similarity index 97%
rename from meta/recipes-extended/groff/groff_1.24.1.bb
rename to meta/recipes-extended/groff/groff_1.24.2.bb
@@ -17,7 +17,7 @@ SRC_URI = "${GNU_MIRROR}/groff/groff-${PV}.tar.gz \
SRC_URI:append:class-native = "file://build-less.patch"
-SRC_URI[sha256sum] = "74e2819795b6aff431aeac983d63a9c8968eeaba2a2eba7df8ba4c7b41e7cfd8"
+SRC_URI[sha256sum] = "f9c1efd5bebbe37fc6e1063db7473ce8df1e3e0be4ff0f43ce04fce57e9c5dd9"
DEPENDS = "bison-native groff-native"
RDEPENDS:${PN} += "perl sed"
This release resolves the following issues in the GNU Savannah ticket tracker. bug #68689: [PATCH] [mm] `mmroff` vulnerable to command injection (CWE-78) bug #68688: [PATCH] [grohtml] `pre-grohtml` vulnerable to command injection (CWE-78) bug #68687: [PATCH] [pdfmom] vulnerable to command injection (CWE-78) bug #68152: [gxditview] SEGVs when invoked with no arguments This release corrects command injection security vulnerabilities (CWE-78) in the mmroff, pdfmom, and pre-grohtml programs. The last of these is a preprocessor that is run when groff or troff is run with the `-T html` or `-T xhtml` options. The vulnerabilities are variously 14-26 years old. Malicious input can escape groff's default "safer" mode, running commands embedded in that input at the user's privilege level. The groff development team recommends this release to any users who employ the named tools or GNU troff output formats with untrusted inputs. Man page rendering is not vulnerable unless rendering (X)HTML. This release also resolves a command-line argument processing defect in the gxditview program. It is not known to have any security impact. Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> --- .../recipes-extended/groff/{groff_1.24.1.bb => groff_1.24.2.bb} | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) rename meta/recipes-extended/groff/{groff_1.24.1.bb => groff_1.24.2.bb} (97%)