librepo - Library for processing rpm-md

Edit Package librepo
No description set
Refresh
Refresh
Source Files
Filename Size Changed
librepo-1.12.1.tar.gz 0000816206 797 KB
librepo.changes 0000006694 6.54 KB
librepo.spec 0000003881 3.79 KB
Revision 2 (latest revision is 5)
Marco Strigl's avatar Marco Strigl (mstrigl) accepted request 856753 from Wolfgang Engel's avatar Wolfgang Engel (bigironman) (revision 2)
Upgrade to 1.12.1 and merging changes file from devel project and SLE


- Upgrade to 1.12.1
  + Validate path read from repomd.xml (rh#1868639, CVE-2020-14352)
- Changes from 1.12.0
  + Prefer mirrorlist/metalink over baseurl (rh#1775184)
  + Decode package URL when using for local filename (rh#1817130)
  + Fix memory leak in lr_download_metadata() and lr_yum_download_remote()
  + Download sources work when at least one of specified is working (rh#1775184)
- Dropped validate_path.patch to prevent directory traversal attacks
  (boo#1175475, CVE-2020-14352) since it is upstream with version 1.12.1
Comments 0
openSUSE Build Service is sponsored by