summaryrefslogtreecommitdiffstats
path: root/package/bash-completion/bash-completion.hash
diff options
context:
space:
mode:
authorFabrice Fontaine <fontaine.fabrice@gmail.com>2018-05-20 10:11:01 +0200
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>2018-05-20 11:43:15 +0200
commita335d32a5f31dec4f23c89ce9f496fac6eba3d69 (patch)
tree8a369988ba0e6974cf30b54e2d21cc73a9888073 /package/bash-completion/bash-completion.hash
parent34f256a9da690f66f8064a517564028b3be220f6 (diff)
downloadbuildroot-a335d32a5f31dec4f23c89ce9f496fac6eba3d69.tar.gz
buildroot-a335d32a5f31dec4f23c89ce9f496fac6eba3d69.zip
mbedtls: security bump to version 2.7.3
Extract from release announcement: - (2.9, 2.7, 2.1) Fixed an issue in the X.509 module which could lead to a buffer overread during certificate validation. Additionally, the issue could also lead to unnecessary callback checks being made or to some validation checks to be omitted. The overread could be triggered remotely, while the other issues would require a non DER-compliant certificate to be correctly signed by a trusted CA, or a trusted CA with a non DER-compliant certificate. Found by luocm. Fixes #825. - (2.9, 2.7, 2.1) Fixed the buffer length assertion in the ssl_parse_certificate_request() function which could lead to an arbitrary overread of the message buffer. The overreads could be caused by receiving a malformed algorithms section which was too short. In builds with debug output, this overread data was output with the debug data. - (2.9, 2.7, 2.1) Fixed a client-side bug in the validation of the server's ciphersuite choice which could potentially lead to the client accepting a ciphersuite it didn't offer or a ciphersuite that could not be used with the TLS or DTLS version chosen by the server. This could lead to corruption of internal data structures for some configurations. Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Diffstat (limited to 'package/bash-completion/bash-completion.hash')
0 files changed, 0 insertions, 0 deletions
OpenPOWER on IntegriCloud