summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorTim Smith <tsmith@chef.io>2018-02-20 12:48:30 -0800
committerTim Smith <tsmith@chef.io>2018-02-20 12:48:30 -0800
commit33706e4c2a27ce51175abeda61b7ccdddc3ef770 (patch)
tree2f8c3dc180b77307ac2cfc2f314c7c33b4298414
parent02a203fd549d5261e55d8e7f9aee1354d8bce5d4 (diff)
downloadchef-33706e4c2a27ce51175abeda61b7ccdddc3ef770.tar.gz
Update to libxml2 2.9.7
This resolves https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15412 Signed-off-by: Tim Smith <tsmith@chef.io>
-rw-r--r--omnibus_overrides.rb2
-rw-r--r--version_policy.rb2
2 files changed, 2 insertions, 2 deletions
diff --git a/omnibus_overrides.rb b/omnibus_overrides.rb
index 228dcf6177..2e91d5097a 100644
--- a/omnibus_overrides.rb
+++ b/omnibus_overrides.rb
@@ -5,7 +5,7 @@ override "libffi", version: "3.2.1"
override "libiconv", version: "1.15"
override "liblzma", version: "5.2.3"
override "libtool", version: "2.4.2"
-override "libxml2", version: "2.9.5"
+override "libxml2", version: "2.9.7"
override "libxslt", version: "1.1.30"
override "libyaml", version: "0.1.7"
override "makedepend", version: "1.0.5"
diff --git a/version_policy.rb b/version_policy.rb
index 3441ec8138..edd814214d 100644
--- a/version_policy.rb
+++ b/version_policy.rb
@@ -27,7 +27,7 @@ OMNIBUS_OVERRIDES = {
## according to comment in omnibus-sw, the very latest versions don't work on solaris
# https://github.com/chef/omnibus-software/blob/aefb7e79d29ca746c3f843673ef5e317fa3cba54/config/software/libtool.rb#L23
"libtool" => "2.4.2",
- "libxml2" => "2.9.5",
+ "libxml2" => "2.9.7",
"libxslt" => "1.1.30",
"libyaml" => "0.1.7",
"makedepend" => "1.0.5",