diff --git a/SPECS/sqlite/CVE-2015-3717.nopatch b/SPECS/sqlite/CVE-2015-3717.nopatch new file mode 100644 index 00000000000..e69de29bb2d diff --git a/SPECS/sqlite/sqlite.spec b/SPECS/sqlite/sqlite.spec index b0073dc9357..40d9efcd453 100644 --- a/SPECS/sqlite/sqlite.spec +++ b/SPECS/sqlite/sqlite.spec @@ -2,13 +2,15 @@ Summary: A portable, high level programming interface to various calling conventions Name: sqlite Version: 3.32.3 -Release: 1%{?dist} +Release: 2%{?dist} License: Public Domain URL: https://www.sqlite.org Group: System Environment/GeneralLibraries Vendor: Microsoft Corporation Distribution: Mariner Source0: https://www.sqlite.org/2020/%{name}-autoconf-%{sourcever}.tar.gz +# CVE-2015-3717 applies to versions shipped in iOS and OS X +Patch0: CVE-2015-3717.nopatch Obsoletes: sqlite-autoconf Requires: sqlite-libs = %{version}-%{release} Provides: sqlite3 @@ -35,7 +37,7 @@ Obsoletes: sqlite-autoconf The sqlite3 library. %prep -%setup -q -n %{name}-autoconf-%{sourcever} +%autosetup -p1 -n %{name}-autoconf-%{sourcever} %build %configure \ @@ -89,6 +91,8 @@ rm -rf %{buildroot}/* %{_libdir}/libsqlite3.so.0.8.6 %changelog +* Thu Oct 22 2020 Ruying Chen 3.32.3-2 +- Nopatch CVE-2015-3717. Applies to versions shipped in iOS and OS X. * Tue Jul 07 2020 Joe Schmitt 3.32.3-1 - Update to version 3.32.3 to fix CVE-2020-15358. - Update URL to use https. diff --git a/toolkit/resources/manifests/package/pkggen_core_aarch64.txt b/toolkit/resources/manifests/package/pkggen_core_aarch64.txt index 5d03e1c1aaa..4ce6e4d3747 100644 --- a/toolkit/resources/manifests/package/pkggen_core_aarch64.txt +++ b/toolkit/resources/manifests/package/pkggen_core_aarch64.txt @@ -80,9 +80,9 @@ popt-devel-1.16-7.cm1.aarch64.rpm popt-lang-1.16-7.cm1.aarch64.rpm nspr-4.21-2.cm1.aarch64.rpm nspr-devel-4.21-2.cm1.aarch64.rpm -sqlite-3.32.3-1.cm1.aarch64.rpm -sqlite-devel-3.32.3-1.cm1.aarch64.rpm -sqlite-libs-3.32.3-1.cm1.aarch64.rpm +sqlite-3.32.3-2.cm1.aarch64.rpm +sqlite-devel-3.32.3-2.cm1.aarch64.rpm +sqlite-libs-3.32.3-2.cm1.aarch64.rpm nss-3.44-2.cm1.aarch64.rpm nss-devel-3.44-2.cm1.aarch64.rpm nss-libs-3.44-2.cm1.aarch64.rpm diff --git a/toolkit/resources/manifests/package/pkggen_core_x86_64.txt b/toolkit/resources/manifests/package/pkggen_core_x86_64.txt index 4f7a37dd685..203d9a05e8b 100644 --- a/toolkit/resources/manifests/package/pkggen_core_x86_64.txt +++ b/toolkit/resources/manifests/package/pkggen_core_x86_64.txt @@ -80,9 +80,9 @@ popt-devel-1.16-7.cm1.x86_64.rpm popt-lang-1.16-7.cm1.x86_64.rpm nspr-4.21-2.cm1.x86_64.rpm nspr-devel-4.21-2.cm1.x86_64.rpm -sqlite-3.32.3-1.cm1.x86_64.rpm -sqlite-devel-3.32.3-1.cm1.x86_64.rpm -sqlite-libs-3.32.3-1.cm1.x86_64.rpm +sqlite-3.32.3-2.cm1.x86_64.rpm +sqlite-devel-3.32.3-2.cm1.x86_64.rpm +sqlite-libs-3.32.3-2.cm1.x86_64.rpm nss-3.44-2.cm1.x86_64.rpm nss-devel-3.44-2.cm1.x86_64.rpm nss-libs-3.44-2.cm1.x86_64.rpm diff --git a/toolkit/resources/manifests/package/toolchain_aarch64.txt b/toolkit/resources/manifests/package/toolchain_aarch64.txt index a440121be13..34544d7d701 100644 --- a/toolkit/resources/manifests/package/toolchain_aarch64.txt +++ b/toolkit/resources/manifests/package/toolchain_aarch64.txt @@ -347,10 +347,10 @@ sed-debuginfo-4.5-3.cm1.aarch64.rpm sed-lang-4.5-3.cm1.aarch64.rpm shadow-utils-4.6-8.cm1.aarch64.rpm shadow-utils-debuginfo-4.6-8.cm1.aarch64.rpm -sqlite-3.32.3-1.cm1.aarch64.rpm -sqlite-debuginfo-3.32.3-1.cm1.aarch64.rpm -sqlite-devel-3.32.3-1.cm1.aarch64.rpm -sqlite-libs-3.32.3-1.cm1.aarch64.rpm +sqlite-3.32.3-2.cm1.aarch64.rpm +sqlite-debuginfo-3.32.3-2.cm1.aarch64.rpm +sqlite-devel-3.32.3-2.cm1.aarch64.rpm +sqlite-libs-3.32.3-2.cm1.aarch64.rpm swig-3.0.12-4.cm1.aarch64.rpm swig-debuginfo-3.0.12-4.cm1.aarch64.rpm systemd-239-32.cm1.aarch64.rpm diff --git a/toolkit/resources/manifests/package/toolchain_x86_64.txt b/toolkit/resources/manifests/package/toolchain_x86_64.txt index fe801ced5cf..13d3b51f76d 100644 --- a/toolkit/resources/manifests/package/toolchain_x86_64.txt +++ b/toolkit/resources/manifests/package/toolchain_x86_64.txt @@ -347,10 +347,10 @@ sed-debuginfo-4.5-3.cm1.x86_64.rpm sed-lang-4.5-3.cm1.x86_64.rpm shadow-utils-4.6-8.cm1.x86_64.rpm shadow-utils-debuginfo-4.6-8.cm1.x86_64.rpm -sqlite-3.32.3-1.cm1.x86_64.rpm -sqlite-debuginfo-3.32.3-1.cm1.x86_64.rpm -sqlite-devel-3.32.3-1.cm1.x86_64.rpm -sqlite-libs-3.32.3-1.cm1.x86_64.rpm +sqlite-3.32.3-2.cm1.x86_64.rpm +sqlite-debuginfo-3.32.3-2.cm1.x86_64.rpm +sqlite-devel-3.32.3-2.cm1.x86_64.rpm +sqlite-libs-3.32.3-2.cm1.x86_64.rpm swig-3.0.12-4.cm1.x86_64.rpm swig-debuginfo-3.0.12-4.cm1.x86_64.rpm systemd-239-32.cm1.x86_64.rpm