summaryrefslogtreecommitdiffstats
path: root/package/domoticz/0002-CMakeLists.txt-fix-build-with-python-and-cmake-3.7.patch
diff options
context:
space:
mode:
authorPeter Korsgaard <peter@korsgaard.com>2018-11-29 15:47:40 +0100
committerPeter Korsgaard <peter@korsgaard.com>2018-11-29 16:29:46 +0100
commit3301b6e1b2e8b22f6caef58ce9289f1ada147f67 (patch)
tree793900367310e3f32134c10f6f9f5c82140e8399 /package/domoticz/0002-CMakeLists.txt-fix-build-with-python-and-cmake-3.7.patch
parent257a2118be2b0664e2b8dbda344a74443f70db86 (diff)
downloadbuildroot-3301b6e1b2e8b22f6caef58ce9289f1ada147f67.tar.gz
buildroot-3301b6e1b2e8b22f6caef58ce9289f1ada147f67.zip
libopenssl: security bump to version 1.0.2q
Fixes the following security vulnerabilities: *) Microarchitecture timing vulnerability in ECC scalar multiplication OpenSSL ECC scalar multiplication, used in e.g. ECDSA and ECDH, has been shown to be vulnerable to a microarchitecture timing side channel attack. An attacker with sufficient access to mount local timing attacks during ECDSA signature generation could recover the private key. This issue was reported to OpenSSL on 26th October 2018 by Alejandro Cabrera Aldaya, Billy Brumley, Sohaib ul Hassan, Cesar Pereida Garcia and Nicola Tuveri. (CVE-2018-5407) [Billy Brumley] *) Timing vulnerability in DSA signature generation The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. This issue was reported to OpenSSL on 16th October 2018 by Samuel Weiser. (CVE-2018-0734) [Paul Dale] For more information, see the changelog: https://www.openssl.org/news/cl102.txt Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Diffstat (limited to 'package/domoticz/0002-CMakeLists.txt-fix-build-with-python-and-cmake-3.7.patch')
0 files changed, 0 insertions, 0 deletions
OpenPOWER on IntegriCloud