summaryrefslogtreecommitdiffstats
path: root/package/python-cryptography/python-cryptography.mk
diff options
context:
space:
mode:
authorPeter Korsgaard <peter@korsgaard.com>2016-12-19 14:13:23 +0100
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>2016-12-19 22:28:40 +0100
commit9d1dab1b80ae5b0851e29b9273e248d966ad8637 (patch)
tree26a041e47d74cc192ee4422daaa789ea2a415c3f /package/python-cryptography/python-cryptography.mk
parentc07ad416b41eab898fc8899f46aed35d5ad923ef (diff)
downloadbuildroot-9d1dab1b80ae5b0851e29b9273e248d966ad8637.tar.gz
buildroot-9d1dab1b80ae5b0851e29b9273e248d966ad8637.zip
libupnp: add upstream security fix for CVE-2016-6255
If there's no registered handler for a POST request, the default behaviour is to write it to the filesystem. Several million deployed devices appear to have this behaviour, making it possible to (at least) store arbitrary data on them. Add a configure option that enables this behaviour, and change the default to just drop POSTs that aren't directly handled. Signed-off-by: Peter Korsgaard <peter@korsgaard.com> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
Diffstat (limited to 'package/python-cryptography/python-cryptography.mk')
0 files changed, 0 insertions, 0 deletions
OpenPOWER on IntegriCloud