted.
Original file line number Diff line number Diff line change 11{
22 "Signatures" : {
3- "expat-2.5.0 .tar.bz2" : " 6f0e6e01f7b30025fa05c85fdad1e5d0ec7fd35d9f61b22f34998de11969ff67 "
3+ "expat-2.6.2 .tar.bz2" : " 9c7c1b5dcbc3c237c500a8fb1493e14d9582146dd9b42aa8d3ffb856a3b927e0 "
44 }
55}
Original file line number Diff line number Diff line change 11%define underscore_version %(echo %{version } | cut -d. -f1-3 --output-delimiter= "_")
22Summary: An XML parser library
33Name: expat
4- Version: 2.5.0
5- Release: 2 %{?dist }
4+ Version: 2.6.2
5+ Release: 1 %{?dist }
66License: MIT
77Vendor: Microsoft Corporation
88Distribution: Mariner
99Group: System Environment/GeneralLibraries
1010URL: https://libexpat.github.io/
1111Source0: https://github.com/libexpat/libexpat/releases/download/R_%{underscore_version }/%{name }-%{version }.tar.bz2
1212
13- Patch0: CVE-2023-52426.patch
14-
1513Requires: %{name }-libs = %{version }-%{release }
1614
1715%description
@@ -32,7 +30,7 @@ Group: System Environment/Libraries
3230This package contains minimal set of shared expat libraries.
3331
3432%prep
35- %autosetup -p1
33+ %autosetup
3634
3735%build
3836%configure \
@@ -55,6 +53,7 @@ rm -rf %{buildroot}/%{_docdir}/%{name}
5553%files
5654%defattr(-,root,root)
5755%doc AUTHORS Changes
56+ %{_mandir }/man1/xmlwf.1.gz
5857%{_bindir }/*
5958
6059%files devel
@@ -68,6 +67,10 @@ rm -rf %{buildroot}/%{_docdir}/%{name}
6867%{_libdir }/libexpat.so.1*
6968
7069%changelog
70+ * Thu Mar 21 2024 Aditya Dubey <adityadubey@microsoft.com> - 2.6.2-1
71+ - Upgrading to 2.6.2 to fix CVE-2023-52425 and CVE-2023-28757
72+ - No longer need Patch CVE-2023-52426 since 2.6.2 fixes it
73+
7174* Thu Mar 07 2024 Saul Paredes <saulparedes@microsoft.com> - 2.5.0-2
7275- Patch CVE-2023-52426
7376
Original file line number Diff line number Diff line change 33983398 "type": "other",
33993399 "other": {
34003400 "name": "expat",
3401- "version": "2.5.0 ",
3402- "downloadUrl": "https://github.com/libexpat/libexpat/releases/download/R_2_5_0 /expat-2.5.0 .tar.bz2"
3401+ "version": "2.6.2 ",
3402+ "downloadUrl": "https://github.com/libexpat/libexpat/releases/download/R_2_6_2 /expat-2.6.2 .tar.bz2"
34033403 }
34043404 }
34053405 },
Original file line number Diff line number Diff line change @@ -95,9 +95,9 @@ elfutils-libelf-0.186-2.cm2.aarch64.rpm
9595elfutils-libelf-devel-0.186-2.cm2.aarch64.rpm
9696elfutils-libelf-devel-static-0.186-2.cm2.aarch64.rpm
9797elfutils-libelf-lang-0.186-2.cm2.aarch64.rpm
98- expat-2.5.0-2 .cm2.aarch64.rpm
99- expat-devel-2.5.0-2 .cm2.aarch64.rpm
100- expat-libs-2.5.0-2 .cm2.aarch64.rpm
98+ expat-2.6.2-1 .cm2.aarch64.rpm
99+ expat-devel-2.6.2-1 .cm2.aarch64.rpm
100+ expat-libs-2.6.2-1 .cm2.aarch64.rpm
101101libpipeline-1.5.5-3.cm2.aarch64.rpm
102102libpipeline-devel-1.5.5-3.cm2.aarch64.rpm
103103gdbm-1.21-1.cm2.aarch64.rpm
Original file line number Diff line number Diff line change @@ -95,9 +95,9 @@ elfutils-libelf-0.186-2.cm2.x86_64.rpm
9595elfutils-libelf-devel-0.186-2.cm2.x86_64.rpm
9696elfutils-libelf-devel-static-0.186-2.cm2.x86_64.rpm
9797elfutils-libelf-lang-0.186-2.cm2.x86_64.rpm
98- expat-2.5.0-2 .cm2.x86_64.rpm
99- expat-devel-2.5.0-2 .cm2.x86_64.rpm
100- expat-libs-2.5.0-2 .cm2.x86_64.rpm
98+ expat-2.6.2-1 .cm2.x86_64.rpm
99+ expat-devel-2.6.2-1 .cm2.x86_64.rpm
100+ expat-libs-2.6.2-1 .cm2.x86_64.rpm
101101libpipeline-1.5.5-3.cm2.x86_64.rpm
102102libpipeline-devel-1.5.5-3.cm2.x86_64.rpm
103103gdbm-1.21-1.cm2.x86_64.rpm
Original file line number Diff line number Diff line change @@ -73,10 +73,10 @@ elfutils-libelf-0.186-2.cm2.aarch64.rpm
7373elfutils-libelf-devel-0.186-2.cm2.aarch64.rpm
7474elfutils-libelf-devel-static-0.186-2.cm2.aarch64.rpm
7575elfutils-libelf-lang-0.186-2.cm2.aarch64.rpm
76- expat-2.5.0-2 .cm2.aarch64.rpm
77- expat-debuginfo-2.5.0-2 .cm2.aarch64.rpm
78- expat-devel-2.5.0-2 .cm2.aarch64.rpm
79- expat-libs-2.5.0-2 .cm2.aarch64.rpm
76+ expat-2.6.2-1 .cm2.aarch64.rpm
77+ expat-debuginfo-2.6.2-1 .cm2.aarch64.rpm
78+ expat-devel-2.6.2-1 .cm2.aarch64.rpm
79+ expat-libs-2.6.2-1 .cm2.aarch64.rpm
8080file-5.40-2.cm2.aarch64.rpm
8181file-debuginfo-5.40-2.cm2.aarch64.rpm
8282file-devel-5.40-2.cm2.aarch64.rpm
Original file line number Diff line number Diff line change @@ -76,10 +76,10 @@ elfutils-libelf-0.186-2.cm2.x86_64.rpm
7676elfutils-libelf-devel-0.186-2.cm2.x86_64.rpm
7777elfutils-libelf-devel-static-0.186-2.cm2.x86_64.rpm
7878elfutils-libelf-lang-0.186-2.cm2.x86_64.rpm
79- expat-2.5.0-2 .cm2.x86_64.rpm
80- expat-debuginfo-2.5.0-2 .cm2.x86_64.rpm
81- expat-devel-2.5.0-2 .cm2.x86_64.rpm
82- expat-libs-2.5.0-2 .cm2.x86_64.rpm
79+ expat-2.6.2-1 .cm2.x86_64.rpm
80+ expat-debuginfo-2.6.2-1 .cm2.x86_64.rpm
81+ expat-devel-2.6.2-1 .cm2.x86_64.rpm
82+ expat-libs-2.6.2-1 .cm2.x86_64.rpm
8383file-5.40-2.cm2.x86_64.rpm
8484file-debuginfo-5.40-2.cm2.x86_64.rpm
8585file-devel-5.40-2.cm2.x86_64.rpm
You can’t perform that action at this time.
0 commit comments